Skip to main content

hatch-pinned-extra

License GitHub last commit PyPI - Downloads uv

Hatch plugin that adds a packaging extra to the wheel metadata with pinned dependencies from uv.lock.

Usage

# pyproject.toml
[build-system]
requires = [
    "hatchling",
    "hatch-pinned-extra>=0.0.1,<0.1.0",
]
build-backend = "hatchling.build"

[tool.hatch.metadata.hooks.pinned_extra]
name = "pinned"

If your package doesn't have any optional dependencies already, you will need to mark them as dynamic:

# pyproject.toml
[project]
dynamic = [
    "optional-dependencies",
]

Reading pinned dependencies from pylock.toml file

To use a pylock.toml file instead of uv.lock, set lockfile to the file path:

[tool.hatch.metadata.hooks.pinned_extra]
lockfile = "pylock.prod.toml"

[!NOTE] The pinned will contain ALL the dependencies in pylock.toml, so you'll want to make sure it includes only runtime or relevant dependencies, e.g. by generating it with the --no-dev flag.

[!NOTE] pylock.toml files may produce less precise environment markers than uv.lock because the pylock format does not carry the resolver's internal per-Python-version splits. For example, a uv.lock-derived pinned requirement might read anyio==4.13.0; python_full_version >= "3.13" or (python_full_version >= "3.10" and python_full_version < "3.13") while the equivalent from a pylock.toml would be anyio==4.13.0; python_full_version >= "3.10".

Enabling the Plugin

The plugin requires the HATCH_PINNED_EXTRA_ENABLE environment variable to be set to a truthy value to activate (e.g. 1, true, yes, on). This design allows you to control when pinned dependencies are included:

# Build with pinned dependencies
HATCH_PINNED_EXTRA_ENABLE=1 uv build

# Update lockfile without constraints from pinned dependencies
uv lock --upgrade

This approach solves the circular dependency issue where pinned dependencies become constraints during uv lock --upgrade, preventing actual upgrades.

Release files for hatch-pinned-extra 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for hatch-pinned-extra 0.4.0
File Size Uploaded
hatch_pinned_extra-0.4.0.tar.gz 322.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for hatch-pinned-extra 0.4.0
File Interpreter ABI Platform
hatch_pinned_extra-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 335.2 kB

Release files / hatch_pinned_extra-0.4.0.tar.gz

Download URL hatch_pinned_extra-0.4.0.tar.gz
Size 322.3 kB
Tags Source
SHA-256 checksum
How to use checksums
7dd4a871e41321fe23c3a3e158c670502c7afdcb4b23079a758df708d6b83d73
BLAKE2b-256 checksum
How to use checksums
da5a8b9632e7f87ee49bce3f566f1529325cfaa0520ec97de5ad81bb289ef97d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 22, 2026.

Transparency log

Release files / hatch_pinned_extra-0.4.0-py3-none-any.whl

Download URL hatch_pinned_extra-0.4.0-py3-none-any.whl
Size 12.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8386c1b9934099784504bbe5ab4f0d99d3b56ef55bb6f17115971d0dc1cebc40
BLAKE2b-256 checksum
How to use checksums
5d0b1e1189debc743fa0e59b8af418c9b718f723a37b79860418d06a4302e7cc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 22, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

0.0.3

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page