packageurl-python
A purl aka. Package URL parser and builder
Decision gist · record as of 2026-08-14
Yes. This is a lightweight, actively maintained library with zero runtime dependencies, permissive licensing, and no known vulnerabilities. Install it if you need to work with standardized package identifiers across different ecosystems or integrate purl handling into a larger tool. The low friction and broad Python support make it a straightforward addition to any project.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low friction: pure Python wheel with no runtime dependencies.
- Actively maintained with last commit on 2026-03-11 and latest release on 2025-11-24.
- Supports Python 3.8 through 3.13.
License · maintenance · safety
MIT (permissive) — MIT license (permissive) — you can use, modify, and distribute this package freely in commercial and open-source projects with minimal restrictions.
last release 2025-11-24 (263 days) · last repo commit 2026-03-11 · 91 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 35,215,310 downloads/mo, #749 on PyPI
Alternatives
Verify before relying
pip install packageurl-python
from packageurl import PackageURL
purl = PackageURL.from_string("pkg:maven/org.apache.commons/io@1.3.4")
print(purl.to_string())- Whether the Django and SQLAlchemy contrib modules are production-ready or experimental.
- Performance characteristics when parsing or building very large numbers of purls.
- Completeness of purl-to-URL inference for all supported package types.
What it is and what it does
packageurl-python is a parser and builder for Package URLs (purls), a standardized format for identifying software packages across different package managers. It implements the purl specification and lets you parse purl strings into structured objects, build purls programmatically, and convert between purls and repository/download URLs. The library has no runtime dependencies, making it lightweight to embed in other tools.
The package includes optional contrib modules for Django and SQLAlchemy integration, plus utilities to infer purls from regular URLs and vice versa. It supports all major package ecosystems (Maven, npm, PyPI, RubyGems, GitHub, and others) and is actively maintained with broad Python version support.
Use it for
- Parse and normalize package identifiers in software composition analysis or supply-chain security tools.
- Build standardized package references programmatically in package management or dependency resolution systems.
- Convert between purl format and repository URLs to automate package discovery or download workflows.
- Store package metadata in Django or SQLAlchemy models using the contrib mixins.
- Infer package URLs from GitHub or package repository links in automated tooling.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is a lightweight, actively maintained library with zero runtime dependencies, permissive licensing, and no known vulnerabilities. Install it if you need to work with standardized package identifiers across different ecosystems or integrate purl handling into a larger tool. The low friction and broad Python support make it a straightforward addition to any project.
Install
packageurl-python on PyPI
Before you install
Low friction: pure Python wheel with no runtime dependencies. Actively maintained with last commit on 2026-03-11 and latest release on 2025-11-24. Supports Python 3.8 through 3.13.
License in practice
MIT license (permissive) — you can use, modify, and distribute this package freely in commercial and open-source projects with minimal restrictions.
Quickstart
pip install packageurl-python
from packageurl import PackageURL
purl = PackageURL.from_string("pkg:maven/org.apache.commons/io@1.3.4")
print(purl.to_string())
Verify before relying
- Whether the Django and SQLAlchemy contrib modules are production-ready or experimental.
- Performance characteristics when parsing or building very large numbers of purls.
- Completeness of purl-to-URL inference for all supported package types.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 263 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 35,215,310 / month, #749 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Software Development :: LibrariesTopic :: UtilitiesTyping :: Typed |
Evidence: packageurl_python-0.17.6-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “purl builder parser”
- packageurl-pythonParses and builds Package URLs (purls) — standardized identifiers for…
- socketdevA Python SDK that wraps the Socket.dev REST API, enabling…
- purlProvides an immutable, chainable URL class for constructing, parsing,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also purl · pypi-simple · furl · mozilla-repo-urls · s3urls · taskcluster-urls · hbreader · std-uritemplate · git-url-parse · urlextract