About Leo's optional dependencies

36 views
Skip to first unread message

Edward K. Ream

unread,
Sep 12, 2026, 8:57:14 AMSep 12
to leo-editor
Leo issue #4978 now suggests installing only the minimal sets of dependencies, either from:

    pip install leo

or:

    pip install . (within a Leo repo).

Indeed, there is not much difference between the following:

  pip install leo[optional-dependency-set]
  pip install an-optional-module

In short, I see no advantage to defining various optional dependency sets.

Summary

Leo's tests (including ci.yml) must run with the new minimal dependencies.

All code that uses optional modules should recommend  pip install module if the module can't be imported.

All questions, comments, and suggestions are welcome.

Edward

Edward K. Ream

unread,
Sep 12, 2026, 11:09:04 AMSep 12
to leo-editor
On Saturday, September 12, 2026 at 7:57:14 AM UTC-5 Edward K. Ream wrote:

> Leo issue #4978 now suggests installing only the minimal sets of dependencies
...
> All code that uses optional modules should recommend  pip install module if the module can't be imported.

On second thought, I think pip install .[all] should be another option, and the suggestions should include that option.

Edward

Edward K. Ream

unread,
Sep 12, 2026, 1:01:31 PMSep 12
to leo-editor
On Saturday, September 12, 2026 at 10:09:04 AM UTC-5 Edward K. Ream wrote:

> On second thought, I think pip install .[all] should be another option, and the suggestions should include that option.

On third (last?) thought, I think PR #4982 is well worth doing, but not because Leo should install a minimal set of modules by default.

Indeed, the PR makes Leo's codebase (including unit tests) more resilient to missing modules, and will soon give better warnings when modules go missing. And that can happen: nothing prevents a user from uninstalling a module.

But restricting the modules that Leo installs will have virtually no effect on security. Leo installs well-known modules. Far more than Leo's integrity will be at stake if those modules become compromised.

Finally, installing a minimal set of modules complicates the user experience for all Leonistas, including devs.

Summary

PR #4982 is worth doing for reasons other than security.

After the PR is complete and passes all its tests (with minimal and full dependencies), I'll commit a version of pyproject.toml that:

- Installs all dependencies by default.
- Indicates (via commented-out sections) how optional dependencies could be specified.

All your comments, questions, and suggestions are welcome.

Edward
Reply all
Reply to author
Forward
0 new messages