PEP 665, take 2 -- A file format to list Python dependencies for reproducibility of an application

There also allowed to accept, so I’m not quite sure where your relative path concern comes from?

What do you directly gain? Possibly nothing if the community doesn’t adopt the PEP. But if it does then you get a standard on how to specify what to install.

But I would also urge you to not turn off hashes as that’s a security hole.

Yes, that would be possible. That’s effectively what the pin file proposal at A file format to list Python dependencies of an application without strict reproducibility guarantees is doing.

1 Like