Skip to content
Novus Examples
txt439 B

pip constraints.txt

A pip constraints file pinning the same nine fictional packages. Constraints bound a resolution without adding dependencies, so a tool that treats this like requirements.txt installs nine packages too many. Every package, version, hash and licence is fictional — the tree describes nothing real.

Preview — first 13 linestxt
# SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented.
# Constraints only: these pin versions WITHOUT requesting installation.

example-router==2.1.3
example-http-core==1.8.0
example-metrics==4.0.0
example-cache==0.9.2
example-crypto-shim==1.2.0
example-logger==3.4.1
example-retry==1.0.4
example-json-path==2.0.5
example-yaml-lite==1.1.7

Specifications

Seed
51200
Sample Only
true
Ecosystem
pip
Constraints
9
Installs
0
Line Endings
LF

Testing contract

Expected to pass
Scenario
Distinguish a constraints file from a requirements file.
Expected result
Resolver applies 9 version bounds and adds 0 packages to the install set.

What is a .txt file?

TXT is a plain-text file containing unformatted character data with no styling or structure beyond line breaks. Its interpretation depends on character encoding, most commonly UTF-8, and on line-ending convention. It is the most universal and portable text container.

How to use this file

Use an example TXT to test encoding detection, line-ending (LF versus CRLF) handling, and any tool that reads or streams raw text input.

How to use this file for testing

“pip constraints.txt” is a deterministic Novus Examples fixture for Config parsing, Conversion testing. TOML and INI configuration files with nested sections and typed values — for testing config parsers and loaders.

Documented properties for this file: seed 51200 · LF. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.

Point your config loader at the file and assert it reads the documented sections and typed values, including any deliberately-tricky nesting or comments.

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.