Skip to content

Support PEP-639 style License-Expression fields - #322

Merged
peterebden merged 3 commits into
masterfrom
peter/license-expression
Sep 16, 2026
Merged

peterebden merged 3 commits into
masterfrom
peter/license-expression

Conversation

@peterebden

Copy link
Copy Markdown
Member

These are superseding the old freeform text License: fields. There are some packages in the wild that have this and not Licence any more, presumably that will increase over time.

https://peps.python.org/pep-0639/

These are SPDX expressions. Please doesn't parse those for now, but it can crudely support them by simply entering each expression as a licence. In the future when we add the ability to parse them, this should just work.

Also fixed a couple of existing bugs about how the repo argument got used in pip_library.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps we should generate this wheel at test time, just to prove there's nothing weird going on in this plugin (a la CVE-2024-3094)? It'd be pretty straightforward too, given that we could build it with arcat. If you want to save keystrokes and a bit of complexity, fakepkg/__init__.py isn't necessary - a wheel consisting only of metadata is legit (and occasionally seen in the wild as a way of implementing virtual packages).

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's fair - just call me Jia Ebden...

(I've left the __init__.py in, it doesn't make it any harder to construct)

@peterebden
peterebden force-pushed the peter/license-expression branch from 6752779 to ed83e95 Compare September 15, 2026 11:58
repo = repo or CONFIG.PYTHON.DEFAULT_PIP_REPO
if repo:
if looks_like_build_label(repo): # Looks like a build label, not a URL.
repo_flag = f'-f %(location {repo})'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

😞

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Amazingly nobody noticed...

@peterebden
peterebden merged commit 7bec83f into master Sep 16, 2026
390 of 395 checks passed
@peterebden
peterebden deleted the peter/license-expression branch September 16, 2026 13:41
@chrisnovakovic chrisnovakovic mentioned this pull request Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants