Skip to content

Upgrade bundled pip to 22.1 series #92688

Description

@pradyunsg

This is in the same vein as #91141. There has been a new pip release, and ensurepip's bundled wheels should be updated to the newer version of pip.

Activity

  1. pradyunsg commented on May 11, 2022

    @pradyunsg
    MemberAuthor

    Notably, due to pypa/pip#11044, Python 3.11+ can have a slightly different behaviour starting with pip 22.1 (it uses importlib.metadata instead of distutils/pkg_resources for loading metadata of installed packages).

  2. illia-v commented on Jun 4, 2022

    @illia-v
    Contributor

    It will be nice if #31885 is merged before the upgrade to have a checksum of the pip wheel verified.

  3. stefanor commented on Jun 11, 2022

    @stefanor
    Contributor

    FWIW, the 22.1 series doesn't work for ensurepip, yet (pypa/pip#11183)

  4. uranusjr commented on Jun 12, 2022

    @uranusjr
    Contributor

    There are a lot of layers compounding to the ultimate issue:

    1. pkg_resources unconditionally ignores any metadata inside a sys.path item with suffix .whl. This ignore clause was originally intended for PKG-INFO metadata (according to in-code comments), but also got applied to .dist-info metadata without careful scrutiny.
    2. importlib.metadata does not inherit this quirk.
    3. ensurepip populates pip by running pip inside the wheel, a use case not supported by pip maintainers.
    4. pip accidentally relied on the pkg_resources quirk to exclude itself from the installed packages, making installation process work.

    So there are at least three ways we can fix this. But since running pip inside a wheel is not supported in the first place, I suggest changing ensurepip to not ship valid wheels, or pre-process them before running pip (matching how get-pip.py does this), which should resolve the issue. This also prevents people from getting a wrong idea from the stdlib, that pip actively supports being run inside a wheel.

  5. added
    stdlibStandard Library Python modules in the Lib/ directory
    3.11only security fixes
    on Jun 12, 2022
  6. sbidoul commented on Jul 24, 2022

    @sbidoul
    Contributor

    22.2 is compatible with ensurepip (pypa/pip#11217).
    So I filed #95194 and this issue can be closed.

  7. kumaraditya303 commented on Jul 24, 2022

    @kumaraditya303
    Contributor

    Superseded by #95194

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.11only security fixesstdlibStandard Library Python modules in the Lib/ directory

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions