# Pin all packages of a project

**URL:** <https://discourse.julialang.org/t/pin-all-packages-of-a-project/39308>\
**Category:** General Usage\
**Created:** [May 11, 2020, 8:36pm UTC](https://discourse.julialang.org/t/pin-all-packages-of-a-project/39308 "2020-05-11T20:36:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![heliosdrm](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/heliosdrm/32/3851_2.png) [@heliosdrm](https://discourse.julialang.org/u/heliosdrm)\
**Post date:** [May 11, 2020, 8:36pm UTC](https://discourse.julialang.org/t/pin-all-packages-of-a-project/39308/1 "2020-05-11T20:36:30Z")

</div>

Is there a simple way to lock the versions of all the packages of a given project? Something like `]pin X` for all (direct and indirect) dependencies of its environment.

The `Manifest.toml` file is a very nice way of ensuring that a project is reproducible — until I or someone else mess it up by adding or updating packages when that project is activated. If this happens without a careful record of the project’s history, such an accident may be a pain.

I think it would be nice to have a command — e.g. `]lock` that protects the `Manifest.toml` from being changed by other `Pkg` commands (and `]unlock` for the opposite).

And maybe, also allow `]pin` without arguments, such that all the direct dependencies are fixed in the current version.

---

<div class="post-metadata">

**Author:** ![tbeason](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tbeason/32/15898_2.png) [@tbeason](https://discourse.julialang.org/u/tbeason)\
**Post date:** [May 11, 2020, 9:27pm UTC](https://discourse.julialang.org/t/pin-all-packages-of-a-project/39308/2 "2020-05-11T21:27:47Z")

</div>

Not sure but I think you can already do this (not as easily as what you are suggesting though) as you can already pin individual packages. So you could probably just do that for all of the packages in the project.

[https://julialang.github.io/Pkg.jl/v1/managing-packages/#Pinning-a-package-1](https://julialang.github.io/Pkg.jl/v1/managing-packages/#Pinning-a-package-1)

---

<div class="post-metadata">

**Author:** ![kristoffer.carlsson](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/kristoffer.carlsson/32/22_2.png) [@kristoffer.carlsson](https://discourse.julialang.org/u/kristoffer.carlsson)\
**Post date:** [May 13, 2020, 9:16am UTC](https://discourse.julialang.org/t/pin-all-packages-of-a-project/39308/3 "2020-05-13T09:16:22Z")

</div>

> [@heliosdrm](#):
>
> If this happens without a careful record of the project’s history, such an accident may be a pain.

Note that you can always just `undo`

```julia
(@v1.4) pkg> up # oops
...
   Updating `~/.julia/environments/v1.4/Project.toml`
  [587475ba] ↑ Flux v0.10.4 #master (https://github.com/FluxML/Flux.jl.git) ⇒ v0.10.5 #master (https://github.com/FluxML/Flux.jl.git)
  [91a5bcdd] ↑ Plots v1.2.3 ⇒ v1.2.4
  [295af30f] ↑ Revise v2.5.4 ⇒ v2.6.6
  [e88e6eb3] ↑ Zygote v0.4.19 #master (https://github.com/FluxML/Zygote.jl.git) ⇒ v0.4.20 #master (https://github.com/FluxML/Zygote.jl.git)
   Updating `~/.julia/environments/v1.4/Manifest.toml`
  [4c555306] ↑ ArrayLayouts v0.2.5 ⇒ v0.3.1
  [fa961155] ↑ CEnum v0.2.0 ⇒ v0.3.0
  [c5f51814] ↑ CUDAdrv v6.2.3 ⇒ v6.3.0
  [be33ccc6] ↑ CUDAnative v3.0.4 ⇒ v3.1.0
  [587475ba] ↑ Flux v0.10.4 #master (https://github.com/FluxML/Flux.jl.git) ⇒ v0.10.5 #master (https://github.com/FluxML/Flux.jl.git)
  [d9f16b24] + Functors v0.1.0
  [0c68f7d7] ↑ GPUArrays v3.2.0 ⇒ v3.3.0
  [61eb1bfa] + GPUCompiler v0.2.0
  [e88e6eb3] ↑ Zygote v0.4.19 #master (https://github.com/FluxML/Zygote.jl.git) ⇒ v0.4.20 #master (https://github.com/FluxML/Zygote.jl.git)
  [9fa8497b] + Future
   Building Plots → `~/.julia/packages/Plots/zOV0T/deps/build.log`

(@v1.4) pkg> undo # pwew
   Updating `~/.julia/environments/v1.4/Project.toml`
  [587475ba] ↓ Flux v0.10.5 #master (https://github.com/FluxML/Flux.jl.git) ⇒ v0.10.4 #master (https://github.com/FluxML/Flux.jl.git)
  [91a5bcdd] ↓ Plots v1.2.4 ⇒ v1.2.3
  [295af30f] ↓ Revise v2.6.6 ⇒ v2.5.4
  [e88e6eb3] ↓ Zygote v0.4.20 #master (https://github.com/FluxML/Zygote.jl.git) ⇒ v0.4.19 #master (https://github.com/FluxML/Zygote.jl.git)
   Updating `~/.julia/environments/v1.4/Manifest.toml`
  [4c555306] ↓ ArrayLayouts v0.3.1 ⇒ v0.2.5
  [fa961155] ↓ CEnum v0.3.0 ⇒ v0.2.0
  [c5f51814] ↓ CUDAdrv v6.3.0 ⇒ v6.2.3
  [be33ccc6] ↓ CUDAnative v3.1.0 ⇒ v3.0.4
  [587475ba] ↓ Flux v0.10.5 #master (https://github.com/FluxML/Flux.jl.git) ⇒ v0.10.4 #master (https://github.com/FluxML/Flux.jl.git)
  [d9f16b24] - Functors v0.1.0
  [0c68f7d7] ↓ GPUArrays v3.3.0 ⇒ v3.2.0
  [61eb1bfa] - GPUCompiler v0.2.0
  [e88e6eb3] ↓ Zygote v0.4.20 #master (https://github.com/FluxML/Zygote.jl.git) ⇒ v0.4.19 #master (https://github.com/FluxML/Zygote.jl.git)
  [9fa8497b] - Future

```

---

<div class="post-metadata">

**Author:** ![heliosdrm](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/heliosdrm/32/3851_2.png) [@heliosdrm](https://discourse.julialang.org/u/heliosdrm)\
**Post date:** [May 13, 2020, 10:02am UTC](https://discourse.julialang.org/t/pin-all-packages-of-a-project/39308/4 "2020-05-13T10:02:03Z")

</div>

I didn’t know `undo`. That’s great!

---

<div class="post-metadata">

**Author:** ![wulpuqu](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/wulpuqu/32/17640_2.png) [@wulpuqu](https://discourse.julialang.org/u/wulpuqu)\
**Post date:** [October 13, 2020, 11:59am UTC](https://discourse.julialang.org/t/pin-all-packages-of-a-project/39308/5 "2020-10-13T11:59:11Z")

</div>

Starting julia with `JULIA_DEPOT_PATH=/depot/path/ julia --project=/project/dir` to specify your own depot path and the path of the project. Something like this should work:

```julia
using Pkg
proj = Pkg.project()
deps = proj.dependencies
topin = [Pkg.PackageSpec(k,deps[k]) for k in keys(deps) ]
for pkg in topin
    Pkg.pin(pkg)
end

```

And to `free` packages you just have to change the for loop by

```julia
for pkg in topin
    Pkg.free(pkg)
end

```
