Skip to content

Resources

Python Enhancement Proposals (PEPs)

Note: PEPs are historical documents. The up-to-date, canonical spec for Python packaging, is maintained on the PyPA specs page.

PEPs Pitloom's extractors and assemblers directly implement support for, each with a short note on what SBOM metadata it feeds:

  • PEP 376 – Database of Installed Python Distributions: RECORD hash/size format, reused for wheel-embedded SBOM file digests (see PEP 770 below).
  • PEP 427 – The Wheel Binary Package Format 1.0: defines the .dist-info/ layout Pitloom reads/writes package files against. Stale on one point the PEP text itself doesn't reflect: the name/version escaping rule for .dist-info directory naming (PEP 503 normalisation, then - → _) was revised in 2021 to match real tooling — see the canonical Binary Distribution Format spec instead of this PEP for that rule specifically.
  • PEP 440 – Version Identification and Dependency Specification: version syntax used for dependency-constraint conversion (e.g. Poetry's ^/~) and wheel-vs-SBOM version checks.
  • PEP 503 – Simple Repository API: package-name normalisation, used generically wherever two package names must compare equal regardless of case/-/_/. -- PyPI purl construction, dependency dedup, wheel-vs-SBOM name checks, and wheel .dist-info path escaping.
  • PEP 508 – Dependency specification for Python Software Packages: parsed for each dependency's name, version constraints, extras, and markers.
  • PEP 517 – A build-system independent format for source trees: build-backend interface used to detect which backend produced a project's metadata.
  • PEP 518 – Specifying Minimum Build System Requirements for Python Projects: [build-system] table read to select the right metadata/file-discovery backend.
  • PEP 621 – Storing project metadata in pyproject.toml: primary source of name, version, authors, dependencies, license, urls, etc.
  • PEP 639 – Improving License Clarity with Better Package Metadata: SPDX license expression → the package's declared license. license-files are not listed in the SBOM: the build backend copies them into the wheel's own .dist-info/licenses/, which describes the package container, not the project. The wheel keeps them as built.
  • PEP 751 – A file format to record Python dependencies for installation reproducibility: pylock.toml, the highest-priority resolved-dependency source in the lock-file cascade (see Dependency sources).
  • PEP 770 – Improving measurability of Python packages with Software Bill-of-Materials: defines .dist-info/sboms/, where Pitloom embeds/locates a wheel's own SBOM.
  • All Packaging PEPs

SBOM resources

AI documentation resources

SPDX resources

Other resources