← All tasks
pythonpsf/black #2774Reported task

Black specifies a requirement for click>=7.1.2 but actually requires click>=8.0

envgap__psf__black-2774

01 / FAILURE SIGNATURE

Captured in a clean container

ImportError: cannot import name 'ParameterSource' from 'click.core' (/usr/local/lib/python3.10/dist-packages/click/core.py)

02 / ENVIRONMENT RECIPE

Base commit
565f9c92b79a72deb7faec7503749979c791b6e1
Manifest
setup.py
Reproduce
git config --global --add safe.directory /work && python3 -m pip install setuptools==51.1.1 setuptools-scm==5.0.1 wheel==0.36.2 && python3 -m pip install click==7.1.2 && python3 -m pip install --no-build-isolation . && python3 -c "import black; assert black.format_str('x=1', mode=black.FileMode()) == 'x = 1\n'; print(black.parse_pyproject_toml('pyproject.toml')['line_length'])"
Run under trace
python3 -c "import black; assert black.format_str('x=1', mode=black.FileMode()) == 'x = 1\n'; print(black.parse_pyproject_toml('pyproject.toml')['line_length'])"
Reference environment fix used for admission
diff --git a/setup.py b/setup.py
index 57632498..9ac50777 100644
--- a/setup.py
+++ b/setup.py
@@ -97,7 +97,7 @@ setup(
     python_requires=">=3.6.2",
     zip_safe=False,
     install_requires=[
-        "click>=7.1.2",
+        "click==8.0.3",
         "platformdirs>=2",
         "tomli>=1.1.0",
         "typed-ast>=1.4.2; python_version < '3.8' and implementation_name == 'cpython'",

03 / ORIGINAL ISSUE TEXT

psf/black #2774 · read the original issue
**Describe the bug**



Installing `black` from the head of the `main` branch and `click<8.0` results in a stack trace whenever the tool is run.



**To Reproduce**



```bash

python3 -m venv black-click-compat-bug

source black-click-compat-bug/bin/activate

python -m pip install \

  "click<8.0" \

  git+https://github.com/psf/black

black --help

```



Resulting traceback:



```

Traceback (most recent call last):

  File "/home/enpaul/black-click-compat-bug/bin/black", line 5, in <module>

    from black import patched_main

  File "/home/enpaul/black-click-compat-bug/lib64/python3.10/site-packages/black/__init__.py", line 34, in <module>

    from click.core import ParameterSource

ImportError: cannot import name 'ParameterSource' from 'click.core' (/home/enpaul/black-click-compat-bug/lib64/python3.10/site-packages/click/core.py)

```



**Expected behavior**



Black should specify a requirement for `click>=8.0.0` ([actual specification](https://github.com/psf/black/blob/main/setup.py#L100) is for `>=7.1.2`)



**Environment**



<!-- Please complete the following information: -->



- Black's version: `21.12b1.dev40+g565f9c9`

- OS: Linux (Fedora 35)

- Python: `Python 3.10.1`

Continue on GitHub ↗

04 / LABELS

Labels checked by running the task · assistant reviewed

misspecificationsecurity
Label rules and the text that matched
[
  {
    "category": "misspecification",
    "rule": "diff.changes_existing_manifest_line",
    "source": "manifest_diff:setup.py",
    "excerpt": "-        \"click>=7.1.2\",\n+        \"click==8.0.3\","
  },
  {
    "category": "security",
    "rule": "audit.nonempty_security_flags",
    "source": "security_flags",
    "excerpt": "[\"unpinned\"]"
  }
]

Historical install-only results are not EnvGap validation.

Bootstrap commands are explicit benchmark prerequisites executed identically before original and gold manifests; they prevent unrelated modern build-tool/API drift.

Current registry downloads are permitted in these preparation checks. Unpinned transitives are not historically reconstructed.

Gold was verified in a fresh envgap-python-eval container; runtime tracing is scored separately by envgap eval.

Preparation uses current registries. Historical package availability is not enforced here; execution metadata records this limitation separately from the oracle's date-bounding policy.