tox-pin-deps
Run tox environments with strictly pinned dependencies using simple,
well-maintained tools (you're probably using already) with no project or code changes.
This plugin
uses jazzband/pip-tools' pip-compile
to freeze test and project dependencies, save a lock file per-testenv, and have
the locked deps installed, in the usual way via pip, on subsequent invocations.
This plugin supports both tox 3 and tox 4.
Usage
- Install
tox-pin-depsin the same environment astox. - Run
tox --pip-compileto pin deps for the defaultenvlist. - Commit files under
{toxinidir}/requirements/*.txtto version control. - Subsequent runs of
toxwill install from the lock file.
- Run
tox --pip-compile --pip-compile-opts \ --upgradeat any time to lock updated dependencies based on:depsnamed intox.inifor the environment- Project ("dist") dependencies named in
pyproject.toml,setup.cfg, orsetup.py.- Unless
skip_installorskipsdistis true
- Unless
- Run
tox --ignore-pinsto use the dependencies named indepswithout any special behavior. - Set
pip_compile_opts = --generate-hashesin thetestenvconfig to enable hash-checking mode. - To always use this plugin, specify
requires = tox-pin-depsin the[tox]section oftox.ini
Motivation
This project is designed to enable reproducible test (and runtime) environments without changing project structure or requiring the use of non-standard tools.
- Use the
depsandinstall_requires/[project.dependencies]that the project already specifies - Only need
pip-compileat lock time, not at runtime - Uses standard, well-supported tooling:
pipandvirtualenv
Why not...?
tox-constraints
- Requires the user to bring their own
constraints.txt constraints.txtis a newer concept in the python packaging, which may be unfamiliar.constraints.txtwith hash checking has had serveral issues since the 2020 pip resolver which make it unsuitable for this use.tox-constraintsdoes not support tox 4
poetry / tox-poetry
poetryis a newer tool that most python programmers haven't worked with.poetryis a runtime dependency for developing/testing projects.- Requirements are specified in non-standard
[tool.poetry]section ofpyproject.toml. - If a project isn't already using
poetry, adopting it for the sole purpose of controlling and pinning dependencies constitutes a significant change to development and packaging workflows. tox-poetrydoes not support tox 4
pipenv / tox-pipenv
pipenvis slow, non-standard, and does NOT work for dist projectspipenvis older, but still a tool that most python programmers haven't worked with.pipenvis a runtime dependency for developing/testing projects.- Requirements are specified in a non-standard
PipfileandPipfile.lock. - If a project isn't already using
pipenv, adopting it for the sole purpose of controlling and pinning dependencies constitutes a significant change to development and packaging workflows. tox-pipenvhas behavioral edge cases that make it uncomfortable to work with.tox-pipenvdoes not support tox 4
pip-compile (directly)
- Need scripts to handle updating / re-locking deps for multiple python versions
- Missing tox
depsintegration for locking test environments
pip-compile-multi
tox-pin-deps does essentially the same thing as pip-compile-multi, except using the
environment deps section as the layer on top of the project's setup.py
or pyproject.toml, instead of a separate text file.
If a project didn't want to use tox for managing test environments,
then pip-compile-multi is a great choice for achieving similar ends.
Metadata
Release files for tox-pin-deps 0.2.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| tox-pin-deps-0.2.2.tar.gz | 37.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| tox_pin_deps-0.2.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 50.0 kB
Release files / tox-pin-deps-0.2.2.tar.gz
| Download URL | tox-pin-deps-0.2.2.tar.gz |
|---|---|
| Size | 37.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
12b6c0b3bbf67cd6f34a448e5c6aedfff103496b23c0549f23d6bc45ecb90154
|
|
BLAKE2b-256 checksum How to use checksums |
1a209328da9d53da40e1517cdf19d07aae9d04bde5d334b87f356df5b90664be
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.2 CPython/3.11.1
|
Release files / tox_pin_deps-0.2.2-py3-none-any.whl
| Download URL | tox_pin_deps-0.2.2-py3-none-any.whl |
|---|---|
| Size | 12.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c7de4ea6533b0f75c2f80b7ec037f3986c6995c43e777caade32d1042c9ecb9d
|
|
BLAKE2b-256 checksum How to use checksums |
a16ea01f9f4b7ec38ef7e4ca1723a4d1c9c54d31d7f39df4782ff1c4d4bc9bdc
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.2 CPython/3.11.1
|