Skip to content

PEP-710: Implement provenance records for installed packages #5627

@fridex

Description

@fridex

We are discussing the possibility of introducing provenance_url.json that would help with tracking of installed packages in Python environments. It could help with creating a lock files or SBOMs from installed packages.

We would like to know your position on this PEP (it's in draft state as of today) as uv is one of the affected installers. See https://peps.python.org/pep-0710/ and this Discourse thread where the discussion around this PEP is happening. Thanks!

Metadata

Metadata

Assignees

Labels

compatibilityCompatibility with a specification or another toolquestionAsking for clarification or support

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions