Skip to content

Pitloom

PyPI - Version GitHub License OpenSSF Best Practices OpenSSF Scorecard DOI

Pitloom automates the generation of SPDX 3-compliant software bills of materials (SBOMs) for Python applications and AI models.

It extracts metadata directly from Python projects, whether declared in the standard [project] table (Flit, Hatchling, PDM, uv_build and others), Poetry's [tool.poetry], or setuptools' setup.cfg and setup.py, and from leading AI model formats, including PyTorch, ONNX, Safetensors, GGUF, and fastText.

With native Hatchling integration and an official GitHub Action, Pitloom embeds SBOMs directly into your wheel distribution under .dist-info/sboms, following the PyPA Package Installation Metadata specification (PEP 770) -- offering software supply chain transparency without disrupting the build pipeline.

Install

pip install pitloom
pip install "pitloom[ai]"            # AI model metadata extraction
pip install "pitloom[content-type]"  # content type detection (magika)
pip install "pitloom[validate]"      # SPDX 3 schema/SHACL validation

Pick your usage surface

Pitloom generates the same kind of SBOM for the same target on every surface. Each page has a quick guide, install steps, usage details, config and code examples.

Surface Reach for this when...
Command line (loom) You want a one-off SBOM from a terminal, a Makefile target or a shell script.
Python API You call Pitloom from Python code, or want to track provenance during training/evaluation.
Hatchling build hook You build wheels with Hatchling and want an SBOM embedded automatically (PEP 770).
GitHub Action Your project is not Hatchling-based, or you want CI to produce an SBOM artifact.
Agent Skills You want an AI coding agent to generate (and optionally enrich or validate) an SBOM on request.
Claude Code plugin You use Claude Code and want the Skills installed with one command.

Guides

Reference

Background for auditing or debugging a generated SBOM, not needed to just generate one:

Security

For supported versions and vulnerability reporting guidelines, please read our Security policy.

Citation

If you use Pitloom in your academic work, please cite it as follows:

Suriyawongkul, A. (2026). Pitloom - SBOM generator for AI models and Python projects (Version 0.20.2) [Computer software]. https://doi.org/10.5281/zenodo.19246283

BibTeX:

@software{Suriyawongkul_Pitloom_SBOM_2026,
    author = {Suriyawongkul, Arthit},
    doi = {10.5281/zenodo.19246283},
    month = oct,
    title = {{Pitloom - SBOM generator for AI models and Python projects}},
    url = {https://github.com/bact/pitloom},
    version = {0.20.2},
    year = {2026}
}