Our production environment was python3.6. Devs rebuilt the requirements.txt with python3.8.
When we attempted to use the requirements.txt with python3.6, we couldn't because a package was missing (and we installed with `--require-hashes`). The dependency was `importlib-metadata` iirc.
But googling around, here's an example of a package that has dependencies that changed based on the python version: https://github.com/pypa/pep517/blob/main/pyproject.toml#L13 .
In our case, we just made sure to rebuild the requirements.txt with the version that matched our production; not sure if there's a "nice" way to support multiple versions with pip-tools.
I might be splitting hairs here, but this seems like an oxymoron: if it's agnostic on anything, it's not really a lock file.
If you don't want to fire up docker, you'll have to look elsewhere other than just pip-tool