Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Python package versions: test a declared range against parsed versions

Last updated: 30 Sept 20264 min read
tutorial
IntermediateBy AITrove Editorial

A version specifier selects candidate releases according to a declared package-version rule.

Download Python source kit

Operation contract

The fixture uses the packaging library to compare three candidate versions against a bounded range. An explicit stable-only policy excludes the prerelease candidate; the lower stable release is included and a later major release is outside the range. This is a selection predicate, not a dependency solver: it says nothing about transitive requirements, platform wheels or whether the candidate bytes came from a trusted publisher.

Failure and ownership boundary

Comparing version strings lexically would order multi-digit components incorrectly. A deployment lock needs exact artifacts and hashes or another authenticated release policy, plus a tested platform/runtime matrix. Python pyproject.toml: build a wheel and inspect its metadata, Python wheel installation: test the built artifact outside its source directory and Python artifact hashes: verify owned bytes against a separately trusted expectation cover later stages.

Tested environment

Dependency check: this program was executed on CPython 3.14.6 with packaging==26.3. Install these versions in a separate virtual environment. The download includes the recorded environment snapshot; no third-party package is part of the website runtime.

Working program

python
from packaging.specifiers import SpecifierSet
from packaging.version import Version

accepted = SpecifierSet(">=2.4,<3")
for candidate in ("2.4", "2.5rc1", "3.0"):
    print(candidate, accepted.contains(Version(candidate), prereleases=False))

Output

Output
2.4 True
2.5rc1 False
3.0 False

Costs and limits

Parsing and comparisons depend on version-string length and number of candidate constraints. The fixture checks three short values. Resolver search can have much higher cost and is not performed here.

Common Mistakes

  • Do not compare package versions as plain strings.
  • A matching specifier is neither a resolved dependency graph nor authenticated code.

Connected lessons

Python pyproject.toml: build a wheel and inspect its metadata, Python wheel installation: test the built artifact outside its source directory, Python artifact hashes: verify owned bytes against a separately trusted expectation.

python
version-specifier-check
Storage details