Skip to content

Pin CI dependencies via uv lock without re-resolving pyproject.toml - #1929

Open
rosspeili wants to merge 2 commits into
quantumlib:mainfrom
rosspeili:fix/ci-pinned-dependencies-1843
Open

Pin CI dependencies via uv lock without re-resolving pyproject.toml#1929
rosspeili wants to merge 2 commits into
quantumlib:mainfrom
rosspeili:fix/ci-pinned-dependencies-1843

Conversation

@rosspeili

Copy link
Copy Markdown

Use --no-install-project plus editable --no-deps install in CI workflows, and --no-emit-project in export-from-uv-lock.sh, and also updated contributor and dev dependency docs to reflect the changes.

Fixes #1843.

Use --no-install-project plus editable --no-deps install in CI workflows, and --no-emit-project in export-from-uv-lock.sh. Update contributor and dev dependency docs accordingly.

Fixes quantumlib#1843.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the documentation and scripts for managing Python dependencies using uv. Specifically, it documents a two-step installation process (uv sync --no-install-project followed by uv pip install --no-deps -e .) across several files to ensure dependencies are strictly resolved from uv.lock. It also updates export-from-uv-lock.sh to use the --no-emit-project flag to prevent unpinned dependency resolution. I have no feedback to provide.

@mpharrigan mpharrigan left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks! some nits


* Always use `uv` for managing Python virtual environments and dependencies.
* Run Python commands, test suites, and linters via `uv run <command>` (e.g., `uv run check/pytest-quick` No newline at end of file
* Install the locked environment with `uv sync --frozen [--no-dev] [--group ...]

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is necessary for agents

Comment on lines +12 to +14
environment files, but they are no longer committed to the repository. The script uses
`--no-emit-project` so exported files omit qualtran and avoid pulling unpinned
dependencies from `pyproject.toml`.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

a little superfluous since the legacy requirements.txt never included the project itself and there's the blurb above

Comment thread CONTRIBUTING.md
Comment on lines +76 to +78
for how to install the locked environment and qualtran itself. In brief: use
`uv sync --frozen [--no-dev] [--group ...] --no-install-project` followed by
`uv pip install --no-deps -e .` so dependencies come only from `uv.lock`.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

again, I think this level of rigor is less important for day-to-day development work. I'd say using uv for development is recommended but not required

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

The CI will download and install non-pinned versions of dependencies

2 participants