Pipfile & Pipfile.lock

Pipfile contains the specification for the project top-level requirements and any desired specifiers. This file is managed by the developers invoking pipenv commands. The Pipfile uses inline tables and the TOML Spec.

Pipfile.lock replaces the requirements.txt file used in most Python projects and adds security benefits of tracking the packages hashes that were last locked. This file is managed automatically through locking actions.

You should add both Pipfile and Pipfile.lock to the project’s source control.

[pipenv] Directives

Pipfile may contain a [pipenv] section to control the behaviour of pipenv itself. Some available settings include:

  • allow_prereleases - Tell pipenv to install pre-release versions of a package -i.e. a version with an alpha/beta/etc. suffix, such as 1.0b1. Equivalent to passing the --pre flag on the command line.

  • disable_pip_input - Prevent pipenv from asking for input. Equivalent to the --no-input flag.

  • install_search_all_sources - Allow installation of packages from an existing Pipfile.lock to search all defined indexes for the constrained package version and hash signatures. See Specifying Package Indexes.

  • sort_pipfile - Sort package names alphabetically inside each category. Categories will be sorted and updated on install and uninstall. This is purely cosmetic to make reading easier for humans, and has no effect on installation order or dependency resolution. Note that Pipfile.lock packages are always sorted alphabetically.

Example Pipfile

Here is a simple example of a Pipfile and the resulting Pipfile.lock.

url = "https://pypi.org/simple"
verify_ssl = true
name = "pypi"

Django = "==4.*"
waitress = {version = "*", markers="sys_platform == 'win32'"}
gunicorn = {version = "*", markers="sys_platform == 'linux'"}

pytest-cov = "==3.*"

Example Pipfile.lock

    "_meta": {
        "hash": {
            "sha256": "d09f41c21ecfb3b019ace66b61ea1174f99e8b0da0d39e70a5c1cf2363d8b88d"
        "pipfile-spec": 6,
        "requires": {},
        "sources": [
                "name": "pypi",
                "url": "https://pypi.org/simple",
                "verify_ssl": true
    "default": {
        "asgiref": {
            "hashes": [
            "markers": "python_version >= '3.7'",
            "version": "==3.6.0"
        "django": {
            "hashes": [
            "index": "pypi",
            "version": "==4.1.7"
        "gunicorn": {
            "hashes": [
            "index": "pypi",
            "markers": "sys_platform == 'linux'",
            "version": "==20.1.0"
        "setuptools": {
            "hashes": [
            "markers": "python_version >= '3.7'",
            "version": "==67.3.2"
        "sqlparse": {
            "hashes": [
            "markers": "python_version >= '3.5'",
            "version": "==0.4.3"
        "waitress": {
            "hashes": [
            "markers": "sys_platform == 'win32'",
            "version": "==2.1.2"
    "develop": {
        "attrs": {
            "hashes": [
            "markers": "python_version >= '3.6'",
            "version": "==22.2.0"
        "coverage": {
            "extras": [
            "hashes": [
            "markers": "python_version >= '3.7'",
            "version": "==7.1.0"
        "iniconfig": {
            "hashes": [
            "markers": "python_version >= '3.7'",
            "version": "==2.0.0"
        "packaging": {
            "hashes": [
            "markers": "python_version >= '3.7'",
            "version": "==23.0"
        "pluggy": {
            "hashes": [
            "markers": "python_version >= '3.6'",
            "version": "==1.0.0"
        "pytest": {
            "hashes": [
            "markers": "python_version >= '3.7'",
            "version": "==7.2.1"
        "pytest-cov": {
            "hashes": [
            "index": "pypi",
            "version": "==3.0.0"

Importing from requirements.txt

For projects utilizing a requirements.txt pipenv can import the contents of this file and create a Pipfile and Pipfile.lock for you:

$ pipenv install -r path/to/requirements.txt

If your requirements file has version numbers pinned, you’ll likely want to edit the new Pipfile to only keep track of top level dependencies and let pipenv keep track of pinning sub-dependencies in the lock file.

Pipfile.lock Security Features

Pipfile.lock leverages the security of package hash validation in pip. The Pipfile.lock is generated with the sha256 hashes of each downloaded package. This guarantees you’re installing the same exact packages on any network as the one where the lock file was last updated, even on untrusted networks.

We recommend designing CI/CD deployments whereby the build does not alter the lock file as a side effect. In other words, you can use pipenv lock or pipenv upgrade to adjust your lockfile through local development. The PR process of reviewing and approving those lock changes before deploying to production that version of the lockfile is a recommended best practice. In other words: always avoid having your CI issue lock, update, upgrade uninstall or any commands that will relock.

Generate requirements.txt output from lock file

$ pipenv requirements

Package Category Groups

Pipenv supports arbitrarily named package categories in the Pipfile/Pipfile.lock for organizing dependencies into different groups.

Traditionally there were only two package groups, and they were named different between the Pipfile and Pipfile.lock:

  • packages in the Pipfile corresponds to default group in the lockfile.

  • dev-packages in the Pipfile corresponds to develop group in the lockfile.

The default/packages group is what you interact with when specifying no particular categories, whereas the develop/dev-packages group is typically what you interact with when specifying the --dev or -d flag.

Beginning in pipenv==2022.10.9 support for named package categories was generalized such that any non-reserved keywords may be used to create named package groups other than the original groups. All named categories (other than the special default/develop) will use the category name consistently between the Pipfile and Pipfile.lock

General Notes and Recommendations

  • Keep both Pipfile and Pipfile.lock in version control.

  • pipenv install package-name adds specifiers to Pipfile and rebuilds the lock file based on the Pipfile specs, by utilizing the internal resolver of pip.

  • Not all the required sub-dependencies need be specified in Pipfile, instead only add specifiers that make sense for the stability of your project. Example: requests requires cryptography but (for reasons) you want to ensure cryptography is pinned to a particular version set.

  • Consider specifying your target Python version in your Pipfile’s [requires] section. For this use either python_version in the format X.Y (or X) or python_full_version in X.Y.Z format.

  • Considering making use of named package categories to further isolate dependency install groups for large monoliths.