pypa/pip · error · PylockValidationError

Invalid sdist filename

Error message

Invalid sdist filename {package.sdist.filename!r}

What it means

PylockValidationError raised when parse_sdist_filename cannot parse the [packages.sdist].filename. PEP 751 sdist filenames must follow '{name}-{version}.tar.gz' (or .zip), so a structurally bad string is rejected during Package validation with context 'sdist'.

Solutions

  1. Find the package whose sdist.filename is reported and read it.
  2. Rewrite the filename as name-version.tar.gz (or .zip), e.g. 'requests-2.31.0.tar.gz'.
  3. Regenerate the lock with the producing tool if the original filename is unknown.
  4. Re-validate.

Example fix

# before
[[packages]]
name = "requests"
version = "2.31.0"
  [packages.sdist]
  filename = "requests-2.31.0-py3-none-any.whl"

# after
[[packages]]
name = "requests"
version = "2.31.0"
  [packages.sdist]
  filename = "requests-2.31.0.tar.gz"
Defensive patterns

Strategy: validation

Validate before calling

from packaging.utils import parse_sdist_filename

def is_valid_sdist_filename(filename: str) -> bool:
    try:
        parse_sdist_filename(filename)
        return True
    except Exception:
        return False

for p in toml_dict.get('packages', []):
    s = (p.get('sdist') or {})
    if s:
        assert is_valid_sdist_filename(s['filename']), s['filename']

Type guard

null

Try / catch

from packaging.pylock import PylockValidationError
try:
    Pylock.from_dict(toml_dict)
except PylockValidationError as e:
    # e.context == 'sdist'; fix [packages.sdist].filename
    report(e.context, e.message)

Prevention

When it happens

Trigger: Calling Pylock.from_dict / Pylock.validate where a package has [packages.sdist] filename = 'foo-1.0.whl' (wheel extension on an sdist), 'foo.tar.gz' (missing version), or 'foo-1.0.0+local.tar.gz' with a malformed version segment.

Common situations: Confusing a wheel filename with an sdist filename in the lock; hand-editing; a sdist URL with the archive renamed after download.

Related errors


AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08). Data as JSON: /api/errors/b84b9c1de3091899. Report an issue: GitHub.

Appendix: source

Thrown at src/pip/_vendor/packaging/pylock.py:637

                    context=f"wheels[{i}]",
                ) from e
            if name != package.name:
                raise PylockValidationError(
                    f"Name in {wheel.filename!r} is not consistent with "
                    f"package name {package.name!r}",
                    context=f"wheels[{i}]",
                )
            if package.version and version != package.version:
                raise PylockValidationError(
                    f"Version in {wheel.filename!r} is not consistent with "
                    f"package version {str(package.version)!r}",
                    context=f"wheels[{i}]",
                )
        if package.sdist:
            try:
                name, version = parse_sdist_filename(package.sdist.filename)
            except Exception as e:
                raise PylockValidationError(
                    f"Invalid sdist filename {package.sdist.filename!r}",
                    context="sdist",
                ) from e
            if name != package.name:
                raise PylockValidationError(
                    f"Name in {package.sdist.filename!r} is not consistent with "
                    f"package name {package.name!r}",
                    context="sdist",
                )
            if package.version and version != package.version:
                raise PylockValidationError(
                    f"Version in {package.sdist.filename!r} is not consistent with "
                    f"package version {str(package.version)!r}",
                    context="sdist",
                )
        try:
            for i, attestation_identity in enumerate(  # noqa: B007
                package.attestation_identities or []

View on GitHub (pinned to f399c37189)