PEP 770 Software Bill‑of‑Materials (SBOM) data from PyPI, Fedora, and Red Hat
sethmlarson.dev·6d
❄️Nixpkgs
Preview
Report Post

Seth Larson @ 2025-12-22

This year I authored PEP 770 which proposed a new standardized location for Software Bill-of-Materials (SBOM) data within Python wheel archives. SBOM data can now be stored in (package)-(version).dist-info/sboms/. You can see the canonical specification on packaging.python.org.

While writing this document we also reserved all .dist-info/ subdirectory names within a registry for future use in other standards. Reviewers agreed that this method of defining file-based metadata (such as SBOMs, but also licenses) is a great mechanism as it doesn’t require creating a new metadata field and version.

Creati…

Similar Posts

Loading similar posts...