Re: Last rites: dev-python/pipenv and dependencies

Michał Górny <[email protected]>
Newsgroups gmane.linux.gentoo.devel
Organization Gentoo
Message-ID <[email protected]>
On Sun, 2026-04-05 at 15:41 +0300, Peter Volkov wrote:
> On Sat, Mar 28, 2026 at 1:27 PM Michał Górny <[email protected]> wrote:
> > # Michał Górny <[email protected]> (2026-03-28)
> > # pipenv relies very heavily on vendoring.  Every version bump requires
> > # a significant effort to unbundle and patch.  On top of that,
> > # the resulting packages pin to narrow dependency versions.  Includes
> > # dependencies with no other consumers.
> > # Removal on 2026-04-27.  Bug #971660.
> > dev-python/click-didyoumean
> > dev-python/dparse
> > dev-python/pipdeptree
> > dev-python/pipenv
> > dev-python/plette
> > dev-python/pythonfinder
> 
> I have a question regarding the planned removal of pipenv and related
> packages.
> 
> I see that a full de-vendor attempt was already made:
> https://github.com/gentoo/gentoo/pull/45214
> 
> While the result pins some dependency versions, this situation is not
> entirely unusual - a number of packages
> in the tree already require narrow dependency ranges. Would it be possible
> to reuse this work and maintain the
> package via proxy-maintainer instead of removing it entirely? It would be
> really sad to see this package removed
> while the upstream pipenv developer has expressed willingness to help
> maintain it in the Gentoo tree.

No.  This package was proxy-maintained, and it didn't work out.  Proxy
maintenance also requires a lot of review effort.  Combined with the
degree of complexity and frequent releases, this makes it untenable.

> Additionally, pipenv’s vendoring seems to be a deliberate upstream design
> choice to ensure the tool works independently
> of the system Python environment. In this specific case, would it make
> sense to reconsider the strict "no bundled libraries"
> policy, like Debian did (https://packages.debian.org/sid/all/pipenv/filelist
> )?

No.  That won't help at all.  It merely shuffles the effort from
unbundling to tracking security issues in the dozens of bundled
dependencies.

-- 
Best regards,
Michał Górny
signature.asc (application/pgp-signature, 293 B)
-----BEGIN PGP SIGNATURE-----

iKQEABYKAEwWIQQcFD0bEK7NPNmWHtiOMjR69AVa6AUCadJifhsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMiwyLDISHG1nb3JueUBnZW50b28ub3JnAAoJEI4yNHr0BVro
huUBAJpoEj0jrqIzvOxKe3/7lCqIjXrcko91rmfE/hQGA92PAP9HOSKWH6k7sYV5
Sm86a+avRB1KdQxMvOiUc8+O2sYgDg==
=Nftb
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.