Relax dependency version pins
Opened this issue · 0 comments
Currently this library has fairly strict dependency version requirements, with some of them pinned to exact versions.
spacy-ann-linker/pyproject.toml
Lines 30 to 38 in d6a785c
It's generally a best practice for reusable libraries to have more relaxed version requirements, one of:
- Version floor only, e.g.,
tqdm >= 4.47.0
- Version floor with version ceiling on major version. That assumes the dependency follows semver and that major version changes have backwards incompatible changes, e.g.,
tqdm >= 4.47, <5
with more specific version ceilings introduced only if a specific update introduces a known incompatibility.
Whether (1) or (2) is followed is not a settled thing, but my preference is for (1) because it gives users the most flexibility and has the most limited scope of failure (only causes problems if a major version change specifically breaks an API used by this library, as opposed to any time another dependency floors on the new major version).
The reason for doing so is that unnecessarily strict version requirements makes it really difficult for users of a library to reconcile dependency resolution against other dependencies. Having strict exact pins is a practice for applications for stable reproducibility.
References: