Skip to main content

Check for differences between requirements.txt files and your environment.

Project description

https://img.shields.io/github/actions/workflow/status/adamchainz/pip-lock/main.yml.svg?branch=main&style=for-the-badge https://img.shields.io/pypi/v/pip-lock.svg?style=for-the-badge https://img.shields.io/badge/code%20style-black-000000.svg?style=for-the-badge pre-commit

Check for differences between requirements.txt files and the current environment.


Working on a Django project? Check out my book Boost Your Django DX which covers many ways to improve your development experience.


Installation

Install with python -m pip install pip-lock.

Python 3.9 to 3.14 supported.

Example usage

Call pip_lock.check_requirements() at your application startup to verify that the current virtual environment matches your requirements file. This gives instant feedback to developers changing branches etc. who would otherwise experience unexpected behaviour or errors due to out of sync requirements.

In a Django project, it makes sense to add the check inside the manage.py file, which is the project’s main entrypoint. You can add a call to pip_lock.check_requirements() after the first import of Django. For example:

#!/usr/bin/env python
import os
import sys
from pathlib import Path


def main():
    os.environ.setdefault("DJANGO_SETTINGS_MODULE", "example.settings")

    try:
        from django.core.management import execute_from_command_line
    except ImportError as exc:
        raise ImportError(
            "Couldn't import Django. Are you sure it's installed and "
            "available on your PYTHONPATH environment variable? Did you "
            "forget to activate a virtual environment?"
        ) from exc

    try:
        import pip_lock
    except ImportError:
        raise ImportError(
            "Couldn't import pip-lock. Are you on the right virtualenv and up "
            + "to date?"
        )

    requirements_path = str(Path(__file__).parent / "requirements.txt")
    pip_lock.check_requirements(
        requirements_path,
        post_text="\nRun the following:\n\npython -m pip install -r requirements.txt\n",
    )

    execute_from_command_line(sys.argv)


if __name__ == "__main__":
    main()

API

check_requirements(requirements_file_path: str, post_text: str='') -> None

Exit with exit code 1 and output to stderr if there are mismatches between the environment and requirements file.

requirements_file_path is the path to the requirements.txt file - we recommend using an absolute file path.

post_text is optional text which is displayed after the stderr message. This can be used to display instructions on how to update the requirements.

Example:

check_requirements(
    "requirements.txt",
    post_text="\nRun the following on your host machine: \n\n    vagrant provision\n",
)
There are requirement mismatches with requirements.txt:
    * Package Django has version 1.9.10 but you have version 1.9.0 installed.
    * Package requests has version 2.11.1 but you have version 2.11.0 installed.
    * Package requests-oauthlib is in requirements.txt but not in virtualenv

Run the following on your host machine:

    vagrant provision

get_mismatches(requirements_file_path: str) -> dict[str, tuple[str, str | None]]

Return a dictionary of package names to tuples of (expected_version, actual_version) for mismatched packages.

requirements_file_path is the path to the requirements.txt file - we recommend using an absolute file path.

Example:

>>> get_mismatches("requirements.txt")
{'django': ('1.10.2', '1.9.0'), 'requests': ('2.11.1', '2.9.2'), 'request-oauthlib': ('0.7.0', None)}

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pip_lock-2.13.0.tar.gz (7.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pip_lock-2.13.0-py3-none-any.whl (5.4 kB view details)

Uploaded Python 3

File details

Details for the file pip_lock-2.13.0.tar.gz.

File metadata

  • Download URL: pip_lock-2.13.0.tar.gz
  • Upload date:
  • Size: 7.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for pip_lock-2.13.0.tar.gz
Algorithm Hash digest
SHA256 9c51bf7e696c1e029fde47b63a9272186ae2515954964e8cd12dddff1e87f706
MD5 438be1917d866cb0cd04d84e0e852af9
BLAKE2b-256 e1bd94abe7b50bea71d09befa743dfe04fdf155db48219af784fea18e89415a9

See more details on using hashes here.

Provenance

The following attestation bundles were made for pip_lock-2.13.0.tar.gz:

Publisher: main.yml on adamchainz/pip-lock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pip_lock-2.13.0-py3-none-any.whl.

File metadata

  • Download URL: pip_lock-2.13.0-py3-none-any.whl
  • Upload date:
  • Size: 5.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for pip_lock-2.13.0-py3-none-any.whl
Algorithm Hash digest
SHA256 a48d4e08ab6d6779b5f5af3d71183f05b5c528e3acdaaf93d1af1c5012f7dbed
MD5 1694d87f00703413d4dcd05c99777245
BLAKE2b-256 556f26b227fc45ac915b5210e63e0b483e4892db1a9d0e95fa13851f8261f5f6

See more details on using hashes here.

Provenance

The following attestation bundles were made for pip_lock-2.13.0-py3-none-any.whl:

Publisher: main.yml on adamchainz/pip-lock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page