# The purpose of a lock file

**URL:** <https://discuss.python.org/t/the-purpose-of-a-lock-file/38756>\
**Category:** Packaging\
**Created:** [November 14, 2023, 3:16pm UTC](https://discuss.python.org/t/the-purpose-of-a-lock-file/38756 "2023-11-14T15:16:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ofek](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/ofek/32/1033_2.png) [@ofek](https://discuss.python.org/u/ofek)\
**Post date:** [November 14, 2023, 3:16pm UTC](https://discuss.python.org/t/the-purpose-of-a-lock-file/38756/1 "2023-11-14T15:16:20Z")

</div>

> [@Storing requirements for tasks in pyproject.toml (drafting a PEP)](https://discuss.python.org/t/storing-requirements-for-tasks-in-pyproject-toml-drafting-a-pep/38486/16):
>
> Okay, but who else needs that information besides the devs, and how will they a) obtain and b) use it?

I think you are interpreting the purpose of a lock file differently. The purpose isn’t for development but rather applications (mostly). Let me give you a concrete use case: say you have a Python application that you wish to deploy, let’s say Instagram’s website for the purpose of this conversation. Then let’s say your only dependency is Django. The following describes how to define the environment in increasingly reproducible ways:

1. Depend on `django`
2. Depend on `django==x.y.z`
3. Same as before but now you resolve all transitive dependencies for your specific setup (Python version, OS, architecture, etc.) yielding precise version pins for the entire graph
4. Same as before but now you add info so as to specifically allow for targeting of other setups (whether that is specific setups or enough info for all setups)
5. Same as before but now rather than pins you store the precise URL which with the artifact is stored without support for source distributions (PEP 665)
6. Same as before but now source distributions are supported which requires in most cases downloading the artifact and invoking its chosen build backend to find out the metadata which then triggers a recursive loop where it could define dependencies that also happen to resolve to source distributions
7. Same as before but now also whenever a source distribution is encountered you resolve its build dependencies in the same way and store that data in a separate section

---

<div class="post-metadata">

**Author:** ![kknechtel](https://avatars.discourse-cdn.com/v4/letter/k/e47c2d/32.png) [@kknechtel](https://discuss.python.org/u/kknechtel)\
**Post date:** [November 14, 2023, 8:06pm UTC](https://discuss.python.org/t/the-purpose-of-a-lock-file/38756/2 "2023-11-14T20:06:51Z")

</div>

> [@ofek](#):
>
> say you have a Python application that you wish to deploy, let’s say Instagram’s website for the purpose of this conversation. Then let’s say your only dependency is Django. The following describes how to define the environment in increasingly reproducible ways:

To be clear, we mean “deploy” as in install the application for a specific other user (e.g. someone else in my organization)? And in this scenario it’s my responsibility to make that happen?

Because if arbitrary others are supposed to be able to use the application, the question is how they _get_ the lockfile, and how their installation process becomes aware of it. A wheel can’t do that, and it’s not clear to me how an sdist would do it.

---

<div class="post-metadata">

**Author:** ![jamestwebber](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/jamestwebber/32/12799_2.png) [@jamestwebber](https://discuss.python.org/u/jamestwebber)\
**Post date:** [November 14, 2023, 8:11pm UTC](https://discuss.python.org/t/the-purpose-of-a-lock-file/38756/3 "2023-11-14T20:11:43Z")

</div>

> [@kknechtel](#):
>
> To be clear, we mean “deploy” as in install the application for a specific other user (e.g. someone else in my organization)? And in this scenario it’s my responsibility to make that happen?

In the context of something like Instagram, I would interpret “deploy” to mean something like “distribute and start the application on an arbitrary number of virtual machines”. The security of the lockfile is not a problem–the whole operation is internal to the organization doing it. But they want it to be completely reproducible.

---

<div class="post-metadata">

**Author:** ![BrenBarn](https://avatars.discourse-cdn.com/v4/letter/b/74df32/32.png) [@BrenBarn](https://discuss.python.org/u/BrenBarn)\
**Post date:** [November 14, 2023, 9:37pm UTC](https://discuss.python.org/t/the-purpose-of-a-lock-file/38756/4 "2023-11-14T21:37:29Z")

</div>

> [@ofek](#):
>
> I think you are interpreting the purpose of a lock file differently. The purpose isn’t for development but rather applications (mostly).

I would say the purpose isn’t _just_ for development but _also_ for applications (as well as other things). For instance in the academic or data science realms there can be a desire to reproduce an environment to build on a previous analysis. And I also think that reproducing a dev environment is a valid use case. I like your list of “increasingly reproducible ways” and it lays out some of the situations that have to be considered, but I just want to point out that, at least for me, application deployment is something to be considered _in addition to_ other use cases for lock files, not instead of them.

---

<div class="post-metadata">

**Author:** ![ofek](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/ofek/32/1033_2.png) [@ofek](https://discuss.python.org/u/ofek)\
**Post date:** [November 14, 2023, 10:05pm UTC](https://discuss.python.org/t/the-purpose-of-a-lock-file/38756/5 "2023-11-14T22:05:43Z")

</div>

Yes that is a good point thank you. Lock files are for environments which applications, dev tools, etc. may use.
