koji
Koji is a system for building and tracking RPMS. The base package contains shared libraries and the command-line interface.
Decision gist · record as of 2026-08-14
Yes, if you work with Koji-based build systems (Fedora, RHEL, or similar RPM-based projects). The package is actively maintained, has low install friction, and provides the standard client for Koji interaction. No security vulnerabilities are known. The copyleft license requires review if you plan to distribute derivative works, but poses no barrier to internal use or integration into open-source projects.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires network access to a Koji server instance; Kerberos authentication may be needed depending on server configuration.
- Low install friction with pure-Python wheels available for both Python 2 and 3.
- Actively maintained with a release 37 days ago.
License · maintenance · safety
LGPLv2 and GPLv2+ (copyleft) — Licensed under LGPLv2 and GPLv2+, both copyleft licenses. Derivative works and distributions must comply with copyleft obligations; proprietary software linking this library must be carefully reviewed for license compatibility.
last release 2026-07-08 (37 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 199,300 downloads/mo, #9,710 on PyPI
Alternatives
Verify before relying
pip install koji
import koji
client = koji.ClientSession('https://koji.fedoraproject.org/koji')
builds = client.listBuilds()- Whether requests-gssapi is required for all use cases or only when Kerberos authentication is needed.
- Specific Python 2.7 support status given the package claims Python 2.7 compatibility but Python 2 is end-of-life.
- What parameters and return types the ClientSession API accepts and returns.
What it is and what it does
Koji is the command-line client and shared library for the Koji RPM build system, which the Fedora Project and other organizations use to manage reproducible software builds. It provides programmatic access to build tracking, artifact management, and build automation through XML-RPC APIs, allowing developers and automation tools to query build status, retrieve artifacts, and trigger builds.
The package is designed as a thin, portable client that works alongside Koji's web interface and server components. It depends on standard HTTP and authentication libraries (requests, requests-gssapi, python-dateutil) to communicate with remote Koji instances, and uses defusedxml for secure XML parsing. It supports both Python 2.7 and modern Python 3 versions, making it suitable for integration into legacy and contemporary build pipelines.
Use it for
- Query build status and retrieve RPM artifacts from a Fedora or enterprise Koji instance.
- Automate build triggering and monitoring in CI/CD pipelines that target RPM-based distributions.
- Integrate Koji build tracking into custom release or deployment tools via its XML-RPC API.
- Manage local buildroots and track buildroot contents for reproducible builds in development workflows.
- Authenticate to Koji servers using Kerberos credentials in enterprise environments.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you work with Koji-based build systems (Fedora, RHEL, or similar RPM-based projects).
The package is actively maintained, has low install friction, and provides the standard client for Koji interaction. No security vulnerabilities are known. The copyleft license requires review if you plan to distribute derivative works, but poses no barrier to internal use or integration into open-source projects.
Install
koji on PyPI
Before you install
Low install friction with pure-Python wheels available for both Python 2 and 3. Actively maintained with a release 37 days ago. Five runtime dependencies are all well-established packages (defusedxml, python-dateutil, requests, requests-gssapi, six).
Requires network access to a Koji server instance; Kerberos authentication may be needed depending on server configuration.
License in practice
Licensed under LGPLv2 and GPLv2+, both copyleft licenses. Derivative works and distributions must comply with copyleft obligations; proprietary software linking this library must be carefully reviewed for license compatibility.
Quickstart
pip install koji
import koji
client = koji.ClientSession('https://koji.fedoraproject.org/koji')
builds = client.listBuilds()
Verify before relying
- Whether requests-gssapi is required for all use cases or only when Kerberos authentication is needed.
- Specific Python 2.7 support status given the package claims Python 2.7 compatibility but Python 2 is end-of-life.
- What parameters and return types the ClientSession API accepts and returns.
Package facts
| License | LGPLv2 and GPLv2+ copyleft |
| Python support | Supports the current Python release >=2.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 5 packagesdefusedxmlpython-dateutilrequestsrequests-gssapisix |
| Maintenance | Actively maintained 37 days since the last release |
| First released | |
| Downloads | 199,300 / month, #9,710 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: GNU Lesser General Public License v2 or later (LGPLv2+)Natural Language :: EnglishOperating System :: POSIX :: LinuxProgramming Language :: Python :: 2.7Programming Language :: Python :: 3Topic :: Utilities |
Evidence: koji-1.36.1-py2-none-any.whl; koji-1.36.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “rpm build system client”
- kojiKoji is a command-line client and library for interacting with…
- rpmProvides access to system RPM Python bindings inside a virtualenv by…
- version-utilsParses and compares package version strings in RPM/Yum format using…
Give your agent the search over MCP, or paste the wish link into any chat.
More Utilities packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.
Install it if you need to display or transform source code.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
See also version-utils · rpm-vercmp · ansible-builder · rpmfile · rpm · python-rrmngmnt · fedora-messaging · bindep · pybuildkite · robotremoteserver