@@ -64,6 +64,15 @@ packages:
6464 require :
6565 - ' @0.0.5'
6666 - +python
67+ # cairo@1.18.0: is uses the meson recipe. The meson build enforces variants
68+ # that are all-enabled or all-disabled. The "all-enabled" variants are set to help
69+ # the concretizer resolve the correct version without disabling all variants.
70+ # pango/harfbuzz/gobject-introspection need cairo+gobject; without pinning it
71+ # the concretizer builds cairo both ways and the two collide on one modulefile.
72+ cairo :
73+ require :
74+ - ' @1.18:'
75+ - +zlib+ft+fc+png+pdf+gobject
6776 cdo :
6877 require :
6978 - ~openmp
@@ -109,10 +118,11 @@ packages:
109118 - +netcdf
110119 - +png
111120 - +tools
121+ # uwtools@2.17: needs ecflow@5.16:; leave the version to the concretizer
112122 ecflow :
113123 require :
114- - ' @5.11.4'
115124 - +ui
125+ - ' @5.18:'
116126 eckit :
117127 require :
118128 - ' @2.0.7'
@@ -404,30 +414,37 @@ packages:
404414 # are removed, which itself is problematic.
405415 python :
406416 require :
407- - ' @3.11'
408- - ~crypt
417+ - ' @3.13'
418+ # The crypt variant only exists for python<=3.12 since the module was dropped.
419+ # An unconditional ~crypt caps python at 3.12
420+ - spec : ~crypt
421+ when : ' @:3.12'
409422 # Not sure about the exact version requirements, but earlier
410423 # versions (definitely 4.5.3 and earlier) don't work with newer
411424 # py-setuptools (version 68 and later) because of a breaking
412425 # change: error in beautifulsoup4 setup command: use_2to3 is invalid
413426 py-beautifulsoup4 :
414427 require :
415428 - ' @4.12.3:'
429+ # Pin to avoid duplicates
430+ py-pybind11 :
431+ require :
432+ - ' @:2'
416433 py-cartopy :
417434 require :
418435 - +plotting
419- # See py-pycparser
420- py-click :
421- require :
422- - ' @8.1.8'
423436 # Pin py-colorama to avoid duplicate packages, hopefully can be removed soon
424437 py-colorama :
425438 require :
426439 - ' @0.4.6'
427- # Pin to version 42 to avoid maturin dependency that breaks Intel oneAPI builds
428- py-cryptography :
440+ # No tutorials extras; prevent py-pandas-datareader dep with broken configparser call
441+ py-arch :
442+ require :
443+ - ~tutorial
444+ # Exclude @:2021.3.0 (broken configparser call), which its default +bag/+delayed variants select
445+ py-dask :
429446 require :
430- - ' @42 '
447+ - ' @2023.4.1: '
431448 py-h5py :
432449 require :
433450 - ~mpi
@@ -453,65 +470,45 @@ packages:
453470 # To avoid duplicate packages
454471 py-numpy :
455472 require :
456- - ' @1 '
473+ - ' @=2.4.6 '
457474 # Restrict py-pandas to older versions compatible with py-numpy and py-xarray
458475 py-pandas :
459476 require :
460477 - ' @:2'
461- # See py-pycparser
462- py-pandas-datareader :
463- require :
464- - ' @:0.10'
478+ # py-versioneer is unavoidably duplicated by pins in py-pyogrio (@0.28) and
479+ # py-partd (@0.29). py-pandas is unconstrained and can further cascade splits
480+ # into py-xarray/met/metplus/jedi-base-env. This constraints py-versioneer to @0.28
481+ # (shared with py-pyogrio) so only py-versioneer itself is duplicated.
482+ - ^py-versioneer@0.28
465483 # To avoid duplicate packages
466484 py-poetry-core :
467485 require :
468486 - ' @1.7'
469- # See py-pycparser
470- py-pooch :
471- require :
472- - ' @1.7.0'
473- # Need older version of py-pycparser until we can update setuputils to >= 77 ?
474- # https://github.com/pydata/xarray/issues/10588
475- py-pycparser :
476- require :
477- - ' @2.21'
478487 # Need at least py-pygithub@2.7 for self-hosted runner management
479488 py-pygithub :
480489 require :
481490 - ' @2.7:'
482- # See py-pycparser
483- py-imageio :
484- require :
485- - ' @2.37.0'
486491 # This version builds with Intel oneAPI compilers, newer versions don't
487492 py-pyogrio :
488493 require :
489494 - ' @0.9.0'
490- # See py-pycparser
491- py-pyparsing :
492- require :
493- - ' @3.1.2'
494495 # To avoid duplicate packages
495496 py-python-dateutil :
496497 require :
497498 - ' @2'
498- # To avoid duplicate packages
499+ # To avoid duplicate packages, pin to recent version.
499500 py-requests :
500501 require :
501- - ' @2.32.3 '
502+ - ' @2.32: '
502503 # To avoid duplicate packages
503504 py-ruamel-yaml :
504505 require :
505506 - ' @0.17.16'
506507 # https://github.com/JCSDA/spack-stack/issues/1942
507508 # https://github.com/spack/spack-packages/issues/3695
508- py-setuptools :
509- require :
510- - ' @73.0.1'
511- # See py-pycparser
512- py-sphinxcontrib-bibtex :
513- require :
514- - ' @2.5.0'
509+ # NOTE: py-setuptools was pinned @73.0.1 for the py3.11 stack; removed for the
510+ # py3.12/numpy2 migration since modern packages (e.g. py-xarray@2025.7) require
511+ # py-setuptools@77.0.3:. Re-evaluate issue #3695 if setuptools duplicates recur.
515512 py-torch :
516513 require :
517514 - +custom-protobuf
@@ -521,10 +518,10 @@ packages:
521518 require :
522519 - ' @1.26.20'
523520 # OR - '@1.26.12' ?
524- # To avoid duplicate packages
521+ # Not '@=0.28'; py-pyogrio needs 0.28 and py-partd/py-dask 0.29, build-only so a split is fine
525522 py-versioneer :
526523 require :
527- - ' @= 0.28'
524+ - ' @0.28: '
528525 # On a per-site basis, either set qt to buildable: false
529526 # or add requirement to build with gcc for Intel oneAPI
530527 qt :
@@ -565,9 +562,10 @@ packages:
565562 upp :
566563 require :
567564 - ' @10.0.10'
565+ # Upper bound keeps the branch version 'main' out; spack sorts it above 2.x
568566 uwtools :
569567 require :
570- - ' @2.7. 2'
568+ - ' @2.17: 2'
571569 w3emc :
572570 require :
573571 - ' @2.13.0'
0 commit comments