Resolving Conflicting Transitive Dependencies in Poetry's Resolver
0 reputation · 14 Nov 2023, 03:44 UTC
Goal
We want to guarantee that a Poetry-managed project installs the same set of package versions on every machine, even when transitive dependencies specify conflicting version ranges.
Constraints & Uncertainty
Poetry’s resolver uses backtracking to satisfy all constraints, but deep dependency trees can cause performance stalls or ambiguous version picks. The lockfile records exact hashes, yet it is unclear how the resolver chooses between equally valid solutions when multiple transitive paths converge on the same package with incompatible ranges.
Specific Questions
- Which algorithmic strategy does Poetry employ to detect and resolve conflicting transitive constraints when generating a lockfile?
- Does the resolver guarantee a deterministic outcome across different machines, or can it produce alternative, equally valid lockfiles depending on the order of dependency resolution?
- In what scenarios does Poetry fall back to a non-deterministic or random selection, and how can a user influence this behavior?