A version specifier selects candidate releases according to a declared package-version rule.
Python package versions: test a declared range against parsed versions
Operation contract
The fixture uses the packaging library to compare three candidate versions against a bounded range. An explicit stable-only policy excludes the prerelease candidate; the lower stable release is included and a later major release is outside the range. This is a selection predicate, not a dependency solver: it says nothing about transitive requirements, platform wheels or whether the candidate bytes came from a trusted publisher.
Failure and ownership boundary
Comparing version strings lexically would order multi-digit components incorrectly. A deployment lock needs exact artifacts and hashes or another authenticated release policy, plus a tested platform/runtime matrix. Python pyproject.toml: build a wheel and inspect its metadata, Python wheel installation: test the built artifact outside its source directory and Python artifact hashes: verify owned bytes against a separately trusted expectation cover later stages.
Tested environment
Dependency check: this program was executed on CPython 3.14.6 with packaging==26.3. Install these versions in a separate virtual environment. The download includes the recorded environment snapshot; no third-party package is part of the website runtime.
Working program
from packaging.specifiers import SpecifierSet
from packaging.version import Version
accepted = SpecifierSet(">=2.4,<3")
for candidate in ("2.4", "2.5rc1", "3.0"):
print(candidate, accepted.contains(Version(candidate), prereleases=False))Output
2.4 True
2.5rc1 False
3.0 FalseCosts and limits
Parsing and comparisons depend on version-string length and number of candidate constraints. The fixture checks three short values. Resolver search can have much higher cost and is not performed here.
Common Mistakes
- Do not compare package versions as plain strings.
- A matching specifier is neither a resolved dependency graph nor authenticated code.
Connected lessons
Python pyproject.toml: build a wheel and inspect its metadata, Python wheel installation: test the built artifact outside its source directory, Python artifact hashes: verify owned bytes against a separately trusted expectation.
