On Mon, Dec 09, 2019 at 11:57:38AM -0500, Eli Schwartz wrote:
> > wow, cool, that might be something for Archlinux...!
> I don't believe this is related to us as we (per policy) try to avoid
> using pip to install packages. Our solution to a package being
> unreproducible because it uses pip's /tmp/pip-install-XXXXX random
> staging directory... is to figure out how to use setuptools' setup.py
> directly. I *think*, IIRC we almost exclusively use setup.py,
> occasionally with the aid of a pyproject.toml-to-setup.py converter.
> There are some issues with using pip that aren't due to reproducible
> builds, including making the bootstrap graph more complex, or pip's
> habit of installing multiple packages by downloading them from PyPI if a
> dependency is missing. Some of these problems can be solved, but it's
> less bother to simply use setup.py directly as that is essentially what
> pip is doing anyway.

ah, ic, thanks for explaining!


