Remove packaging as a runtime dependency of opentelemetry-instrumentation-sqlalchemy
Summary
opentelemetry-instrumentation-sqlalchemy declares packaging >= 21.0 as a
runtime dependency, used solely to compare the installed SQLAlchemy version.
Motivation: the auto-instrumentation injector
The auto-instrumentation injector (the Python auto-instrumentation shipped by the
OpenTelemetry Operator) bundles the instrumentation packages and all of their
runtime dependencies into an init container and prepends that directory to the
target application's PYTHONPATH. Every runtime dependency is therefore injected
into the user's application process, where a common library like packaging
risks version shadowing/conflicts and adds to the injected payload. Removing it
shrinks that footprint. See #4882 for the full rationale.
Where it is used
pyproject.toml: packaging >= 21.0 in dependencies.
src/opentelemetry/instrumentation/sqlalchemy/__init__.py:241 (and 258, 299,
302): parse_version(sqlalchemy.__version__).release >= (1, 4).
Purpose: spec-compliant PEP 440 parsing of sqlalchemy.__version__ to branch
behavior by installed SQLAlchemy version.
Proposed resolution
Import the PEP 440 Version from the internal implementation added in #4882
(opentelemetry.instrumentation._packaging.version) instead of packaging, and
remove packaging from this package's dependencies.
Depends on #4882, which introduces opentelemetry.instrumentation._packaging
in opentelemetry-instrumentation (a dependency of this package).
Remove
packagingas a runtime dependency ofopentelemetry-instrumentation-sqlalchemySummary
opentelemetry-instrumentation-sqlalchemydeclarespackaging >= 21.0as aruntime dependency, used solely to compare the installed SQLAlchemy version.
Motivation: the auto-instrumentation injector
The auto-instrumentation injector (the Python auto-instrumentation shipped by the
OpenTelemetry Operator) bundles the instrumentation packages and all of their
runtime dependencies into an init container and prepends that directory to the
target application's
PYTHONPATH. Every runtime dependency is therefore injectedinto the user's application process, where a common library like
packagingrisks version shadowing/conflicts and adds to the injected payload. Removing it
shrinks that footprint. See #4882 for the full rationale.
Where it is used
pyproject.toml:packaging >= 21.0independencies.src/opentelemetry/instrumentation/sqlalchemy/__init__.py:241(and 258, 299,302):
parse_version(sqlalchemy.__version__).release >= (1, 4).Purpose: spec-compliant PEP 440 parsing of
sqlalchemy.__version__to branchbehavior by installed SQLAlchemy version.
Proposed resolution
Import the PEP 440
Versionfrom the internal implementation added in #4882(
opentelemetry.instrumentation._packaging.version) instead ofpackaging, andremove
packagingfrom this package'sdependencies.Depends on #4882, which introduces
opentelemetry.instrumentation._packagingin
opentelemetry-instrumentation(a dependency of this package).