{"record":{"id":"a5c89b28def87051","repo":"pypa/pip","slug":"version-in-package-sdist-filename-r-is-not-consi","errorCode":null,"errorMessage":"Version in {package.sdist.filename!r} is not consistent with package version {str(package.version)!r}","messagePattern":"Version in (.+?) is not consistent with package version (.+?)","errorType":"validation","errorClass":"PylockValidationError","httpStatus":null,"severity":"error","filePath":"src/pip/_vendor/packaging/pylock.py","lineNumber":648,"sourceCode":"                    f\"package version {str(package.version)!r}\",\n                    context=f\"wheels[{i}]\",\n                )\n        if package.sdist:\n            try:\n                name, version = parse_sdist_filename(package.sdist.filename)\n            except Exception as e:\n                raise PylockValidationError(\n                    f\"Invalid sdist filename {package.sdist.filename!r}\",\n                    context=\"sdist\",\n                ) from e\n            if name != package.name:\n                raise PylockValidationError(\n                    f\"Name in {package.sdist.filename!r} is not consistent with \"\n                    f\"package name {package.name!r}\",\n                    context=\"sdist\",\n                )\n            if package.version and version != package.version:\n                raise PylockValidationError(\n                    f\"Version in {package.sdist.filename!r} is not consistent with \"\n                    f\"package version {str(package.version)!r}\",\n                    context=\"sdist\",\n                )\n        try:\n            for i, attestation_identity in enumerate(  # noqa: B007\n                package.attestation_identities or []\n            ):\n                _get_required(attestation_identity, str, \"kind\")\n        except Exception as e:\n            raise PylockValidationError(\n                e, context=f\"attestation-identities[{i}]\"\n            ) from e\n        return package\n\n    @property\n    def is_direct(self) -> bool:\n        return not (self.sdist or self.wheels)","sourceCodeStart":630,"sourceCodeEnd":666,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_vendor/packaging/pylock.py#L630-L666","documentation":"PylockValidationError: the version parsed from an sdist filename differs from package.version (only checked when package.version is set). Guarantees the source tarball corresponds to the pinned release.","triggerScenarios":"Package validation compares the version from parse_sdist_filename to package.version. Fires when version='2.31.0' but sdist.filename='requests-2.30.0.tar.gz', e.g. an old tarball left after a version bump.","commonSituations":"Partial lock update bumping the version field but leaving the sdist filename; a stale sdist cached by a buggy locker; an sdist rebuilt under a dev/local version that normalizes apart from the pinned one.","solutions":["Read the version segment of sdist.filename and compare to package.version.","Replace the sdist filename so its version equals the declared package version.","Regenerate the lock to keep sdist filename and version in lockstep.","Re-validate."],"exampleFix":"# before\n[[packages]]\nname = \"requests\"\nversion = \"2.31.0\"\n  [packages.sdist]\n  filename = \"requests-2.30.0.tar.gz\"\n\n# after\n[[packages]]\nname = \"requests\"\nversion = \"2.31.0\"\n  [packages.sdist]\n  filename = \"requests-2.31.0.tar.gz\"","handlingStrategy":"validation","validationCode":"from packaging.utils import parse_sdist_filename\nfrom packaging.version import Version\n\ndef sdist_version_consistent(filename: str, version: str) -> bool:\n    try:\n        _, ver = parse_sdist_filename(filename)\n    except Exception:\n        return False\n    return not version or Version(str(ver)) == Version(version)\n\nfor p in toml_dict.get('packages', []):\n    s = p.get('sdist') or {}\n    if s:\n        assert sdist_version_consistent(s['filename'], p.get('version')), s['filename']","typeGuard":"null","tryCatchPattern":"try:\n    Pylock.from_dict(toml_dict)\nexcept PylockValidationError as e:\n    # e.context == 'sdist'; align sdist version with package.version\n    report(e.context, e.message)","preventionTips":["Bump the sdist filename in lock with the package version field.","Regenerate the lock on every dependency update so versions stay coherent.","Validate before relying on select()."],"tags":["pylock","packaging","validation","version","sdist"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}