Curious what others have to say, but my go to is to have a requirements.in with direct packages I need for the project, and then run pip-compile to generate all the dependencies with their exact version at the time so that deployments are repeatable. This works well for deployment, but if I were writing a library for others to use, I think you put the direct dependencies in setup.py
Well if the requirements.txt is pinned to a specific version of a dependency of a dependency, you might not know or really care why that’s set. But then this becomes a nightmare and dependency hell laterif you want a newer version of some package, and that newer version requires a bunch of newer packages and loses the others. At that point you probably will toss your old file and start a new one from scratch piecing together all the requirements with like pip freeze in a new virtual environment.
Sure you could omit the versions, but then everytime you deploy, you don’t know what you’re going to get and a deployment today would be very different next week with a whole bunch of different versions of dependencies.
I don’t quite understand that. I did some research, and I read that the requirements.txt is somehow generated from requirements.in. But what is the difference between the two files then? Could you give me an example of what a requirements.in file would look like?
Yes exactly, like if I know my app needs the requests library, I will just put that in requirements.in but after compile requirements.txt will include the exact version of requests and every version of each dependency. So that every time pip install is run, all dependencies are always the same despite what happens upstream
It’s right, you shouldn’t be using requirements.txt in 2026
What should I use instead? pyproject.toml?
I am pretty new to Python so I’m not very familiar with the ecosystem yet…
It’s not important what you should be doing, just that requirements.txt ‘No’
I’m a dinosaur still using vim but I’d consider switching IDE’s if they had this much snarky behavior. Lol
yes, and give
uva tryhttps://docs.astral.sh/uv/getting-started/installation/
uv init+ project management commandsuv add,uv remove,uv sync,uv run my_spaghetti.py, …you probably don’t need
piporuv pipcommandsand here’s how to use it in docker
https://docs.astral.sh/uv/guides/integration/docker/
UV’s parent company was purchased by OpenAI.
I recommend Poetry instead.
I used poetry for years before uv, but uv is just a better tool. If openai enshittifies it, I have no doubt it’ll be forked instantly.
Think about what they get by controlling a popular package manager. Think about what you give them.
You will not feel the consequences directly.
what I do feel is how slow poetry is for resolving dependencies
That looks really convenient, especially when installing and switching Python versions. I’ll keep that in mind. Thanks!
Curious what others have to say, but my go to is to have a
requirements.inwith direct packages I need for the project, and then runpip-compileto generate all the dependencies with their exact version at the time so that deployments are repeatable. This works well for deployment, but if I were writing a library for others to use, I think you put the direct dependencies insetup.pyWhy not put all dependencies and all with versions. I do that
Well if the
requirements.txtis pinned to a specific version of a dependency of a dependency, you might not know or really care why that’s set. But then this becomes a nightmare and dependency hell laterif you want a newer version of some package, and that newer version requires a bunch of newer packages and loses the others. At that point you probably will toss your old file and start a new one from scratch piecing together all the requirements with likepip freezein a new virtual environment.Sure you could omit the versions, but then everytime you deploy, you don’t know what you’re going to get and a deployment today would be very different next week with a whole bunch of different versions of dependencies.
I don’t quite understand that. I did some research, and I read that the requirements.txt is somehow generated from requirements.in. But what is the difference between the two files then? Could you give me an example of what a requirements.in file would look like?
Thank you!
Please use a pyproject.toml file for both project setup and dependency management. It actually is standardized now in PEPs.
uv is a great tool, now comes with a build tool as well. It has become a de-facto standard.
Ohhh now I get it. It’s basically like
package.jsonandpackage-lock.jsonin node, but for Python.It’s a bit strange to me that this isn’t the default in Python…
Yes exactly, like if I know my app needs the requests library, I will just put that in
requirements.inbut after compilerequirements.txtwill include the exact version of requests and every version of each dependency. So that every time pip install is run, all dependencies are always the same despite what happens upstream