Skip to content

Align and Widen Dependency Version Constraints - #429

Merged
harryswift01 merged 1 commit into
mainfrom
419-general-improve-renovate-dependency-management
Sep 30, 2026
Merged

harryswift01 merged 1 commit into
mainfrom
419-general-improve-renovate-dependency-management

Conversation

@harryswift01

Copy link
Copy Markdown
Member

Summary

This PR widens and corrects the dependency version constraints in pyproject.toml and conda-recipe/meta.yaml, replacing several overly narrow single-patch/single-month pins with properly verified ranges.

Changes

Widened ranges:

  • Widened upper bounds on pandas, rich, networkx, dask, distributed, dask-jobqueue from single-patch/single-month pins to full-range ceilings
  • Lowered floors on pandas, psutil, rich, art, networkx, rdkit, numba, dask, distributed to the actual minimum version required, verified by installing each exact version and running the full test suite

Wheel-availability and security fixes:

  • Raised numpy, mdanalysis, pandas, psutil, rdkit, numba, PyYAML floors where the previous floor lacked a prebuilt wheel for Python 3.12, 3.13, or 3.14 (would otherwise fall back to a fragile source build, or fail to install at all)
  • Raised requests floor to 2.32.2: 2.32.0 and 2.32.1 are both yanked from PyPI
  • Capped numpy at <2.5.0: waterEntropy's vibrational entropy calculation uses np.linalg.eig() on a symmetric covariance matrix, and every 2.5.x release returns eigenvalues in a different (non-deterministic) order than 2.3.x/2.4.x

Consistency and cleanup:

  • Reconciled numpy, psutil, dask, distributed ranges to match the now-loosened constraints in waterEntropy, previously exact-pinned
  • Removed unused dependencies: matplotlib, python-json-logger, sphinx_rtd_theme, sphinxcontrib-contentui, sphinxcontrib-details-directive
  • Kept conda-recipe/meta.yaml in sync with pyproject.toml throughout

Impact

  • Reduces the risk of resolver conflicts when CodeEntropy is installed alongside other scientific tools in a shared environment
  • All floors verified against the full unit test suite on Python 3.12, 3.13, and 3.14
  • Upper bounds are kept, not removed, so future major-version bumps still go through a tested PR rather than resolving unbounded

@harryswift01 harryswift01 added this to the 2.5.0 milestone Sep 29, 2026
@harryswift01 harryswift01 self-assigned this Sep 29, 2026
@harryswift01 harryswift01 added the dependencies Pull requests that update a dependency file label Sep 29, 2026

@jimboid jimboid left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks great, hopefully renovate will now start to behave how we like it to. Happy to merge.

@harryswift01
harryswift01 merged commit 732f1e7 into main Sep 30, 2026
43 of 45 checks passed
@harryswift01
harryswift01 deleted the 419-general-improve-renovate-dependency-management branch September 30, 2026 08:11
@harryswift01 harryswift01 linked an issue Sep 30, 2026 that may be closed by this pull request
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[General]: Widen and correct dependency version constraints

2 participants