Ensuring reproducible installs when a locked dependency disappears from PyPI
0 reputation · 17 Jul 2023, 21:05 UTC
When Poetry generates a poetry.lock, it records the exact versions and hashes of all packages required by a project. This determinism is essential for reproducible builds across environments. However, if a dependency listed in the lockfile is later removed from every configured repository—PyPI or a private index—Poetry’s installer will fail, breaking the reproducibility guarantee.
The core issue is how to handle a missing package without compromising the lockfile’s integrity. Options include falling back to a cached copy, disabling strict lockfile enforcement, or enabling an offline mode that relies solely on the lockfile’s contents. Each approach has implications for security, build consistency, and deployment automation.
Which strategy should be adopted to handle the case when a dependency listed in poetry.lock is no longer available in any configured repository? Does Poetry provide an offline installation mode that can resolve missing packages using the lockfile alone, and if so, how can it be enabled?