← All tasks
pythonpypa/pip #9304Not a task: not reproduced

New Resolver unable to handle multiple versions of git dependencies

envgap__pypa__pip-9304

Original GitHub issue ↗Opened 2020-12-15

01 / FAILURE SIGNATURE

As reported upstream

ERROR: Cannot install -r requirements.txt (line 70), -r requirements.txt (line 71) and common 1.0.1 (from git+git://github.com/repoOrg/common@v1.0.1) because these package versions have conflicting dependencies.
Not a benchmark task.
  • No curated issue-specific recipe or verified environment fix is available.

02 / ENVIRONMENT RECIPE

Base commit
Not freshly verified
Manifest
requirements.txt
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

pypa/pip #9304 · read the original issue
**What did you want to do?**

New Resolver is unable to handle cases where private Git Dependencies are shared but do not match "version" (i.e. Branch, Tag, Commit). This not only makes repo management much more tedious but also makes feature testing in repos much harder or impossible. 



For example if we have: 

* a repo with common shared code called **common**

* a repo with logic to operate a particular service called **service**

* a repo for a app called **app**



Requirements.txt in **service** calls:

```

commoncode @ git+git://github.com/repoOrg/common.git@v1.0.0

```

While requirements.txt in **app** calls:

```

commoncode @ git+git://github.com/repoOrg/common.git@v1.0.1

service @ git+git://github.com/repoOrg/service.get@v2.1.0

```



**Output**



```

ERROR: Cannot install -r requirements.txt (line 70), -r requirements.txt (line 71) and common 1.0.1 (from git+git://github.com/repoOrg/common@v1.0.1) because these package versions have conflicting dependencies.



The conflict is caused by:

    The user requested common 1.0.1 (from git+git://github.com/repoOrg/common@v1.0.1)

    service 2.1.0 depends on common 1.0.0 (from git+git://github.com/repoOrg/common@v1.0.0)

```



**Additional information**

I have spent a considerable amount of time reading though available documentation and have not been able to identify a solution for this use case (such as version ranging). Am I missing something? Ideally there would be some way to specify compatible range in **service**, with concrete versions specified in **app**.
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

conflict
Label rules and the text that matched
[
  {
    "category": "conflict",
    "rule": "signature.incompatible_declared_requirements",
    "source": "failure_signature",
    "excerpt": "ERROR: Cannot install -r requirements.txt (line 70), -r requirements.txt (line 71) and common 1.0.1 (from git+git://github.com/repoOrg/common@v1.0.1) because these package versions have conflicting dependencies."
  }
]

Issue-specific recipe and runtime smoke command require review against the complete issue and repository.

Legacy already_works is install-only; proposed control still requires runtime verification.