fschulze/dev/: devpi-server-6.0.0.dev6 metadata and description

devpi-server: reliable private and pypi.org caching server

Metadata
classifiers
  • Development Status :: 5 - Production/Stable
  • Environment :: Web Environment
  • Intended Audience :: Developers
  • Intended Audience :: System Administrators
  • License :: OSI Approved :: MIT License
  • Programming Language :: Python
  • Programming Language :: Python :: 3 :: Only
  • Topic :: Internet :: WWW/HTTP
  • Topic :: Internet :: WWW/HTTP :: WSGI :: Application
  • Programming Language :: Python :: Implementation :: PyPy
  • Programming Language :: Python :: 3.4
  • Programming Language :: Python :: 3.5
  • Programming Language :: Python :: 3.6
  • Programming Language :: Python :: 3.7
  • Programming Language :: Python :: 3.8
keywords pypi realtime cache server
license MIT
maintainer Holger Krekel, Florian Schulze
maintainer_email [email protected]
requires_dist
  • py (>=1.4.23)
  • appdirs
  • argon2-cffi
  • attrs
  • defusedxml
  • devpi-common (<4,>=3.3.0)
  • itsdangerous (>=0.24)
  • execnet (>=1.2)
  • pyramid (>=1.8)
  • waitress (>=1.0.1)
  • repoze.lru (>=0.6)
  • passlib[argon2]
  • pluggy (<1.0,>=0.6.0)
  • strictyaml
  • python2-secrets ; python_version < "3.6"
  • ruamel.yaml (<=0.15.94) ; python_version == "3.4"
requires_python >=3.4
Files
File Tox results History
devpi-server-6.0.0.dev6.tar.gz
Size
213 KB
Type
Source
sha256
9100855d4484832d88dce11a0413b5e9c36cb9f4531f4cd9bf1b2043f50d5fec
devpi_server-6.0.0.dev6-py3-none-any.whl
Size
220 KB
Type
Python Wheel
Python
3
sha256
6092021414268afca0a8cb75013636eed692f43ab54ec505343c7e977146a71f

devpi-server: server for private package indexes and PyPI caching

PyPI cache

You can point pip or easy_install to the root/pypi/+simple/ index, serving as a transparent cache for pypi-hosted packages.

User specific indexes

Each user (which can represent a person, project or team) can have multiple indexes and upload packages and docs via standard twine or setup.py invocations. Users and indexes can be manipulated through devpi-client and a RESTful HTTP API.

Index inheritance

Each index can be configured to merge in other indexes so that it serves both its uploads and all releases from other index(es). For example, an index using root/pypi as a parent is a good place to test out a release candidate before you push it to PyPI.

Good defaults and easy deployment

Get started easily and create a permanent devpi-server deployment including pre-configured templates for nginx and process managers.

Separate tool for Packaging/Testing activities

The complementary devpi-client tool helps to manage users, indexes, logins and typical setup.py-based upload and installation workflows.

See https://doc.devpi.net on how to get started and further documentation.

Support

If you find a bug, use the issue tracker at Github.

For general questions use the #devpi IRC channel on freenode.net or the [email protected] mailing list.

For support contracts and paid help contact merlinux.eu.

Changelog

6.0.0.dev6 (2020-07-06)

Deprecations and Removals

  • Remove deprecated command line options which were replaced by separate scripts.

  • Dropped support for Python 2.7.

  • Removed deprecated --start, --stop and --status options.

Features

  • fix #140: support force flag for deletion on non-volatile indexes.

  • fix #725: new option mirror_whitelist_inheritance for indexes. The union setting is the old behaviour and used for existing indexes to not break existing installations. With it the whitelist of each index in the inheritance order is merged into the current whitelist. This could lead to unexpected whitelisting. The new intersection setting is used for all new indexes and it intersects the whitelist at each step in the inheritance order which is more secure and never causes unexpected whitelisting.

  • fix #792: support data-yanked attribute from PEP 592 for mirror indexes.

  • Replicas download files asynchronously from the metadata and will do so with multiple parallel requests. This means the metadata will be in sync faster and downloads will process quicker. Missing files will be downloaded on demand if they haven’t been fetched yet. The new --file-replication-threads option allows controlling the amount of parallel downloads. Event processing waits until files for that serial are available. Since newest files are downloaded first, event processing might wait until all files are downloaded.

  • Much faster mirror project names parsing. For PyPI the speedup can be about 30x.

  • Do some sanity checks on the secret provided by --secretfile.

  • The server secret for token signing is now derived via argon2 from the data provided by --secretfile. Existing login tokens are invalidated by this.

Bug Fixes

  • fix #451: packages not on mirror_whitelist no longer query the mirror

  • fix #680: indexes with multiple mirror bases now work correctly with default secure whitelist settings.

  • Handle cases where the Content-Type header from a mirror can be an empty string.

Other Changes

  • Warning! Once you used 6.0.0 with a replica you have to check that all files have been downloaded with devpi-fsck before attempting to downgrade to 5.x.y, as those older versions have no mechanism to re-download those.

  • Use secrets.token_bytes instead of os.urandom for salts and server secrets.

  • Replicas need to use the same secret as the master for the --secretfile option to be able to authenticate with the master.

  • The secret file must be user accessible only, devpi-server will not start if it is not.

5.5.0 (2020-05-04)

Features

  • Proxy requests from replica to master are now streamed if possible. This improves reliability of large uploads through replicas and reduces RAM usage on the replica.

5.4.1 (2020-03-26)

Bug Fixes

  • Import won’t abort anymore when a base index was removed. The bases setting will be imported as is.

5.4.0 (2020-01-31)

Features

  • The requires_python metadata is now included in version data on mirror indexes.

  • Downloaded files from mirrors can be included in exports with the --include-mirrored-files option.

  • On import files for mirror indexes are now imported when they were included in the dump (see --include-mirrored-files).

Bug Fixes

  • Fix --no-root-pypi option when importing devpi data.

  • Fix pushing from mirror to an index when the file was removed and mirror_use_external_urls is active.

5.3.1 (2019-12-05)

Bug Fixes

  • fix #688: on file upload existing metadata is only updated, not replaced.