# Enforcing dependencies in my own package

**URL:** <https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967>\
**Category:** General Usage\
**Created:** [October 30, 2018, 1:14pm UTC](https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967 "2018-10-30T13:14:52Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![macroscian](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/macroscian/32/5790_2.png) [@macroscian](https://discourse.julialang.org/u/macroscian)\
**Post date:** [October 30, 2018, 1:14pm UTC](https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967/1 "2018-10-30T13:14:52Z")

</div>

I’m trying to write a package (my first, so apologies for ignorance) using Julia 1.0.1 that depends on the master version of an existing package Pages.jl, but am struggling to enforce this.  
My current method is, in REPL

```julia
using Pkg
Pkg.activate(".")
Pkg.add(PackageSpec(name="Pages", rev="master"))

```

to build the Project.toml and Manifest.toml, the latter now containing

```julia
[[Pages]]
deps = ["HTTP", "JSON", "PlotlyBase", "Sockets", "Test"]
git-tree-sha1 = "a82e00554e2956010b207656d347ff4cae0dee05"
repo-rev = "master"
repo-url = "https://github.com/EricForgy/Pages.jl.git"
uuid = "7c165e09-dada-5b64-9fdc-39b801c58527"
version = "0.2.0+"

```

which seems to capture the requirement in the repo-rev. But when I attempt to load my package by

```julia
Pkg.add(PackageSpec(url="https://github.com/macroscian/uv_package"))

```

which is my (poorly written) package, which contains `using Pages#master` in the module, and also has the above Manifest.toml in the directory, it reports, under “Resolving package versions…” that it’s got Pages v0.2.0, which is a few crucial revisions prior to the head of master (but also an acceptable version in the manifest.toml above). As a double-check, the functionality of the third-party package is correspondingly not the latest commit.

I’ve almost certainly done something stupid and can’t spot the correct approach in the documentation, so any help would be greatly appreciated in ensuring that I can enforce the dependency on a later commit than is tagged  
Thanks - Gavin

---

<div class="post-metadata">

**Author:** ![fredrikekre](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fredrikekre/32/1688_2.png) [@fredrikekre](https://discourse.julialang.org/u/fredrikekre)\
**Post date:** [October 30, 2018, 1:30pm UTC](https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967/2 "2018-10-30T13:30:08Z")

</div>

1. You can’t depend on branches.
2. The `Manifest.toml` file in the package is not used at all (this is the most common misconception about how Pkg works).
3. `using Pages#master` is not valid syntax.

If you want to use a specific branch of one of the dependencies you need to explicitly add that branch, either before or after you add your own package e.g.

```julia
pkg> add https://github.com/macroscian/uv_package
[...]

pkg> add Pages#master

```

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [October 30, 2018, 1:33pm UTC](https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967/3 "2018-10-30T13:33:52Z")

</div>

> [@fredrikekre](#):
>
> The `Manifest.toml` file in the package is not used at all (this is the most common misconception about how Pkg works)

did this change? cf

> [@Does Manifest.toml belong in the repository?](https://discourse.julialang.org/t/does-manifest-toml-belong-in-the-repository/12029/3):
>
> It might also be nice to have a manifest checked into package repos for a few reasons: So that you have at least one known good configuration that presumably passed tests and such. To keep the different developers of the package in sync using similar setups. Of course, 2 cuts both ways: it’s nice that all the devs have similar setups and they can upgrade in sync, but that means that there’s less testing of the package with different setups. Benefit 1 may be better accomplished with some kind …

---

<div class="post-metadata">

**Author:** ![fredrikekre](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fredrikekre/32/1688_2.png) [@fredrikekre](https://discourse.julialang.org/u/fredrikekre)\
**Post date:** [October 30, 2018, 1:34pm UTC](https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967/4 "2018-10-30T13:34:41Z")

</div>

> [@Tamas\_Papp](#):
>
> did this change?

No.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [October 30, 2018, 1:46pm UTC](https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967/5 "2018-10-30T13:46:47Z")

</div>

I am confused, can you please help me understand why it was recommended to commit a `Manifest.toml` when it is not used at all?

---

<div class="post-metadata">

**Author:** ![fredrikekre](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fredrikekre/32/1688_2.png) [@fredrikekre](https://discourse.julialang.org/u/fredrikekre)\
**Post date:** [October 30, 2018, 1:49pm UTC](https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967/6 "2018-10-30T13:49:20Z")

</div>

> [@Tamas\_Papp](#):
>
> I am confused, can you please help me understand why it was recommended to commit a `Manifest.toml` when it is not used at all?

Stefan recommended it, I don’t 😛 (at least not as long as it is used by Pkg.test).

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [October 30, 2018, 1:55pm UTC](https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967/7 "2018-10-30T13:55:22Z")

</div>

You [also recommended it](https://github.com/JuliaLang/Pkg.jl/issues/492#issuecomment-417358648), in another context (to be fair, along with `Pkg.up()`) 😛

So is that it isn’t used _automatically_, but `Pkg.up()` and `Pkg.resolve()` _will_ use it if available?

---

<div class="post-metadata">

**Author:** ![fredrikekre](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fredrikekre/32/1688_2.png) [@fredrikekre](https://discourse.julialang.org/u/fredrikekre)\
**Post date:** [October 30, 2018, 2:33pm UTC](https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967/8 "2018-10-30T14:33:46Z")

</div>

> [@Tamas\_Papp](#):
>
> You [also recommended it](https://github.com/JuliaLang/Pkg.jl/issues/492#issuecomment-417358648)

Bit of a stretch to call that a recommendation 🙂

> [@Tamas\_Papp](#):
>
> So is that it isn’t used _automatically_ , but `Pkg.up()` and `Pkg.resolve()` _will_ use it if available?

No, it will only ever be used if the `Project.toml` file of the package is the active project. This is not the case when you `add` a package, since you usually add it to some other environment (like the default `v1.0` environment).

On CI however, we start julia with the package itself as the active project, and then we of course use the `Manifest.toml` that is in the package, if it exists. This is IMO bad, since you can have some weird configuration in there, and tests passes, but it will not be representative of the environment users use the package in.

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [October 30, 2018, 2:43pm UTC](https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967/9 "2018-10-30T14:43:45Z")

</div>

It’s useful because it provides a record of a working state for the project by itself, which is generally good to have. That’s why it should be used for CI: so that you know that a particular configuration worked. When using it as a dependency, it may not be used in that same configuration, but it’s still good to know _some_ working configuration. Whatever project is using it as a dependency in a different configuration should check in its manifest, which then serves as a record of another working configuration. If that project does recursive dependency testing, then you not only know that the main project works and passes tests but also that all of its dependencies pass their tests. Of course, that level of testing is not required.

---

<div class="post-metadata">

**Author:** ![chelseas](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/chelseas/32/12148_2.png) [@chelseas](https://discourse.julialang.org/u/chelseas)\
**Post date:** [April 13, 2022, 6:34am UTC](https://discourse.julialang.org/t/enforcing-dependencies-in-my-own-package/16967/10 "2022-04-13T06:34:23Z")

</div>

IS this still true – you can’t depend on a main / master branch? 😕
