DEV Community

Luiz Fernando Nunes da Silva
Luiz Fernando Nunes da Silva

Posted on AI-assisted

29 of the 100 most-downloaded PyPI projects have a version that names two different code states

A version number is a string a human edits. When two release tags declare the same version and the code differs, one address now points to two artefacts. Nothing notices, because the version is all anyone recorded.

I wanted to know how often this happens, so I built a small tool to check it and ran it on the 100 most-downloaded PyPI projects with a public repository. The method was fixed before the first run, and no project was tuned.

result repositories
every version names one code state 59
at least one version names two 29
not enough tags compared 4
no version found, or inconclusive 8

Every collision is listed and can be checked by hand. In requests:

$ closure-drift --compare v2.16.0 v2.16.1
DIFFERS UNDER ONE LABEL: both declare 2.16.0, and the code differs in 2 path(s).
Enter fullscreen mode Exit fullscreen mode

Why it happens

Mostly not carelessness. A tag created before the version was bumped, branch markers such as 7.x, and monorepos where several tag families share one version file. I asked the maintainers of three projects about their cases; all three confirmed what the tool measured.

Checking your own repository

pipx install git+https://github.com/luizfnsilva/closure_drift@v1.0.0
closure-drift            # inside any git repository
Enter fullscreen mode Exit fullscreen mode

It is one file, standard library only, read-only, no network. Exit 0 means clean, 1 means drift, 2 means it could not tell, and the report says why. To stop it before it happens, --would-tag checks a commit before you tag it, and runs as a GitHub Action or a pre-commit hook.

The full study, the method and every collision: https://github.com/luizfnsilva/closure_drift

Top comments (0)