Skip to main content

A command line tool, to simplify vendoring pure Python dependencies.

Project description

vendoring

A command line tool, to simplify vendoring pure Python dependencies.

Why does this exist?

pip had a "home-grown" setup for vendoring dependencies. The invoke task grew in complexity to over 500 lines and, at some point, became extremely difficult to improve and maintain.

This tool is based off the overgrown invoke task, breaking it out into a dedicated codebase with the goal of making it more maintainable and reusable. This also enabled independent evolution of this codebase and better access to infrastructure (like dedicated CI) to ensure it keeps working properly.

Should I use it?

This tool has no stability promises -- it has only one intended user: pip. There may be unannounced changes to this codebase at any time, as long as the intended user (i.e. the pip project) is prepared for those changes.

As a general rule of thumb, if the project is going to be a PyPI package, it should not use this tool.

Many downstream redistributors have policies against this kind of bundling of dependencies, which means that they'll patch your software to debundle it. This can cause various kinds of issues, due to violations of assumptions being made about where the dependencies are available/which versions are being used. These issues result in difficult-to-debug errors, which are fairly difficult to communicate with end users.

pip is a very special case with a thorough rationale for vendoring/bundling dependencies with itself.

Contributing

Check the Contributing guide.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vendoring-1.2.0.tar.gz (21.5 kB view details)

Uploaded Source

Built Distribution

vendoring-1.2.0-py2.py3-none-any.whl (15.4 kB view details)

Uploaded Python 2 Python 3

File details

Details for the file vendoring-1.2.0.tar.gz.

File metadata

  • Download URL: vendoring-1.2.0.tar.gz
  • Upload date:
  • Size: 21.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.4.2 importlib_metadata/4.8.1 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.6

File hashes

Hashes for vendoring-1.2.0.tar.gz
Algorithm Hash digest
SHA256 6340a84bf542222c96f22ebc3cb87e4d86932dc04bc8d446e38285594702c00e
MD5 1ff259e92000390feacd35686384605e
BLAKE2b-256 dabdb92bbd4a5e6fb52c05af4fdef86726e05c38e5a36313716cf37e38183c65

See more details on using hashes here.

File details

Details for the file vendoring-1.2.0-py2.py3-none-any.whl.

File metadata

  • Download URL: vendoring-1.2.0-py2.py3-none-any.whl
  • Upload date:
  • Size: 15.4 kB
  • Tags: Python 2, Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.4.2 importlib_metadata/4.8.1 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.6

File hashes

Hashes for vendoring-1.2.0-py2.py3-none-any.whl
Algorithm Hash digest
SHA256 35b5fca683264e69e851a7580bb6a6f9848af024ffc8382ed5491bcfa55750c6
MD5 a97f7f74700be564a9f8ad1fa33b5e1f
BLAKE2b-256 12f890e946f50210c6f9d08d636b83fc30dea0c4ca6fb4abc342db5c8b159e6b

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page