Pixi
Categories: python
Renovate supports updating Pixi dependencies.
File Matching¶
By default, Renovate will check any files matching any of the following regular expressions:
/(^|/)pyproject\.toml$/
/(^|/)pixi\.toml$/
For details on how to extend a manager's managerFilePatterns value, please follow this link.
Supported datasources¶
This manager supports extracting the following datasources: conda, pypi.
Dependency types¶
Feature dependencies produce dynamic depType values in the form feature-<name>, where <name> is the feature name defined in the pixi configuration. Top-level dependencies (under [dependencies] or [pypi-dependencies]) do not have a depType set.
Default config¶
{
"managerFilePatterns": [
"/(^|/)pyproject\\.toml$/",
"/(^|/)pixi\\.toml$/"
]
}
Lock File Maintenance¶
This manager supports lockFileMaintenance for the following file(s):
pixi.lock
Lock file maintenance is delegated to the underlying package manager, which Renovate runs as an external command.
Additional Information¶
Pixi package manager¶
Currently support channels from anaconda and prefix.dev, other channels are not supported yet.
Whenever the pixi config in pyproject.toml or pixi.toml file is updated, pixi.lock file will be checked for updates as well.
When using pyproject.toml, standard PEP 621 dependencies (e.g. [project.dependencies] or [dependency-groups]) are handled by the pep621 manager, which also updates pixi.lock when those dependencies change.
Trust model for pixi lock file updates¶
Running pixi lock can execute arbitrary code from conda package hooks, so Renovate treats pixi.lock refreshes as an unsafe execution.
See pixi's security documentation for details.
Self-hosted administrators must explicitly allow this path by including pixi in the global allowedUnsafeExecutions setting.
When pixi is not allowed, the package file is still updated, but pixi.lock is left unchanged.
Renovatebot will pick pixi version in following order:
- renovatebot setting
constraints.pixi requires-pixiinpixi.toml
The minimal support version of pixi is 0.40.0 (pixi lock has only been introduced with that version).
Therefore when you are setting constraints.pixi in your renovatebot config or requires-pixi in pixi.toml, please be careful to pick a supported pixi version.