Skip to content

requirements-*.txt in Python are skipped #1

Description

@XeniaGabriela

Awesome tool! I just noticed that a lot of Python repos have manifests such as requirements-dev.txt and requirements-prod.txt instead of one requirements.txt. Unfortunatley, those manifests are skipped. Could you include them in the scan?

BR, Xenia

Activity

  1. thebenignhacker commented on Jul 27, 2026

    @thebenignhacker
    Member

    Thanks Xenia, and sorry for the slow reply.

    You were right. Manifest discovery matched the exact filename
    requirements.txt, so requirements-dev.txt, requirements-prod.txt and
    anything else in that family was skipped silently, with no warning that files
    had been passed over.

    Fixed in #3. Discovery now covers the requirements*.txt family and also the
    requirements/*.txt directory layout, since some projects split that way
    instead:

    manifest: requirements/base.txt   -> [pycryptodome]
    manifest: requirements-dev.txt    -> [cryptography]
    manifest: requirements-prod.txt   -> [pyjwt]
    

    While fixing this I found that pyproject.toml and Pipfile were listed as
    supported but were actually being run through the requirements.txt line
    parser, which produced dependencies named after TOML keys and missed the real
    packages entirely. Both have proper parsers now, so if you have projects using
    those, they will give real results rather than quietly empty ones.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions