Skip to content
Open
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,8 @@ respx == 0.23.1

cachecontrol >= 0.14.3
google-api-core[grpc] >= 2.25.1, < 3.0.0dev; platform.python_implementation != 'PyPy'
google-cloud-firestore >= 2.27.0; platform.python_implementation != 'PyPy'
google-cloud-firestore >= 2.28.0; platform.python_implementation != 'PyPy' and python_version >= '3.10'
google-cloud-firestore >= 2.27.0; platform.python_implementation != 'PyPy' and python_version < '3.10'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Using python_version >= '3.10' and python_version < '3.10' can lead to unexpected behavior with older or alternative package managers, dependency parsers, and security scanners that incorrectly perform lexicographical string comparison instead of PEP 440 version comparison.

Specifically, under lexicographical comparison:

  • '3.9' >= '3.10' evaluates to True (since '9' > '1'), which would incorrectly select the >= 2.28.0 requirement on Python 3.9.
  • '3.9' < '3.10' evaluates to False, failing to select the >= 2.27.0 requirement on Python 3.9.

Since the minimum supported Python version for this project is 3.9 (as specified in setup.py), you can safely use python_version != '3.9' and python_version == '3.9' respectively. This is completely robust against any lexicographical string comparison bugs.

google-cloud-firestore >= 2.28.0; platform.python_implementation != 'PyPy' and python_version != '3.9'
google-cloud-firestore >= 2.27.0; platform.python_implementation != 'PyPy' and python_version == '3.9'

google-cloud-storage >= 3.1.1
pyjwt[crypto] >= 2.12.1
cryptography < 44.0.0; platform.python_implementation == 'PyPy' and python_version < '3.11'
Expand Down
Loading