pypa/pip · error · PylockValidationError
Name in is not consistent with package name
Error message
Name in {package.sdist.filename!r} is not consistent with package name {package.name!r} What it means
PylockValidationError: the name parsed from an sdist filename does not match the package's declared name. Mirrors the wheel-name check but for the source-distribution entry, ensuring the sdist actually belongs to the package.
Solutions
- Compare the leading name segment of sdist.filename with package.name.
- Move the sdist to the matching package, or correct the filename so its name matches package.name (PEP 503 normalization applies).
- Regenerate the lock if the source is uncertain.
- Re-validate.
Example fix
# before [[packages]] name = "flask" version = "3.0.0" [packages.sdist] filename = "werkzeug-2.3.0.tar.gz" # after [[packages]] name = "werkzeug" version = "2.3.0" [packages.sdist] filename = "werkzeug-2.3.0.tar.gz"
Defensive patterns
Strategy: validation
Validate before calling
from packaging.utils import parse_sdist_filename, canonicalize_name
def sdist_name_consistent(filename: str, package_name: str) -> bool:
try:
name, _ = parse_sdist_filename(filename)
except Exception:
return False
return canonicalize_name(name) == canonicalize_name(package_name)
for p in toml_dict.get('packages', []):
s = p.get('sdist') or {}
if s:
assert sdist_name_consistent(s['filename'], p['name']), s['filename'] Type guard
null
Try / catch
try:
Pylock.from_dict(toml_dict)
except PylockValidationError as e:
# e.context == 'sdist'; move/correct the sdist filename
report(e.context, e.message) Prevention
- Attach each sdist to the package whose name matches its leading segment.
- After renaming a distribution, regenerate sdists so the filename carries the new name.
- Normalize before comparing names; trailing/leading dashes differ post-normalization.
When it happens
Trigger: Package validation calls parse_sdist_filename(package.sdist.filename) and compares the resulting name to package.name. Fires when e.g. name="flask" but sdist.filename='werkzeug-2.3.0.tar.gz', or a fork's sdist retains the upstream name.
Common situations: Wrong sdist attached to a package block; renamed distribution whose sdist was not republished; locker bug indexing sdists by wrong key.
Related errors
- Invalid sdist filename
- Name in is not consistent with package name
- Version in is not consistent with package version
- Cannot determine sdist filename
- Invalid wheel filename
AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08).
Data as JSON: /api/errors/83e4ecf41032c700.
Report an issue: GitHub.
Appendix: source
Thrown at src/pip/_vendor/packaging/pylock.py:642
f"package name {package.name!r}",
context=f"wheels[{i}]",
)
if package.version and version != package.version:
raise PylockValidationError(
f"Version in {wheel.filename!r} is not consistent with "
f"package version {str(package.version)!r}",
context=f"wheels[{i}]",
)
if package.sdist:
try:
name, version = parse_sdist_filename(package.sdist.filename)
except Exception as e:
raise PylockValidationError(
f"Invalid sdist filename {package.sdist.filename!r}",
context="sdist",
) from e
if name != package.name:
raise PylockValidationError(
f"Name in {package.sdist.filename!r} is not consistent with "
f"package name {package.name!r}",
context="sdist",
)
if package.version and version != package.version:
raise PylockValidationError(
f"Version in {package.sdist.filename!r} is not consistent with "
f"package version {str(package.version)!r}",
context="sdist",
)
try:
for i, attestation_identity in enumerate( # noqa: B007
package.attestation_identities or []
):
_get_required(attestation_identity, str, "kind")
except Exception as e:
raise PylockValidationError(
e, context=f"attestation-identities[{i}]"View on GitHub (pinned to f399c37189)