Managing Dependencies With Pipenv

Christian Külker




Python is used for many different purposes, and how you want to manage your dependencies may change depending on how you decide to publish the software. This document shows some tools for different types of software: applications and libraries.

Managing Application Dependencies

With some caveats, pipenv, mentioned in the Python Packaging Guide (from which this section got its inspirations), is a tool for managing the dependencies of Python applications (as opposed to Python libraries).

Pipenv is a dependency manager for Python projects, similar to npm (Node.js), which may be handy for development, but comes with all the drawbacks of a shared library environment: reinstalling similar things per user per application, wasting time and disk space.

Installing Pipenv

python3 -m pip install --user pipenv

Collecting pipenv
pipenv-2018.11.26-py3-none-any.whl (5.2MB)
    100% |████████████████████████████████| 5.2MB 155kB/s
Requirement already satisfied: virtualenv in /usr/lib/python3/dist-packages \
(from pipenv) (15.1.0)
Requirement already satisfied: pip>=9.0.1 in /usr/lib/python3/dist-packages \
(from pipenv) (18.1)
Requirement already satisfied: setuptools>=36.2.1 in /usr/lib/python3/\
dist-packages (from pipenv) (40.8.0)
Requirement already satisfied: certifi in /usr/lib/python3/dist-packages (\
from pipenv) (2018.8.24)
Collecting virtualenv-clone>=0.2.5 (from pipenv)
Installing collected packages: virtualenv-clone, pipenv
  The script virtualenv-clone is installed in '/home/$USER/.local/bin' which \
is not on PATH.
  Consider adding this directory to PATH or, if you prefer to suppress this \
warning, use --no-warn-script-location.
  The scripts pipenv and pipenv-resolver are installed in '/home/$USER/.local\
/bin' which is not on PATH.
  Consider adding this directory to PATH or, if you prefer to suppress this \
warning, use --no-warn-script-location.
Successfully installed pipenv-2018.11.26 virtualenv-clone-0.5.4

This will “successfully” install pipenv. What is interesting is what kind of definition of “successful” is used in this context.

zsh: command not found: pipenv

However as the “consider” suggests:

export PATH=/home/$USER/.local/bin:$PATH
cd python-packaging-tutorial-example-package
pipenv install requests

Creating a virtualenv for this project…
Pipfile: /home/$USER/g/\
Using /usr/bin/python3 (3.7.3) to create virtualenv…
⠼ Creating virtual environment...Already using interpreter /usr/bin/python3
Using base prefix '/usr'
New python executable in /home/$USER/.local/share/virtualenvs/\
Also creating executable in /home/$USER/.local/share/virtualenvs/\
Installing setuptools, pkg_resources, pip, wheel...done.

✔ Successfully created virtual environment!
Virtualenv location: /home/$USER/.local/share/virtualenvs/\
Creating a Pipfile for this project…
Installing requests…
Adding requests to Pipfile's [packages]…
✔ Installation Succeeded
Pipfile.lock not found, creating…
Locking [dev-packages] dependencies…
Locking [packages] dependencies…
✔ Success!
Updated Pipfile.lock (444a6d)!
Installing dependencies from Pipfile.lock (444a6d)…
  🐍   ▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉▉ 5/5 — 00:00:02
To activate this project's virtualenv, run pipenv shell.
Alternatively, run a command inside the virtualenv with pipenv run.

This creates 2 files: Pipfile

name = "pypi"
url = ""
verify_ssl = true


requests = "*"

python_version = "3.7"

And Pipfile.lock (sha256 hashes are truncated in this output!)

    "_meta": {
        "hash": {
            "sha256": "bb57e0d7853b45999e472fde31c527d8d7b5b5539dc979444a6d"
        "pipfile-spec": 6,
        "requires": {
            "python_version": "3.7"
        "sources": [
                "name": "pypi",
                "url": "",
                "verify_ssl": true
    "default": {
        "certifi": {
            "hashes": [
            "version": "==2020.4.5.1"
        "chardet": {
            "hashes": [
            "version": "==3.0.4"
        "idna": {
            "hashes": [
            "version": "==2.9"
        "requests": {
            "hashes": [
            "index": "pypi",
            "version": "==2.23.0"
        "urllib3": {
            "hashes": [
            "version": "==1.25.9"
    "develop": {}

Where the dependencies on certifi, chardet, idna, requests and urllib3 come from is not entirely clear. I could be wrong, but it seems like a waste of resources.

To better test this, your sample project should have some dependencies. The project above has only setuptools, pkg_resources, pip and wheel. To test this, create a file with your dependencies: like mydep. Here is some pseudo code.

import mydep

result = mydep.action()

print('the result of mydep actyion: ' + result)

Run the code like.

pipenv run python


Version Date Notes
0.1.4 2023-03-06 Improve writing
0.1.3 2022-07-13 Shell->bash, move history, formatting
0.1.2 2022-05-10 Fix json syntax highlighting
0.1.1 2022-05-09 PDF: False (no ⠼ (U+283C), 🐍 (U+1F40D) in font
WenQuanYi Micro Hei Mon//OT:script=lat)
0.1.0 2020-05-18 Initial release

