pypa/pip · error · PylockValidationError
Invalid sdist filename
Error message
Invalid sdist filename {package.sdist.filename!r} What it means
PylockValidationError raised when parse_sdist_filename cannot parse the [packages.sdist].filename. PEP 751 sdist filenames must follow '{name}-{version}.tar.gz' (or .zip), so a structurally bad string is rejected during Package validation with context 'sdist'.
Solutions
- Find the package whose sdist.filename is reported and read it.
- Rewrite the filename as name-version.tar.gz (or .zip), e.g. 'requests-2.31.0.tar.gz'.
- Regenerate the lock with the producing tool if the original filename is unknown.
- Re-validate.
Example fix
# before [[packages]] name = "requests" version = "2.31.0" [packages.sdist] filename = "requests-2.31.0-py3-none-any.whl" # after [[packages]] name = "requests" version = "2.31.0" [packages.sdist] filename = "requests-2.31.0.tar.gz"
Defensive patterns
Strategy: validation
Validate before calling
from packaging.utils import parse_sdist_filename
def is_valid_sdist_filename(filename: str) -> bool:
try:
parse_sdist_filename(filename)
return True
except Exception:
return False
for p in toml_dict.get('packages', []):
s = (p.get('sdist') or {})
if s:
assert is_valid_sdist_filename(s['filename']), s['filename'] Type guard
null
Try / catch
from packaging.pylock import PylockValidationError
try:
Pylock.from_dict(toml_dict)
except PylockValidationError as e:
# e.context == 'sdist'; fix [packages.sdist].filename
report(e.context, e.message) Prevention
- Use only .tar.gz / .zip with name-version prefix for sdist filenames.
- Never put a wheel filename in the sdist field or vice versa.
- Validate the lock immediately after any manual edit.
When it happens
Trigger: Calling Pylock.from_dict / Pylock.validate where a package has [packages.sdist] filename = 'foo-1.0.whl' (wheel extension on an sdist), 'foo.tar.gz' (missing version), or 'foo-1.0.0+local.tar.gz' with a malformed version segment.
Common situations: Confusing a wheel filename with an sdist filename in the lock; hand-editing; a sdist URL with the archive renamed after download.
Related errors
- Cannot determine sdist filename
- Invalid wheel filename
- Name in is not consistent with package name
- Version in is not consistent with package version
- Cannot determine wheel filename
AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08).
Data as JSON: /api/errors/b84b9c1de3091899.
Report an issue: GitHub.
Appendix: source
Thrown at src/pip/_vendor/packaging/pylock.py:637
context=f"wheels[{i}]",
) from e
if name != package.name:
raise PylockValidationError(
f"Name in {wheel.filename!r} is not consistent with "
f"package name {package.name!r}",
context=f"wheels[{i}]",
)
if package.version and version != package.version:
raise PylockValidationError(
f"Version in {wheel.filename!r} is not consistent with "
f"package version {str(package.version)!r}",
context=f"wheels[{i}]",
)
if package.sdist:
try:
name, version = parse_sdist_filename(package.sdist.filename)
except Exception as e:
raise PylockValidationError(
f"Invalid sdist filename {package.sdist.filename!r}",
context="sdist",
) from e
if name != package.name:
raise PylockValidationError(
f"Name in {package.sdist.filename!r} is not consistent with "
f"package name {package.name!r}",
context="sdist",
)
if package.version and version != package.version:
raise PylockValidationError(
f"Version in {package.sdist.filename!r} is not consistent with "
f"package version {str(package.version)!r}",
context="sdist",
)
try:
for i, attestation_identity in enumerate( # noqa: B007
package.attestation_identities or []View on GitHub (pinned to f399c37189)