hatch-pinned-extra
Hatch plugin that adds a packaging extra to the wheel metadata with pinned dependencies from uv.lock.
Usage
# pyproject.toml
[build-system]
requires = [
"hatchling",
"hatch-pinned-extra>=0.0.1,<0.1.0",
]
build-backend = "hatchling.build"
[tool.hatch.metadata.hooks.pinned_extra]
name = "pinned"
If your package doesn't have any optional dependencies already, you will need to mark them as dynamic:
# pyproject.toml
[project]
dynamic = [
"optional-dependencies",
]
Reading pinned dependencies from pylock.toml file
To use a pylock.toml file instead of uv.lock, set lockfile to the file path:
[tool.hatch.metadata.hooks.pinned_extra]
lockfile = "pylock.prod.toml"
[!NOTE] The
pinnedwill contain ALL the dependencies inpylock.toml, so you'll want to make sure it includes only runtime or relevant dependencies, e.g. by generating it with the--no-devflag.
[!NOTE]
pylock.tomlfiles may produce less precise environment markers thanuv.lockbecause the pylock format does not carry the resolver's internal per-Python-version splits. For example, auv.lock-derived pinned requirement might readanyio==4.13.0; python_full_version >= "3.13" or (python_full_version >= "3.10" and python_full_version < "3.13")while the equivalent from apylock.tomlwould beanyio==4.13.0; python_full_version >= "3.10".
Enabling the Plugin
The plugin requires the HATCH_PINNED_EXTRA_ENABLE environment variable to be set to a truthy value to activate (e.g. 1, true, yes, on). This design allows you to control when pinned dependencies are included:
# Build with pinned dependencies
HATCH_PINNED_EXTRA_ENABLE=1 uv build
# Update lockfile without constraints from pinned dependencies
uv lock --upgrade
This approach solves the circular dependency issue where pinned dependencies become constraints during uv lock --upgrade, preventing actual upgrades.
Release files for hatch-pinned-extra 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| hatch_pinned_extra-0.4.0.tar.gz | 322.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| hatch_pinned_extra-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 335.2 kB
Release files / hatch_pinned_extra-0.4.0.tar.gz
| Download URL | hatch_pinned_extra-0.4.0.tar.gz |
|---|---|
| Size | 322.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7dd4a871e41321fe23c3a3e158c670502c7afdcb4b23079a758df708d6b83d73
|
|
BLAKE2b-256 checksum How to use checksums |
da5a8b9632e7f87ee49bce3f566f1529325cfaa0520ec97de5ad81bb289ef97d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 22, 2026.
Transparency logRelease files / hatch_pinned_extra-0.4.0-py3-none-any.whl
| Download URL | hatch_pinned_extra-0.4.0-py3-none-any.whl |
|---|---|
| Size | 12.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8386c1b9934099784504bbe5ab4f0d99d3b56ef55bb6f17115971d0dc1cebc40
|
|
BLAKE2b-256 checksum How to use checksums |
5d0b1e1189debc743fa0e59b8af418c9b718f723a37b79860418d06a4302e7cc
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 22, 2026.
Transparency log