fix: adopt uv for dependency management #33
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/adopt-uv-for-dependency-management"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR migrates the Master node from using
requirements.txtwith pip to usingpyproject.tomlwith uv for modern, faster dependency management.Changes
requirements.txtwithpyproject.tomlfor dependency managementpycryptowithpycryptodomefor better compatibilitymaster.shto useuv runinstead of direct Python callsREADME.mdto reflect uv usage__init__.py(not needed for standalone scripts)Key Benefits
Usage
uv sync(instead ofpip install -r requirements.txt)uv run python master.py --debug --dbfile sample-keydb.txtuv run python master.pyoruv shellBreaking Changes
curl -LsSf https://astral.sh/uv/install.sh | shFiles Changed
Master/pyproject.toml(new)Master/master.sh(updated)README.md(minimal updates)Master/requirements.txt(deleted)Master/__init__.py(deleted)This PR modernizes the dependency management while maintaining backward compatibility and improving the overall development experience.
is there not a more secure way to get 'uv' installed ? E.g. from some managed environment ? That:
looks scary as hell; and seeing that this curl script contains base64 opaque binaries that it then runs:
Feels really rather scary ?
Dw.
Yeah I agree on that. We could either manually fetch and verify the artefacts or use ubuntu's snap, https://snapcraft.io/install/astral-uv/ubuntu. Although I am less familiar with that tool.
sudo snap install astral-uv --classicCheers,
Luke
-------- Original Message --------
On 14/06/2025 16:13, Dirk-Willem van Gulik - dirkx at webweaving.org @.***> wrote:
In the installation instructions of uv they suggest using pip to install it, would there be a downside to doing that?
Personally I'm not too keen on snaps.
I've put together a script here which can be used to run upgrades of uv.
https://gist.github.com/thisislawatts/4fac9fa61f145512d36721754f165fc6
@stormeuh, do you have any recommended reading around the snaps? I haven't worked with them too much before so unsure of the trade-offs they introduce.
Pull request closed