Python: Store verifiable dependency description and build environment details as separate parts of a reproducible release contract
Store runtime dependencies in [project.dependencies] and build requirements in [build-system.requires] of pyproject.toml, then pin exact versions with sha256 hashes in a separate requirements file to create a byte-level verifiable release contract.
Python / pyproject.toml / dependencies / reproducibility / pip / hash-checking / build-system / release-contract