I am working on a python library and we are currently using pip-tools to pin dependencies.
pip-tools
E.g. a basic requirements.in:
requirements.in
blac