Packaging Best Practices
Rules for packages that install cleanly, version predictably, and publish safely.
Search across all documentation pages
Rules for packages that install cleanly, version predictably, and publish safely.
readme = "README.md" in [project].[project].v1.2.3 tag for 1.2.3 release.pip install dist/*.whl in fresh venv before upload.Libraries: PyPI with semver. Applications: Docker or pipx.
If other teams or the community install it. Internal-only: private index.
Check pypi.org for availability. Lowercase, hyphens, no typosquatting.
MIT or Apache-2.0 for most open source. Legal review for proprietary.
Yes for sdist. Tests not installed with wheel (exclude via config).
README notice, PyPI classifier Development Status :: 7 - Inactive, final release.
Independent versions per package. Separate PyPI projects.
PyPI supports PGP-signed attestations. Trusted publishing is the modern default.
When meaningful changes accumulate. Patch releases for security fixes immediately.
Declare in build config. Access via importlib.resources at runtime.
Stack versions: This page was written for Python 3.14.0, FastAPI 0.115+, Django 5.2, Flask 3.1, Pydantic 2, PyTorch 2.6+, pandas 2.2+, Polars 1.x, ruff 0.9+, and uv 0.6+.
Reviewed by Chris St. John·Last updated Jul 19, 2026