aider/requirements.txt
Claudia Pellegrino 31c4198cee
fix: let fewer conflicts occur across requirements
**tl;dr** Introduce a common umbrella constraints file (that works
across requirement extras) to avoid package version conflicts and
to reduce the need for manual pinning in `*.in` files.

Previously, spurious package version conflicts could sometimes occur
across requirements for `pip install -e .`, `pip install -e .[help]`,
`pip install -e .[playwright]`, and so on. Here’s why:

- There are five different requirement configs: the set of base
  requirements (`requirements.txt`) and four additional requirement sets\
  (aka "extras"): `dev`, `help`, `browser`, and `playwright`.

- Each of those five configurations spans its own tree of dependencies
  [1]. Those five trees can slightly overlap. (For example, `greenlet`
  is a transitive requirement for both the `help` and `playwright`
  trees, respectively.)

- If you want to resolve those dependency trees so you get concrete
  version numbers, you can’t just look at each tree independently.
  This is because when trees overlap, they sometimes pull in the same
  package for different reasons, respectively, and maybe with different
  version constraints.
  For example, the `help` tree pulls in `greenlet`, because `sqlalchemy`
  requires it. At the same time, the `playwright` tree also pulls in
  `greenlet` because it’s needed by the `playwright` package.
  Resolving those constraints strictly individually (i.e., per tree) is
  usually a mistake. It may work for a while, but occasionally you’re
  going to end up with two conflicting versions of the same package.

To prevent those version conflicts from occurring, the five
`pip-compile` invocations were designed as a chain.
The process starts at the smallest tree (i.e., the base
`requirements.in` file). It calculates the version numbers for the tree,
remembers the result, and feeds it into the calculation of the next
tree.

The chain design somewhat helped mitigate conflicts, but not always.
The reason for that is that the chain works like a greedy algorithm:
once a decision has been made for a given package in a tree, that
decision is immediately final, and the compilation process isn’t allowed
to go back and change that decision if it learns new information.
New information comes in all the time, because larger trees usually have
more complex constraints than smaller trees, and the process visits
larger trees later, facing additional constraints as it hops from tree
to tree. Sometimes it bumps into a new constraint against a package for
which it has already made a decision earlier (i.e., it has pinned the
concrete version number in the `requirements*.txt` file of an earlier
tree).

That’s why the greedy chain-based method, even though it mostly works
just fine, can never avoid spurious conflicts entirely.
To help mitigate those conflicts, pinning entries were manually added to
`requirements.in` files on a case-by-case basis as conflicts occurred.
Those entries can make the file difficult to reason about, and they must
be kept in sync manually as packages get upgraded. That’s a maintenance
burden.

Turning the chain into an umbrella may help. Instead of hopping from
tree to tree, look at the entire forest at once, calculate all the
concrete version numbers for all trees in one fell swoop, and save the
results in a common, all-encompassing umbrella file.

Armed with the umbrella file (called `common-constraints.txt`), visit
each tree (in any order – it no longer matters) and feed it just the
umbrella file as a constraint, along with its own `*.in` file as the
input.
Chaining is no longer necessary, because the umbrella file already
contains all version constraints for all the packages one tree could
possibly need, and then some.

This technique should reduce manual pinning inside `*.in` files, and
makes sure that computed version numbers no longer contradict each other
across trees.

[1]: From a graph theory point of view, I’m being blatantly incorrect
here; those dependency graphs are usually not trees, because they have
cycles. I’m still going to call them "trees" for the sake of this
discussion, because the word "tree" feels less abstract and intimidating
and hopefully more relatable.
2025-03-02 02:50:03 +01:00

418 lines
10 KiB
Text

#
# This file is autogenerated by pip-compile with Python 3.12
# by the following command:
#
# pip-compile --allow-unsafe --constraint=requirements/common-constraints.txt --output-file=requirements.txt requirements/requirements.in
#
aiohappyeyeballs==2.4.6
# via
# -c requirements/common-constraints.txt
# aiohttp
aiohttp==3.11.13
# via
# -c requirements/common-constraints.txt
# litellm
aiosignal==1.3.2
# via
# -c requirements/common-constraints.txt
# aiohttp
annotated-types==0.7.0
# via
# -c requirements/common-constraints.txt
# pydantic
anyio==4.8.0
# via
# -c requirements/common-constraints.txt
# httpx
# openai
# watchfiles
attrs==25.1.0
# via
# -c requirements/common-constraints.txt
# aiohttp
# jsonschema
# referencing
backoff==2.2.1
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
# posthog
beautifulsoup4==4.13.3
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
certifi==2025.1.31
# via
# -c requirements/common-constraints.txt
# httpcore
# httpx
# requests
cffi==1.17.1
# via
# -c requirements/common-constraints.txt
# sounddevice
# soundfile
charset-normalizer==3.4.1
# via
# -c requirements/common-constraints.txt
# requests
click==8.1.8
# via
# -c requirements/common-constraints.txt
# litellm
configargparse==1.7
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
diff-match-patch==20241021
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
diskcache==5.6.3
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
distro==1.9.0
# via
# -c requirements/common-constraints.txt
# openai
# posthog
filelock==3.17.0
# via
# -c requirements/common-constraints.txt
# huggingface-hub
flake8==7.1.2
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
frozenlist==1.5.0
# via
# -c requirements/common-constraints.txt
# aiohttp
# aiosignal
fsspec==2025.2.0
# via
# -c requirements/common-constraints.txt
# huggingface-hub
gitdb==4.0.12
# via
# -c requirements/common-constraints.txt
# gitpython
gitpython==3.1.44
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
grep-ast==0.6.1
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
h11==0.14.0
# via
# -c requirements/common-constraints.txt
# httpcore
httpcore==1.0.7
# via
# -c requirements/common-constraints.txt
# httpx
httpx==0.28.1
# via
# -c requirements/common-constraints.txt
# litellm
# openai
huggingface-hub==0.29.1
# via
# -c requirements/common-constraints.txt
# tokenizers
idna==3.10
# via
# -c requirements/common-constraints.txt
# anyio
# httpx
# requests
# yarl
importlib-metadata==7.2.1
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
# litellm
importlib-resources==6.5.2
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
jinja2==3.1.5
# via
# -c requirements/common-constraints.txt
# litellm
jiter==0.8.2
# via
# -c requirements/common-constraints.txt
# openai
json5==0.10.0
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
jsonschema==4.23.0
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
# litellm
jsonschema-specifications==2024.10.1
# via
# -c requirements/common-constraints.txt
# jsonschema
litellm==1.61.16
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
markdown-it-py==3.0.0
# via
# -c requirements/common-constraints.txt
# rich
markupsafe==3.0.2
# via
# -c requirements/common-constraints.txt
# jinja2
mccabe==0.7.0
# via
# -c requirements/common-constraints.txt
# flake8
mdurl==0.1.2
# via
# -c requirements/common-constraints.txt
# markdown-it-py
mixpanel==4.10.1
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
monotonic==1.6
# via
# -c requirements/common-constraints.txt
# posthog
multidict==6.1.0
# via
# -c requirements/common-constraints.txt
# aiohttp
# yarl
networkx==3.2.1
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
numpy==1.26.4
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
# scipy
# soundfile
openai==1.64.0
# via
# -c requirements/common-constraints.txt
# litellm
packaging==24.2
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
# huggingface-hub
pathspec==0.12.1
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
# grep-ast
pexpect==4.9.0
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
pillow==10.4.0
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
posthog==3.16.0
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
prompt-toolkit==3.0.50
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
propcache==0.3.0
# via
# -c requirements/common-constraints.txt
# aiohttp
# yarl
psutil==7.0.0
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
ptyprocess==0.7.0
# via
# -c requirements/common-constraints.txt
# pexpect
pycodestyle==2.12.1
# via
# -c requirements/common-constraints.txt
# flake8
pycparser==2.22
# via
# -c requirements/common-constraints.txt
# cffi
pydantic==2.10.6
# via
# -c requirements/common-constraints.txt
# litellm
# openai
pydantic-core==2.27.2
# via
# -c requirements/common-constraints.txt
# pydantic
pydub==0.25.1
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
pyflakes==3.2.0
# via
# -c requirements/common-constraints.txt
# flake8
pygments==2.19.1
# via
# -c requirements/common-constraints.txt
# rich
pypandoc==1.15
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
pyperclip==1.9.0
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
python-dateutil==2.9.0.post0
# via
# -c requirements/common-constraints.txt
# posthog
python-dotenv==1.0.1
# via
# -c requirements/common-constraints.txt
# litellm
pyyaml==6.0.2
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
# huggingface-hub
referencing==0.36.2
# via
# -c requirements/common-constraints.txt
# jsonschema
# jsonschema-specifications
regex==2024.11.6
# via
# -c requirements/common-constraints.txt
# tiktoken
requests==2.32.3
# via
# -c requirements/common-constraints.txt
# huggingface-hub
# mixpanel
# posthog
# tiktoken
rich==13.9.4
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
rpds-py==0.23.1
# via
# -c requirements/common-constraints.txt
# jsonschema
# referencing
scipy==1.13.1
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
six==1.17.0
# via
# -c requirements/common-constraints.txt
# mixpanel
# posthog
# python-dateutil
smmap==5.0.2
# via
# -c requirements/common-constraints.txt
# gitdb
sniffio==1.3.1
# via
# -c requirements/common-constraints.txt
# anyio
# openai
socksio==1.0.0
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
sounddevice==0.5.1
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
soundfile==0.13.1
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
soupsieve==2.6
# via
# -c requirements/common-constraints.txt
# beautifulsoup4
tiktoken==0.9.0
# via
# -c requirements/common-constraints.txt
# litellm
tokenizers==0.19.1
# via
# -c requirements/common-constraints.txt
# litellm
tqdm==4.67.1
# via
# -c requirements/common-constraints.txt
# huggingface-hub
# openai
tree-sitter==0.21.3
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
# grep-ast
# tree-sitter-languages
tree-sitter-languages==1.10.2
# via
# -c requirements/common-constraints.txt
# grep-ast
typing-extensions==4.12.2
# via
# -c requirements/common-constraints.txt
# anyio
# beautifulsoup4
# huggingface-hub
# openai
# pydantic
# pydantic-core
# referencing
urllib3==2.3.0
# via
# -c requirements/common-constraints.txt
# mixpanel
# requests
watchfiles==1.0.4
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in
wcwidth==0.2.13
# via
# -c requirements/common-constraints.txt
# prompt-toolkit
yarl==1.18.3
# via
# -c requirements/common-constraints.txt
# aiohttp
zipp==3.21.0
# via
# -c requirements/common-constraints.txt
# importlib-metadata
# The following packages are considered to be unsafe in a requirements file:
pip==25.0.1
# via
# -c requirements/common-constraints.txt
# -r requirements/requirements.in