Skip to content

fix(dependencies): fix the version of setuptools package#4199

Merged
aicam merged 1 commit into
apache:mainfrom
aicam:fix-setuptools
Feb 9, 2026
Merged

fix(dependencies): fix the version of setuptools package#4199
aicam merged 1 commit into
apache:mainfrom
aicam:fix-setuptools

Conversation

@aicam

@aicam aicam commented Feb 9, 2026

Copy link
Copy Markdown
Contributor

What changes were proposed in this PR?

Locks setuptools library because they removed some functions. Ref. In summary, on Feb 8 2026, they removed a pkg_resources which is used by fs library and broke our testing pipeline.

Add setuptools with the latest compatible version to requirements.txt.

Any related issues, documentation, discussions?

No

How was this PR tested?

Test cases passed on this PR but have failed on previous ones when running pytest.

Was this PR authored or co-authored using generative AI tooling?

No

@github-actions github-actions Bot added engine dependencies Pull requests that update a dependency file fix labels Feb 9, 2026
@aicam aicam self-assigned this Feb 9, 2026
@aicam aicam changed the title fix(setuptools): lock setuptools fix(Python dependency): lock setuptools Feb 9, 2026
@aicam
aicam requested a review from bobbai00 February 9, 2026 23:17
@bobbai00 bobbai00 changed the title fix(Python dependency): lock setuptools fix(dependencies): fix the version of setuptools package Feb 9, 2026

@bobbai00 bobbai00 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please add more details to the PR description

@aicam
aicam merged commit fa87887 into apache:main Feb 9, 2026
14 checks passed
@carloea2

carloea2 commented Feb 9, 2026

Copy link
Copy Markdown
Contributor

@aicam is this approach the best in a long term? I think fixing the version is a concern

@aicam

aicam commented Feb 9, 2026

Copy link
Copy Markdown
Contributor Author

@aicam is this approach the best in a long term? I think fixing the version is a concern

I think we should set version for all libraries.

madisonmlin pushed a commit to madisonmlin/texera that referenced this pull request Mar 10, 2026
<!--
Thanks for sending a pull request (PR)! Here are some tips for you:
1. If this is your first time, please read our contributor guidelines:
[Contributing to
Texera](https://github.com/apache/texera/blob/main/CONTRIBUTING.md)
  2. Ensure you have added or run the appropriate tests for your PR
  3. If the PR is work in progress, mark it a draft on GitHub.
  4. Please write your PR title to summarize what this PR proposes, we 
    are following Conventional Commits style for PR titles as well.
  5. Be sure to keep the PR description updated to reflect all changes.
-->

### What changes were proposed in this PR?
Locks `setuptools` library because they removed some functions.
[Ref](https://setuptools.pypa.io/en/stable/history.html?utm_source=chatgpt.com)
<!--
Please clarify what changes you are proposing. The purpose of this
section
is to outline the changes. Here are some tips for you:
  1. If you propose a new API, clarify the use case for a new API.
  2. If you fix a bug, you can clarify why it is a bug.
  3. If it is a refactoring, clarify what has been changed.
  3. It would be helpful to include a before-and-after comparison using 
     screenshots or GIFs.
  4. Please consider writing useful notes for better and faster reviews.
-->
Add `setuptools` with the latest compatible version to
`requirements.txt`.

### Any related issues, documentation, discussions?
<!--
Please use this section to link other resources if not mentioned
already.
1. If this PR fixes an issue, please include `Fixes apache#1234`, `Resolves
apache#1234`
or `Closes apache#1234`. If it is only related, simply mention the issue
number.
  2. If there is design documentation, please add the link.
  3. If there is a discussion in the mailing list, please add the link.
-->
No

### How was this PR tested?
<!--
If tests were added, say they were added here. Or simply mention that if
the PR
is tested with existing test cases. Make sure to include/update test
cases that
check the changes thoroughly including negative and positive cases if
possible.
If it was tested in a way different from regular unit tests, please
clarify how
you tested step by step, ideally copy and paste-able, so that other
reviewers can
test and check, and descendants can verify in the future. If tests were
not added,
please describe why they were not added and/or why it was difficult to
add.
-->
Test cases passed on this PR but have failed on previous ones when
running `pytest`.

### Was this PR authored or co-authored using generative AI tooling?
<!--
If generative AI tooling has been used in the process of authoring this
PR,
please include the phrase: 'Generated-by: ' followed by the name of the
tool
and its version. If no, write 'No'. 
Please refer to the [ASF Generative Tooling
Guidance](https://www.apache.org/legal/generative-tooling.html) for
details.
-->
No
SarahAsad23 pushed a commit to madisonmlin/texera that referenced this pull request May 20, 2026
<!--
Thanks for sending a pull request (PR)! Here are some tips for you:
1. If this is your first time, please read our contributor guidelines:
[Contributing to
Texera](https://github.com/apache/texera/blob/main/CONTRIBUTING.md)
  2. Ensure you have added or run the appropriate tests for your PR
  3. If the PR is work in progress, mark it a draft on GitHub.
  4. Please write your PR title to summarize what this PR proposes, we 
    are following Conventional Commits style for PR titles as well.
  5. Be sure to keep the PR description updated to reflect all changes.
-->

### What changes were proposed in this PR?
Locks `setuptools` library because they removed some functions.
[Ref](https://setuptools.pypa.io/en/stable/history.html?utm_source=chatgpt.com)
<!--
Please clarify what changes you are proposing. The purpose of this
section
is to outline the changes. Here are some tips for you:
  1. If you propose a new API, clarify the use case for a new API.
  2. If you fix a bug, you can clarify why it is a bug.
  3. If it is a refactoring, clarify what has been changed.
  3. It would be helpful to include a before-and-after comparison using 
     screenshots or GIFs.
  4. Please consider writing useful notes for better and faster reviews.
-->
Add `setuptools` with the latest compatible version to
`requirements.txt`.

### Any related issues, documentation, discussions?
<!--
Please use this section to link other resources if not mentioned
already.
1. If this PR fixes an issue, please include `Fixes apache#1234`, `Resolves
apache#1234`
or `Closes apache#1234`. If it is only related, simply mention the issue
number.
  2. If there is design documentation, please add the link.
  3. If there is a discussion in the mailing list, please add the link.
-->
No

### How was this PR tested?
<!--
If tests were added, say they were added here. Or simply mention that if
the PR
is tested with existing test cases. Make sure to include/update test
cases that
check the changes thoroughly including negative and positive cases if
possible.
If it was tested in a way different from regular unit tests, please
clarify how
you tested step by step, ideally copy and paste-able, so that other
reviewers can
test and check, and descendants can verify in the future. If tests were
not added,
please describe why they were not added and/or why it was difficult to
add.
-->
Test cases passed on this PR but have failed on previous ones when
running `pytest`.

### Was this PR authored or co-authored using generative AI tooling?
<!--
If generative AI tooling has been used in the process of authoring this
PR,
please include the phrase: 'Generated-by: ' followed by the name of the
tool
and its version. If no, write 'No'. 
Please refer to the [ASF Generative Tooling
Guidance](https://www.apache.org/legal/generative-tooling.html) for
details.
-->
No
yangzhang75 pushed a commit to yangzhang75/texera that referenced this pull request Jun 22, 2026
<!--
Thanks for sending a pull request (PR)! Here are some tips for you:
1. If this is your first time, please read our contributor guidelines:
[Contributing to
Texera](https://github.com/apache/texera/blob/main/CONTRIBUTING.md)
  2. Ensure you have added or run the appropriate tests for your PR
  3. If the PR is work in progress, mark it a draft on GitHub.
  4. Please write your PR title to summarize what this PR proposes, we 
    are following Conventional Commits style for PR titles as well.
  5. Be sure to keep the PR description updated to reflect all changes.
-->

### What changes were proposed in this PR?
Locks `setuptools` library because they removed some functions.
[Ref](https://setuptools.pypa.io/en/stable/history.html?utm_source=chatgpt.com)
<!--
Please clarify what changes you are proposing. The purpose of this
section
is to outline the changes. Here are some tips for you:
  1. If you propose a new API, clarify the use case for a new API.
  2. If you fix a bug, you can clarify why it is a bug.
  3. If it is a refactoring, clarify what has been changed.
  3. It would be helpful to include a before-and-after comparison using 
     screenshots or GIFs.
  4. Please consider writing useful notes for better and faster reviews.
-->
Add `setuptools` with the latest compatible version to
`requirements.txt`.

### Any related issues, documentation, discussions?
<!--
Please use this section to link other resources if not mentioned
already.
1. If this PR fixes an issue, please include `Fixes apache#1234`, `Resolves
apache#1234`
or `Closes apache#1234`. If it is only related, simply mention the issue
number.
  2. If there is design documentation, please add the link.
  3. If there is a discussion in the mailing list, please add the link.
-->
No

### How was this PR tested?
<!--
If tests were added, say they were added here. Or simply mention that if
the PR
is tested with existing test cases. Make sure to include/update test
cases that
check the changes thoroughly including negative and positive cases if
possible.
If it was tested in a way different from regular unit tests, please
clarify how
you tested step by step, ideally copy and paste-able, so that other
reviewers can
test and check, and descendants can verify in the future. If tests were
not added,
please describe why they were not added and/or why it was difficult to
add.
-->
Test cases passed on this PR but have failed on previous ones when
running `pytest`.

### Was this PR authored or co-authored using generative AI tooling?
<!--
If generative AI tooling has been used in the process of authoring this
PR,
please include the phrase: 'Generated-by: ' followed by the name of the
tool
and its version. If no, write 'No'. 
Please refer to the [ASF Generative Tooling
Guidance](https://www.apache.org/legal/generative-tooling.html) for
details.
-->
No
@Yicong-Huang

Copy link
Copy Markdown
Contributor

@aicam is this approach the best in a long term? I think fixing the version is a concern

I think we should set version for all libraries.

Just to clarify, pinning a library version in requirements.txt is generally not ideal for a source/library project. We usually want to specify a compatible version range instead of forcing one exact version.

Pinning with == makes sense for a binary release, Docker image, executable package, or any deployment artifact where we need a reproducible runtime environment. But for a library/source project, strict pins can unnecessarily constrain downstream users and create dependency conflicts with other packages.

For example, instead of:

foo==1.2.3

we usually prefer something like:

foo>=1.2,<2

This says the project is compatible with a range of versions while still protecting against known breaking changes.

We will enforce version lock in LICENSE-binary files for release purposes.

@Yicong-Huang

Copy link
Copy Markdown
Contributor

@aicam, I am revisiting the decision of pinning setuptools. I also wonder the same as @carloea2 if pinning the version is the best move for long term.

Yicong-Huang added a commit to Yicong-Huang/texera that referenced this pull request Jul 17, 2026
…#6110)

### What changes were proposed in this PR?

Audits the explicit transitive pins in `amber/requirements.txt` and
removes the two that serve no purpose. Verified with the pip dependency
graph (`Required-by`) and a full `pip install --dry-run --report`
resolution:

| Pin | Verdict | Why |
| --- | --- | --- |
| `python-dateutil==2.8.2` | **Drop** | Required by six installed
packages (pandas, botocore, betterproto, pg8000, aiobotocore,
strictyaml) — always installed regardless. A `pip freeze` leftover from
the original requirements.txt (apache#1259); every dependent declares `>=2.8`,
so the pin only held us on a 2021 release. Resolves to 2.9.0.post0 |
| `aiobotocore==3.7.0` | **Drop** | Hard dependency of s3fs; its version
is already uniquely constrained by the `botocore==1.42.90` pin
(aiobotocore's per-release botocore window is very narrow). Removing it
eliminates a manual pairing hazard when bumping the boto3/botocore pins.
Still resolves to 3.7.0 |
| `s3fs`, `SQLAlchemy`, `pg8000` | Keep | Empty `Required-by` —
pyiceberg only pulls them via extras, so dropping them would actually
uninstall them (Iceberg S3 FileIO / SqlCatalog would break at runtime).
pg8000 deliberately replaces LGPL psycopg2 (apache#3299) |
| `setuptools==80.10.2` | Keep | Guards `fs`'s `pkg_resources` import
against newer setuptools removing it (apache#4199); `fs` declares setuptools
with no version bound |

`amber/LICENSE-binary-python` updates `python-dateutil` to the resolved
2.9.0.post0 (it stays installed transitively, so the
`check_binary_deps.py` gate still requires the claim); aiobotocore
already claims 3.7.0, which is unchanged by the resolution.

### Any related issues, documentation, discussions?

Closes apache#6108. Follow-up to apache#6101 / apache#6103.

### How was this PR tested?

- `pip install --dry-run --ignore-installed --report` without the pins:
resolution unchanged except python-dateutil → 2.9.0.post0;
aiobotocore/botocore/boto3 stay at their current versions.
- Upgraded the local venv to the resolved versions and ran the existing
pyamber suite (`pytest -m "not integration"`) — passes.
- CI's pyamber leg re-resolves from scratch and `check_binary_deps.py`
verifies the LICENSE-binary-python claims.

### Was this PR authored or co-authored using generative AI tooling?

Generated-by: Claude Code (claude-fable-5)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Signed-off-by: Yicong Huang <17627829+Yicong-Huang@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file engine fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants