Skip to content

build: pin majors for stable dependencies - #51

Merged
rnovatorov merged 1 commit into
mainfrom
build/restyle-dependency-pins
Sep 23, 2026
Merged

rnovatorov merged 1 commit into
mainfrom
build/restyle-dependency-pins

Conversation

@rnovatorov

@rnovatorov rnovatorov commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

What

Applies the agreed pin convention to the runtime dependencies in pyproject.toml:

Pin the major version for packages at or above 1.0 (semver reserves breaking changes for major bumps). Pin the minor version only for 0.x packages (breaking changes arrive with minor bumps).

Dependency Before After Why
aiomqtt ==2.5.* ==2.* major ≥ 1 → major pin
dnspython ==2.8.* ==2.* major ≥ 1 → major pin
json-log-formatter ==1.1.* ==1.* major ≥ 1 → major pin
httpx ==0.28.* ==0.28.* (unchanged) 0.x → minor pin

Guarantees

  • No version changes: re-locked without upgrading; resolved versions are identical to main — aiomqtt 2.5.1, dnspython 2.8.0, json-log-formatter 1.1.1, httpx 0.28.1. The uv.lock diff is specifier text only.
  • Consumers gain freedom to co-install newer minor releases of the major-pinned packages.
  • Dev tooling untouched.

Actual dependency version updates are deferred to a separate PR.

Pin the major version for dependencies at or above 1.0, where
semver reserves breaking changes for major bumps; keep minor pins
only for 0.x packages, where breaking changes arrive with minor
bumps. Resolved versions are unchanged - this is a constraint
restyle only, verified against uv.lock.
@rnovatorov
rnovatorov force-pushed the build/restyle-dependency-pins branch from da7897f to a8c2658 Compare September 23, 2026 11:47
@rnovatorov rnovatorov changed the title build: pin majors for dependencies above v1 build: pin majors for stable dependencies Sep 23, 2026
@rnovatorov
rnovatorov merged commit 9aa4250 into main Sep 23, 2026
7 checks passed
@rnovatorov
rnovatorov deleted the build/restyle-dependency-pins branch September 23, 2026 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant