Repository navigation
Upgrade bundled pip to 22.1 series #92688
Description
Activity
Notably, due to pypa/pip#11044, Python 3.11+ can have a slightly different behaviour starting with pip 22.1 (it uses importlib.metadata instead of distutils/pkg_resources for loading metadata of installed packages).
It will be nice if #31885 is merged before the upgrade to have a checksum of the pip wheel verified.
Reacted by Pradyun GedamFWIW, the 22.1 series doesn't work for ensurepip, yet (pypa/pip#11183)
There are a lot of layers compounding to the ultimate issue:
pkg_resourcesunconditionally ignores any metadata inside asys.pathitem with suffix.whl. This ignore clause was originally intended forPKG-INFOmetadata (according to in-code comments), but also got applied to.dist-infometadata without careful scrutiny.importlib.metadatadoes not inherit this quirk.ensurepippopulates pip by running pip inside the wheel, a use case not supported by pip maintainers.- pip accidentally relied on the
pkg_resourcesquirk to exclude itself from the installed packages, making installation process work.
So there are at least three ways we can fix this. But since running pip inside a wheel is not supported in the first place, I suggest changing
ensurepipto not ship valid wheels, or pre-process them before running pip (matching howget-pip.pydoes this), which should resolve the issue. This also prevents people from getting a wrong idea from the stdlib, that pip actively supports being run inside a wheel.Reacted by Pradyun Gedam- addedstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory3.11only security fixesonly security fixes
on Jun 12, 2022 22.2 is compatible with ensurepip (pypa/pip#11217).
So I filed #95194 and this issue can be closed.Superseded by #95194
This is in the same vein as #91141. There has been a new pip release, and ensurepip's bundled wheels should be updated to the newer version of pip.