{"record":{"id":"83e4ecf41032c700","repo":"pypa/pip","slug":"name-in-package-sdist-filename-r-is-not-consiste","errorCode":null,"errorMessage":"Name in {package.sdist.filename!r} is not consistent with package name {package.name!r}","messagePattern":"Name in (.+?) is not consistent with package name (.+?)","errorType":"validation","errorClass":"PylockValidationError","httpStatus":null,"severity":"error","filePath":"src/pip/_vendor/packaging/pylock.py","lineNumber":642,"sourceCode":"                    f\"package name {package.name!r}\",\n                    context=f\"wheels[{i}]\",\n                )\n            if package.version and version != package.version:\n                raise PylockValidationError(\n                    f\"Version in {wheel.filename!r} is not consistent with \"\n                    f\"package version {str(package.version)!r}\",\n                    context=f\"wheels[{i}]\",\n                )\n        if package.sdist:\n            try:\n                name, version = parse_sdist_filename(package.sdist.filename)\n            except Exception as e:\n                raise PylockValidationError(\n                    f\"Invalid sdist filename {package.sdist.filename!r}\",\n                    context=\"sdist\",\n                ) from e\n            if name != package.name:\n                raise PylockValidationError(\n                    f\"Name in {package.sdist.filename!r} is not consistent with \"\n                    f\"package name {package.name!r}\",\n                    context=\"sdist\",\n                )\n            if package.version and version != package.version:\n                raise PylockValidationError(\n                    f\"Version in {package.sdist.filename!r} is not consistent with \"\n                    f\"package version {str(package.version)!r}\",\n                    context=\"sdist\",\n                )\n        try:\n            for i, attestation_identity in enumerate(  # noqa: B007\n                package.attestation_identities or []\n            ):\n                _get_required(attestation_identity, str, \"kind\")\n        except Exception as e:\n            raise PylockValidationError(\n                e, context=f\"attestation-identities[{i}]\"","sourceCodeStart":624,"sourceCodeEnd":660,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_vendor/packaging/pylock.py#L624-L660","documentation":"PylockValidationError: the name parsed from an sdist filename does not match the package's declared name. Mirrors the wheel-name check but for the source-distribution entry, ensuring the sdist actually belongs to the package.","triggerScenarios":"Package validation calls parse_sdist_filename(package.sdist.filename) and compares the resulting name to package.name. Fires when e.g. name=\"flask\" but sdist.filename='werkzeug-2.3.0.tar.gz', or a fork's sdist retains the upstream name.","commonSituations":"Wrong sdist attached to a package block; renamed distribution whose sdist was not republished; locker bug indexing sdists by wrong key.","solutions":["Compare the leading name segment of sdist.filename with package.name.","Move the sdist to the matching package, or correct the filename so its name matches package.name (PEP 503 normalization applies).","Regenerate the lock if the source is uncertain.","Re-validate."],"exampleFix":"# before\n[[packages]]\nname = \"flask\"\nversion = \"3.0.0\"\n  [packages.sdist]\n  filename = \"werkzeug-2.3.0.tar.gz\"\n\n# after\n[[packages]]\nname = \"werkzeug\"\nversion = \"2.3.0\"\n  [packages.sdist]\n  filename = \"werkzeug-2.3.0.tar.gz\"","handlingStrategy":"validation","validationCode":"from packaging.utils import parse_sdist_filename, canonicalize_name\n\ndef sdist_name_consistent(filename: str, package_name: str) -> bool:\n    try:\n        name, _ = parse_sdist_filename(filename)\n    except Exception:\n        return False\n    return canonicalize_name(name) == canonicalize_name(package_name)\n\nfor p in toml_dict.get('packages', []):\n    s = p.get('sdist') or {}\n    if s:\n        assert sdist_name_consistent(s['filename'], p['name']), s['filename']","typeGuard":"null","tryCatchPattern":"try:\n    Pylock.from_dict(toml_dict)\nexcept PylockValidationError as e:\n    # e.context == 'sdist'; move/correct the sdist filename\n    report(e.context, e.message)","preventionTips":["Attach each sdist to the package whose name matches its leading segment.","After renaming a distribution, regenerate sdists so the filename carries the new name.","Normalize before comparing names; trailing/leading dashes differ post-normalization."],"tags":["pylock","packaging","validation","naming","sdist"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}