Pitloom¶
Pitloom automates the generation of SPDX 3-compliant software bills of materials (SBOMs) for Python applications and AI models.
It extracts metadata directly from Python projects, whether declared in
the standard [project] table (Flit, Hatchling, PDM, uv_build and others),
Poetry's [tool.poetry], or setuptools' setup.cfg and setup.py,
and from leading AI model formats,
including PyTorch, ONNX, Safetensors, GGUF, and fastText.
With native Hatchling integration and an official GitHub Action,
Pitloom embeds SBOMs directly into your wheel distribution under
.dist-info/sboms, following the
PyPA Package Installation Metadata specification (PEP 770) --
offering software supply chain transparency without disrupting
the build pipeline.
Install¶
pip install pitloom
pip install "pitloom[ai]" # AI model metadata extraction
pip install "pitloom[content-type]" # content type detection (magika)
pip install "pitloom[validate]" # SPDX 3 schema/SHACL validation
Pick your usage surface¶
Pitloom generates the same kind of SBOM for the same target on every surface. Each page has a quick guide, install steps, usage details, config and code examples.
| Surface | Reach for this when... |
|---|---|
Command line (loom) |
You want a one-off SBOM from a terminal, a Makefile target or a shell script. |
| Python API | You call Pitloom from Python code, or want to track provenance during training/evaluation. |
| Hatchling build hook | You build wheels with Hatchling and want an SBOM embedded automatically (PEP 770). |
| GitHub Action | Your project is not Hatchling-based, or you want CI to produce an SBOM artifact. |
| Agent Skills | You want an AI coding agent to generate (and optionally enrich or validate) an SBOM on request. |
| Claude Code plugin | You use Claude Code and want the Skills installed with one command. |
Guides¶
- Wheel SBOMs and PEP 770 embedding --
embed-wheel,verify-wheel,validate-wheel, the package hash. - SBOM fragments -- merge, validate and list fragments.
- Loom ID registry -- keep
spdxIds stable across fragments and runs. - Building a project (
--allow-build) -- discover a project's real file list with its own build backend. - AI model formats and AI model scan limits.
Reference¶
Background for auditing or debugging a generated SBOM, not needed to just generate one:
- Configuration -- every
[tool.pitloom]setting, its default, and how to reach it from each surface. - Dependency sources and precedence -- what a Source SBOM's dependency list holds, which lock file wins, and which commands use lock files.
- Creation metadata -- who/what/when/how each element records about its own creation.
- Metadata provenance -- how Pitloom tracks the source of each metadata field.
- Resources -- SBOM, AIBOM, SPDX and related standards reading list.
- Project README.
Security¶
For supported versions and vulnerability reporting guidelines, please read our Security policy.
Citation¶
If you use Pitloom in your academic work, please cite it as follows:
Suriyawongkul, A. (2026). Pitloom - SBOM generator for AI models and Python projects (Version 0.20.2) [Computer software]. https://doi.org/10.5281/zenodo.19246283
BibTeX:
@software{Suriyawongkul_Pitloom_SBOM_2026,
author = {Suriyawongkul, Arthit},
doi = {10.5281/zenodo.19246283},
month = oct,
title = {{Pitloom - SBOM generator for AI models and Python projects}},
url = {https://github.com/bact/pitloom},
version = {0.20.2},
year = {2026}
}