如何在requirements.txt与setup.py中为同名包指定对应PyPI源?
解决方案
在requirements.txt中指定包对应源
pip 19.0及以上版本支持直接在包名后通过@指定对应源的语法,刚好满足你的需求——不用拆分多文件,也规避了--extra-index-url可能带来的私有源漏洞风险。
直接在requirements.txt里按如下格式编写:
# 公共PyPI源的通用包,比如requests requests>=2.31.0 # ABC团队Gitlab PyPI源的apples包(同名但内容独立) apples==1.2.3 @ https://gitlab.example.com/api/v4/projects/123/packages/pypi/simple # DEF团队Artifactory PyPI源的orange包 orange==4.5.6 @ https://artifactory.example.com/api/pypi/def-team-pypi/simple
安装时直接执行pip install -r requirements.txt,每个包都会严格从你指定的源拉取,不会出现源混淆的问题。
在setup.py中配置依赖源
如果你的项目用setup.py管理依赖,同样可以遵循PEP 508规范,在install_requires里直接指定源:
from setuptools import setup setup( name="your-project", version="0.1.0", install_requires=[ "requests>=2.31.0", "apples==1.2.3 @ https://gitlab.example.com/api/v4/projects/123/packages/pypi/simple", "orange==4.5.6 @ https://artifactory.example.com/api/pypi/def-team-pypi/simple" ] )
执行pip install .安装项目时,pip会自动从指定源拉取对应依赖。
注意事项
- 先检查pip版本:用
pip --version确认版本≥19.0,不够的话执行pip install --upgrade pip升级 - 私有源需要认证时,不要直接在文件里写明文账号密码,推荐用
~/.netrc文件配置:machine gitlab.example.com login your-username password your-access-token - 如果是从Git仓库直接拉取包,也可以用Git URL替代PyPI源地址,比如:
apples==1.2.3 @ git+https://gitlab.example.com/abc-team/apples.git@v1.2.3
内容的提问来源于stack exchange,提问作者npengra317
相关产品推荐
相关产品推荐

