Skip to main content

vendoring

A command line tool, to simplify vendoring pure Python dependencies.

Why does this exist?

pip had a "home-grown" setup for vendoring dependencies. The invoke task grew in complexity to over 500 lines and, at some point, became extremely difficult to improve and maintain.

This tool is based off the overgrown invoke task, breaking it out into a dedicated codebase with the goal of making it more maintainable and reusable. This also enabled independent evolution of this codebase and better access to infrastructure (like dedicated CI) to ensure it keeps working properly.

Should I use it?

This tool has no stability promises -- it has only one intended user: pip. There may be unannounced changes to this codebase at any time, as long as the intended user (i.e. the pip project) is prepared for those changes.

As a general rule of thumb, if the project is going to be a PyPI package, it should not use this tool.

Many downstream redistributors have policies against this kind of bundling of dependencies, which means that they'll patch your software to debundle it. This can cause various kinds of issues, due to violations of assumptions being made about where the dependencies are available/which versions are being used. These issues result in difficult-to-debug errors, which are fairly difficult to communicate with end users.

pip is a very special case with a thorough rationale for vendoring/bundling dependencies with itself.

Contributing

Check the Contributing guide.

Release files for vendoring 1.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vendoring 1.4.0
File Size Uploaded
vendoring-1.4.0.tar.gz 24.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vendoring 1.4.0
File Interpreter ABI Platform
vendoring-1.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 43.9 kB

Release files / vendoring-1.4.0.tar.gz

Download URL vendoring-1.4.0.tar.gz
Size 24.8 kB
Tags Source
SHA-256 checksum
How to use checksums
48113adfb29db5e5051da823c083219567b9b3405859682cc04400a7743279d9
BLAKE2b-256 checksum
How to use checksums
55a62ad9ec99117eccf78ba6e69e7c904a3dc08ca2fba50e8869a3f02c1bc518
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.2

Release files / vendoring-1.4.0-py3-none-any.whl

Download URL vendoring-1.4.0-py3-none-any.whl
Size 19.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3a5b5c44bdec2683a94cd4c7c25bad556b38539cf316defca65948d76107eb30
BLAKE2b-256 checksum
How to use checksums
e3ba2fe43514bcf426888101c2968f3c821c6338afc122ccbbde6e29ee2a5036
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.2

Release history Release notifications | RSS feed

This release

1.4.0 This release

2 release files

1.3.0

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page