stale-twilight-79248
02/26/2026, 2:53 PMdependency-name >= ... to dependency-name @ git+<https://github>....
3. add this fork as a git submodule to the monorepo
4. pip install -e custom-forks/dependency-name so we can iterate and test our change to the fork live within our activated venv
5. commit / push changes to the forked repo so that our published packages which depend on this forked dep can pull / install the updated code from github when deployed in the wild
6. work on getting our changes merged upstream (can sometimes take months or longer 😞 )
I'm trying to achieve the same with pants, but it's proving to be difficult. setting the dependency to point to a git repo works fine (unless you try to pin lockfile deps with a constraints file, at which point it just entirely blows up
But I can't figure out how to tell pants to override that dep with a local editable install when exporting the venv or running any tasks which include that dep
Thoughts?brief-scientist-13682
02/26/2026, 5:41 PMstale-twilight-79248
02/26/2026, 10:29 PMbrief-scientist-13682
02/26/2026, 11:00 PMhappy-kitchen-89482
02/26/2026, 11:42 PMhappy-kitchen-89482
02/26/2026, 11:42 PMstale-twilight-79248
03/04/2026, 2:46 PMpip install -e the local fork when exporting a venv?brief-scientist-13682
03/04/2026, 3:34 PM:; git clone <https://github.com/VaasuDevanS/cowsay-python>
:; cat requirements.txt
-e cowsay-python/
:; pex3 lock create -r requirements.txt --indent 2 -o lock.json
# Note `"editable": true,` in the artifacts list below:
:; jq .locked_resolves[0].locked_requirements lock.json
[
{
"artifacts": [
{
"algorithm": "sha256",
"editable": true,
"hash": "111eb24cead5476d6384dfe692e61f73a897275b48373bcc5385c0b4bfbf7dc2",
"url": "file:///home/jsirois/support/pants/slack/3-4-2026/cowsay-python"
}
],
"project_name": "cowsay",
"requires_dists": [
"coverage; extra == \"test\"",
"pytest; extra == \"test\""
],
"requires_python": ">=3.8",
"version": "6.1"
}
]
But Pex cannot install as editable:
:; pex3 venv create --lock lock.json -d editable-venv
# Edit local clone and show this breaks it:
:; echo "INVALID" >> cowsay-python/cowsay/__main__.py
:; PYTHONPATH=cowsay-python/ python -mcowsay -t 'Moo!'
____
| Moo! |
====
\
\
^__^
(oo)\_______
(__)\ )\/\
||----w |
|| ||
Traceback (most recent call last):
File "<frozen runpy>", line 198, in _run_module_as_main
File "<frozen runpy>", line 88, in _run_code
File "/home/jsirois/support/pants/slack/3-4-2026/cowsay-python/cowsay/__main__.py", line 34, in <module>
INVALID
NameError: name 'INVALID' is not defined
# But the venv has pristinely installed copies and no break:
:; editable-venv/bin/python -mcowsay -t 'Moo!'
____
| Moo! |
====
\
\
^__^
(oo)\_______
(__)\ )\/\
||----w |
|| ||
That said @stale-twilight-79248 re:
> But I can't figure out how to tell pants to override that dep with a local editable install when exporting the venv or running any tasks which include that dep
Why are you trying to do things differently than item 4 in your initial list? Can't you just export a venv using the existing Pants means and then, exactly as in 4. above: pip install -e custom-forks/dependency-name ?
If not, what is the error?brief-scientist-13682
03/04/2026, 3:42 PMpy_editable_in_resolve looks promising, but I'll leave that dig in to you all. I'm just sniffing out Pex bugs I can fix to help with any needed workarounds outside Pants.brief-scientist-13682
03/10/2026, 8:56 AMpex3 venv create --lock lock.json --override='-e foo @ this/local/foo' --override='-e bar @ this/local/bar' -d /venv/dir to create a venv with overrides of the locked foo and bar projects using local editable installs. It looks like Pants does not create venvs directly from the lock like this for pants export and instead it creates a PEX 1st, and then runs PEX_TOOLS=1 the/PEX venv /venv/dir ; so this new capability likely won't help you unless Pants changes how it creates venvs and allows you to pass through `--override`s in some manner.
I still think pants export && dist/the/venv/bin/pip install --force-reinstall -e this/local/foo -e this/local/bar is likely the right path to be taking here; so I'm still curious to know why you don't want to or cannot take that path.stale-twilight-79248
04/07/2026, 4:37 PMbrief-scientist-13682
04/07/2026, 4:38 PMbrief-scientist-13682
04/07/2026, 4:45 PMpip: ERROR: Can't verify hashes for these requirements because we don't have a way to hash version control repositories:
pip: nautobot@ git+<https://github.com/utsc-networking/nautobot@utsc-custom> from git+<https://github.com/utsc-networking/nautobot@utsc-custom>
To their doc: https://pip.pypa.io/en/stable/topics/secure-installs/#hash-checking-mode
Back before I deleted my PyPA discourse account, I was involved in the PEP-751 pylock.toml discussions and brought up directory hashing & VCS hashing. As with ~everything PyPA, this went nowhere, but this was the thread that spun out and died: https://discuss.python.org/t/how-to-hash-a-directory-in-lockfiles/70487
I think Pip would require some sort of standard for hashing a project source directory like that thread was trying to move towards to adopt hashes for VCS. That said, that ship has sailed I think and imagine they would only support pylock.toml at this point. Now Pex fully supports pylock.toml and uv as well, so maybe you're missing a hack along those lines ... but I've linked another Pants user's attempt at that angle below.brief-scientist-13682
04/07/2026, 4:46 PMbrief-scientist-13682
04/07/2026, 4:46 PMbrief-scientist-13682
04/07/2026, 4:49 PMbrief-scientist-13682
04/07/2026, 4:49 PMstale-twilight-79248
04/07/2026, 5:08 PMstale-twilight-79248
04/07/2026, 5:09 PM