-r requirements.txt
# 這裡全部釘版，讓 CI（tests.yml 的 lint／audit／package job）、本機與 .pre-commit-config.yaml 用同一組工具版本；
# 升版要刻意為之（Dependabot 會提議）。
# Everything here is pinned so CI (tests.yml lint / audit / package jobs), local runs and
# .pre-commit-config.yaml enforce the same tool versions; bump deliberately (Dependabot proposes bumps).
ruff==0.16.10
# .pre-commit-config.yaml 的 ruff-pre-commit rev 要與這個釘版相同（tests/test_review_build.py 會檢查）／ The ruff-pre-commit rev in .pre-commit-config.yaml must equal this pin (tests/test_review_build.py checks it)
mypy==2.4.0
# CI 以 --cov=vibeharness 跑 pytest（版本與 requirements.lock 相同）／ CI runs pytest with --cov=vibeharness (same version as requirements.lock)
pytest-cov==7.1.0
# CI 的 wheel 打包 job、publish.yml 與本機發布建置使用 ／ Used by the wheel-packaging job in CI, publish.yml and local release builds
build==1.6.1
# CI 的 audit job 對 requirements.lock 使用 ／ Used by the CI audit job against requirements.lock
pip-audit==2.10.1
