# How to build and deploy applications with locked transitive dependencies?

**URL:** <https://discuss.python.org/t/how-to-build-and-deploy-applications-with-locked-transitive-dependencies/96675>\
**Category:** Python Help\
**Tags:** packaging-help\
**Created:** [June 25, 2025, 2:53pm UTC](https://discuss.python.org/t/how-to-build-and-deploy-applications-with-locked-transitive-dependencies/96675 "2025-06-25T14:53:30Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![stachel](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/stachel/32/28809_2.png) [@stachel](https://discuss.python.org/u/stachel)\
**Post date:** [June 25, 2025, 5:12pm UTC](https://discuss.python.org/t/how-to-build-and-deploy-applications-with-locked-transitive-dependencies/96675/4 "2025-06-25T17:12:41Z")

</div>

> [@steve.dower](#):
>
> If you _really_ care, then you should vendor all your dependencies and distribute a complete package.

I don’t particularly see the benefits of using vendor packages instead of fetching them from a private package index, pinning all transitive dependencies and saving the hashes.

> [@steve.dower](#):
>
> [Python-standalone-builds](https://gregoryszorc.com/docs/python-build-standalone/main/) is a helpful project for non-Windows OS here, as they can give you pre-built CPython packages that are relocatable. Add in your app and your dependencies and you should be pretty close to a redistributable, reproducible package for your app.

I’m familiar with that project, but that’s not where the problem I’m trying to solve lies.

> [@steve.dower](#):
>
> Requirements files (and lock files) are really for consumers of your app, not for deployments. Docker works because it essentially vendors everything before you deploy - you can do the same without Docker, you just need to get familiar with how your target operating systems resolve paths.

Who exactly do you mean by “consumers” then? I’m building an application and distributing it as a wheel to internal end users. They install the application (deploy it on their servers), and I want to ensure that they install it with exactly the same dependencies (i.e., the same versions of Python packages) that I used during testing. Based on [another discussion about lock files](https://discuss.python.org/t/the-purpose-of-a-lock-file/38756), it seems that lock files are designed specifically for this purpose.

---

_[View the full topic](https://discuss.python.org/t/how-to-build-and-deploy-applications-with-locked-transitive-dependencies/96675)._
