{"record":{"id":"b84b9c1de3091899","repo":"pypa/pip","slug":"invalid-sdist-filename-package-sdist-filename-r","errorCode":null,"errorMessage":"Invalid sdist filename {package.sdist.filename!r}","messagePattern":"Invalid sdist filename (.+?)","errorType":"validation","errorClass":"PylockValidationError","httpStatus":null,"severity":"error","filePath":"src/pip/_vendor/packaging/pylock.py","lineNumber":637,"sourceCode":"                    context=f\"wheels[{i}]\",\n                ) from e\n            if name != package.name:\n                raise PylockValidationError(\n                    f\"Name in {wheel.filename!r} is not consistent with \"\n                    f\"package name {package.name!r}\",\n                    context=f\"wheels[{i}]\",\n                )\n            if package.version and version != package.version:\n                raise PylockValidationError(\n                    f\"Version in {wheel.filename!r} is not consistent with \"\n                    f\"package version {str(package.version)!r}\",\n                    context=f\"wheels[{i}]\",\n                )\n        if package.sdist:\n            try:\n                name, version = parse_sdist_filename(package.sdist.filename)\n            except Exception as e:\n                raise PylockValidationError(\n                    f\"Invalid sdist filename {package.sdist.filename!r}\",\n                    context=\"sdist\",\n                ) from e\n            if name != package.name:\n                raise PylockValidationError(\n                    f\"Name in {package.sdist.filename!r} is not consistent with \"\n                    f\"package name {package.name!r}\",\n                    context=\"sdist\",\n                )\n            if package.version and version != package.version:\n                raise PylockValidationError(\n                    f\"Version in {package.sdist.filename!r} is not consistent with \"\n                    f\"package version {str(package.version)!r}\",\n                    context=\"sdist\",\n                )\n        try:\n            for i, attestation_identity in enumerate(  # noqa: B007\n                package.attestation_identities or []","sourceCodeStart":619,"sourceCodeEnd":655,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_vendor/packaging/pylock.py#L619-L655","documentation":"PylockValidationError raised when parse_sdist_filename cannot parse the [packages.sdist].filename. PEP 751 sdist filenames must follow '{name}-{version}.tar.gz' (or .zip), so a structurally bad string is rejected during Package validation with context 'sdist'.","triggerScenarios":"Calling Pylock.from_dict / Pylock.validate where a package has [packages.sdist] filename = 'foo-1.0.whl' (wheel extension on an sdist), 'foo.tar.gz' (missing version), or 'foo-1.0.0+local.tar.gz' with a malformed version segment.","commonSituations":"Confusing a wheel filename with an sdist filename in the lock; hand-editing; a sdist URL with the archive renamed after download.","solutions":["Find the package whose sdist.filename is reported and read it.","Rewrite the filename as name-version.tar.gz (or .zip), e.g. 'requests-2.31.0.tar.gz'.","Regenerate the lock with the producing tool if the original filename is unknown.","Re-validate."],"exampleFix":"# before\n[[packages]]\nname = \"requests\"\nversion = \"2.31.0\"\n  [packages.sdist]\n  filename = \"requests-2.31.0-py3-none-any.whl\"\n\n# after\n[[packages]]\nname = \"requests\"\nversion = \"2.31.0\"\n  [packages.sdist]\n  filename = \"requests-2.31.0.tar.gz\"","handlingStrategy":"validation","validationCode":"from packaging.utils import parse_sdist_filename\n\ndef is_valid_sdist_filename(filename: str) -> bool:\n    try:\n        parse_sdist_filename(filename)\n        return True\n    except Exception:\n        return False\n\nfor p in toml_dict.get('packages', []):\n    s = (p.get('sdist') or {})\n    if s:\n        assert is_valid_sdist_filename(s['filename']), s['filename']","typeGuard":"null","tryCatchPattern":"from packaging.pylock import PylockValidationError\ntry:\n    Pylock.from_dict(toml_dict)\nexcept PylockValidationError as e:\n    # e.context == 'sdist'; fix [packages.sdist].filename\n    report(e.context, e.message)","preventionTips":["Use only .tar.gz / .zip with name-version prefix for sdist filenames.","Never put a wheel filename in the sdist field or vice versa.","Validate the lock immediately after any manual edit."],"tags":["pylock","packaging","validation","filename","sdist"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}