pypa/pip · error · PylockValidationError

Name in is not consistent with package name

Error message

Name in {package.sdist.filename!r} is not consistent with package name {package.name!r}

What it means

PylockValidationError: the name parsed from an sdist filename does not match the package's declared name. Mirrors the wheel-name check but for the source-distribution entry, ensuring the sdist actually belongs to the package.

Solutions

  1. Compare the leading name segment of sdist.filename with package.name.
  2. Move the sdist to the matching package, or correct the filename so its name matches package.name (PEP 503 normalization applies).
  3. Regenerate the lock if the source is uncertain.
  4. Re-validate.

Example fix

# before
[[packages]]
name = "flask"
version = "3.0.0"
  [packages.sdist]
  filename = "werkzeug-2.3.0.tar.gz"

# after
[[packages]]
name = "werkzeug"
version = "2.3.0"
  [packages.sdist]
  filename = "werkzeug-2.3.0.tar.gz"
Defensive patterns

Strategy: validation

Validate before calling

from packaging.utils import parse_sdist_filename, canonicalize_name

def sdist_name_consistent(filename: str, package_name: str) -> bool:
    try:
        name, _ = parse_sdist_filename(filename)
    except Exception:
        return False
    return canonicalize_name(name) == canonicalize_name(package_name)

for p in toml_dict.get('packages', []):
    s = p.get('sdist') or {}
    if s:
        assert sdist_name_consistent(s['filename'], p['name']), s['filename']

Type guard

null

Try / catch

try:
    Pylock.from_dict(toml_dict)
except PylockValidationError as e:
    # e.context == 'sdist'; move/correct the sdist filename
    report(e.context, e.message)

Prevention

When it happens

Trigger: Package validation calls parse_sdist_filename(package.sdist.filename) and compares the resulting name to package.name. Fires when e.g. name="flask" but sdist.filename='werkzeug-2.3.0.tar.gz', or a fork's sdist retains the upstream name.

Common situations: Wrong sdist attached to a package block; renamed distribution whose sdist was not republished; locker bug indexing sdists by wrong key.

Related errors


AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08). Data as JSON: /api/errors/83e4ecf41032c700. Report an issue: GitHub.

Appendix: source

Thrown at src/pip/_vendor/packaging/pylock.py:642

                    f"package name {package.name!r}",
                    context=f"wheels[{i}]",
                )
            if package.version and version != package.version:
                raise PylockValidationError(
                    f"Version in {wheel.filename!r} is not consistent with "
                    f"package version {str(package.version)!r}",
                    context=f"wheels[{i}]",
                )
        if package.sdist:
            try:
                name, version = parse_sdist_filename(package.sdist.filename)
            except Exception as e:
                raise PylockValidationError(
                    f"Invalid sdist filename {package.sdist.filename!r}",
                    context="sdist",
                ) from e
            if name != package.name:
                raise PylockValidationError(
                    f"Name in {package.sdist.filename!r} is not consistent with "
                    f"package name {package.name!r}",
                    context="sdist",
                )
            if package.version and version != package.version:
                raise PylockValidationError(
                    f"Version in {package.sdist.filename!r} is not consistent with "
                    f"package version {str(package.version)!r}",
                    context="sdist",
                )
        try:
            for i, attestation_identity in enumerate(  # noqa: B007
                package.attestation_identities or []
            ):
                _get_required(attestation_identity, str, "kind")
        except Exception as e:
            raise PylockValidationError(
                e, context=f"attestation-identities[{i}]"

View on GitHub (pinned to f399c37189)