Resolve Python git and direct wheel requirements in the client rather than silently replacing uv source declarations with index packages. Preserve manifest version constraints, extras, markers, and workspace inheritance. Pin git sources with PEP 751 vcs records and record wheel SHA-256 hashes. Reuse the isolated PEP 517 builder, verified wheel CAS ingestion, git transport policy, and atomic cache publication. Require approval before running code from a git dependency or its build requirements. Preserve submodules in cached checkouts and prevent recursive build dependencies from deadlocking. Keep source identity in wheel reuse and in lockfiles covering multiple target environments. Record PEP 610 origin metadata for git and URL installs. Let pnpr return a specific client-resolution response for transitive URLs. Add CLI coverage for direct and uv sources, git revisions and subdirectories, legacy projects, workspace inheritance, integrity and identity failures, build approval, recursive builds, submodules, platform-specific sources, backtracking between direct and index dependencies, requirements-file URL sources, and frozen offline replay. Document the supported forms and add a pacquet minor changeset. Related to pnpm/pnpm#14945, item 6.
306 B
306 B
pacquet
| pacquet |
|---|
| minor |
pnpm install now supports Python dependencies from Git repositories. Direct wheel URLs are also supported. Sources can be declared in [tool.uv.sources]. Git dependencies require allowBuilds approval.
Related to pnpm/pnpm#14945.