Poetry dependency source overrides are ignored #39730
Replies: 1 comment
|
I found the potential issue here. Poetry deprecated priority = "default" in Poetry 1.8 and recommends using a primary source instead. A configured primary source disables Poetry's implicit PyPI source. However, Renovate currently still adds PyPI to its list of registry URLs unless it finds a source with priority = "default": https://github.com/renovatebot/renovate/blob/main/lib/modules/manager/poetry/schema.ts#L252 This can cause Renovate to query pypi.org even though Poetry itself would not use PyPI for that project. Proposed changeRenovate should treat the presence of a primary source the same way Poetry does: if at least one primary source is configured, do not implicitly add PyPI. Conceptually, the condition should change from:
to: This preserves implicit PyPI when no primary/default source is configured while preventing Renovate from introducing PyPI when Poetry would have disabled it. Explicitly configured PyPI sources would continue to work through the existing |
Uh oh!
There was an error while loading. Please reload this page.
How are you running Renovate?
Self-hosted Renovate
Which platform you running Renovate on?
GitHub.com
Which version of Renovate are you using?
42.30.4
Please tell us more about your question or problem
Poetry v2 encourages dependency specification in the PEP621 format. For dependencies not available on pypi, it requires source repository overrides to be made in the
[tool.poetry.dependencies]table (see docs). Renovate currently ignores such source overrides and tries to look up the dependency on pypi instead.Example
pyproject.toml(taken from a comment on the original Poetry v2 discussion)Logs (if relevant)
Logs
All reactions