#python #pep #requirements #specifier #marker #validation #better

pep508_rs

A library for python dependency specifiers, better known as PEP 508

19 releases (7 breaking)

0.9.1 Oct 30, 2024
0.8.1 Oct 29, 2024
0.6.1 Jul 30, 2024
0.4.2 Feb 18, 2024
0.1.1 Mar 29, 2023

#340 in Web programming

Download history 18694/week @ 2024-07-30 17749/week @ 2024-08-06 18450/week @ 2024-08-13 22026/week @ 2024-08-20 21473/week @ 2024-08-27 25006/week @ 2024-09-03 21976/week @ 2024-09-10 20619/week @ 2024-09-17 23290/week @ 2024-09-24 18860/week @ 2024-10-01 22805/week @ 2024-10-08 24442/week @ 2024-10-15 18678/week @ 2024-10-22 19270/week @ 2024-10-29 19829/week @ 2024-11-05 18913/week @ 2024-11-12

80,500 downloads per month
Used in 10 crates (7 directly)

Apache-2.0 OR BSD-2-Clause

335KB
7K SLoC

Dependency specifiers (PEP 508) in Rust

Crates.io PyPI

A library for python dependency specifiers, better known as PEP 508.

Usage

In Rust

use std::str::FromStr;
use pep508_rs::Requirement;

let marker = r#"requests [security,tests] >= 2.8.1, == 2.8.* ; python_version > "3.8""#;
let dependency_specification = Requirement::from_str(marker).unwrap();
assert_eq!(dependency_specification.name, "requests");
assert_eq!(dependency_specification.extras, Some(vec!["security".to_string(), "tests".to_string()]));

Markers

Markers allow you to install dependencies only in specific environments (python version, operating system, architecture, etc.) or when a specific feature is activated. E.g. you can say importlib-metadata ; python_version < "3.8" or itsdangerous (>=1.1.0) ; extra == 'security'. Unfortunately, the marker grammar has some oversights (e.g. https://github.com/pypa/packaging.python.org/pull/1181) and the design of comparisons (PEP 440 comparisons with lexicographic fallback) leads to confusing outcomes. This implementation tries to carefully validate everything and emit warnings whenever bogus comparisons with unintended semantics are made.

Dependencies

~7–10MB
~167K SLoC