Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 23 additions & 7 deletions NOTICE
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,12 @@ license, at your option. See LICENSE-APACHE and LICENSE-MIT.

The version/ package is derived from rstudio/go-pep440-version, itself a fork of
aquasecurity/go-pep440-version (https://github.com/aquasecurity/go-pep440-version),
licensed under the Apache License, Version 2.0.
Copyright (c) Aqua Security Software Ltd., licensed under the Apache License,
Version 2.0. The version/ package also directly adapts material from
pypa/packaging (https://github.com/pypa/packaging); see the version/-specific
paragraphs below (the letter-normalization tables, cmpkey, the
specifier-matching helpers, and the conformance test ports) for the exact
files, symbols, and pinned commit.

The distribution/ package is ported from rstudio/python-distribution-parser
(https://github.com/rstudio/python-distribution-parser), Copyright (c) 2024
Expand Down Expand Up @@ -39,8 +44,8 @@ tag ordering) from pypa/packaging (https://github.com/pypa/packaging),
specifically packaging/tags.py's cpython_tags, generic_tags, compatible_tags,
sys_tags, mac_platforms and _mac_binary_formats, packaging/_manylinux.py's
platform_tags cross-major glibc walk and its _LAST_GLIBC_MINOR placeholder
value (pinned at 6ce6143ac8eebd91b7b0d38e92618f0702e933af, packaging 26.2), and
packaging/_musllinux.py; and from Astral's uv
value (pinned at commit 84a87ee42483d7352f9502d78a9553da8859aa7a, the release
26.2 tag's commit), and packaging/_musllinux.py; and from Astral's uv
(https://github.com/astral-sh/uv), specifically the uv-platform-tags crate,
dual-licensed under the Apache License, Version 2.0, or the MIT license.

Expand Down Expand Up @@ -94,8 +99,14 @@ The requirement/ package adapts the dependency-specifier grammar of
pypa/packaging (https://github.com/pypa/packaging), specifically
packaging/_parser.py's `_parse_requirement` and packaging/requirements.py's
`Requirement`, licensed under the Apache License, Version 2.0; and Astral
uv's (https://github.com/astral-sh/uv) `uv-pep508` crate, dual-licensed
under the Apache License, Version 2.0, or the MIT license.
uv's (https://github.com/astral-sh/uv) `uv-pep508` crate. Unlike the rest of
uv's workspace, `uv-pep508` (and `uv-pep440`) override the workspace license
per-crate to the Apache License, Version 2.0, or the two-clause BSD license,
and ship their own License-Apache and License-BSD files; `uv-pep508`'s
License-BSD reads Copyright (c) 2023 konstin. `uv-pep508` began as konstin's
independent `pep508_rs` crate, later folded into uv, and pep508_rs's own test
suite already ported cases from pypa/packaging. Material from `uv-pep508` is
taken under whichever of its two arms applies.

The marker/ package's Environment platform mapping (os_name, sys_platform,
platform_system, platform_release, platform_version) adapts the
Expand Down Expand Up @@ -137,8 +148,13 @@ The version/ package's conformance tests port the PEP 440 version-specifier
cases of pypa/packaging (https://github.com/pypa/packaging), Copyright (c)
Donald Stufft and individual contributors, specifically
tests/test_specifiers.py's classes TestSpecifier and TestSpecifierSet, pinned
at commit 4eb0753dba8fcaaac8eb75463374e448f0931558 (release 26.2), licensed
under the Apache License, Version 2.0. Translated from Python/pytest to Go
at commit 4eb0753dba8fcaaac8eb75463374e448f0931558 (pypa/packaging main,
2026-07-28, 128 commits after the 26.2 release). Both classes gained
unrelated tests and assertions after 26.2; the ported cross-product and
invalid-specifier tables themselves include a non-ASCII case added after
26.2, so 4eb0753 rather than the 26.2 release commit is the pin the ported
content actually matches. Licensed under the Apache License, Version 2.0.
Translated from Python/pytest to Go
table-driven tests, in version/specifier_conformance_test.go and
version/specifierset_conformance_test.go. Upstream tests resting on
implementation details with no counterpart here are not ported, and the reason
Expand Down
18 changes: 18 additions & 0 deletions distribution/internal/distributions/distribution.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,22 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from the Python `pkginfo` package
// (Copyright (c) 2009 Agendaless Consulting, Inc. and Contributors; see
// NOTICE), specifically pkginfo/distribution.py's per-metadata-version
// header attribute tables (HeaderAttrs1_0 through HeaderAttrs2_4) and its
// header-parsing and leading-whitespace-collapsing logic, used under the MIT
// license.
//
// The SafeName function is ported from pypa/twine
// (https://github.com/pypa/twine), Copyright (c) 2013 Donald Stufft and
// individual contributors and Copyright (c) 2015 Ian Cordasco, specifically
// its port of pkg_resources.safe_name (see
// https://github.com/pypa/twine/issues/743), used under the Apache License,
// Version 2.0. See NOTICE for full license and copyright detail for both.
//
// Changed: translated from Python to Go. Parse returns a Go error instead
// of raising; collapseLeadingWS operates on Go strings rather than Python's
// email.message header folding.

package distributions

Expand Down
12 changes: 12 additions & 0 deletions distribution/internal/distributions/metadata.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,16 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/twine
// (https://github.com/pypa/twine), Copyright (c) 2013 Donald Stufft and
// individual contributors and Copyright (c) 2015 Ian Cordasco, specifically
// its DIST_EXTENSIONS mapping and distribution-type/Python-version guessing
// logic (DistExtensions and NewDistributionMetadata below), used under the
// Apache License, Version 2.0. See NOTICE for full license and copyright
// detail.
// Changed: translated from Python to Go; returns a Go error instead of
// raising. getFullExtension is a local helper with no twine counterpart,
// needed because Go has no os.path.splitext equivalent for multi-dot
// extensions like ".tar.gz".

package distributions

Expand Down
10 changes: 10 additions & 0 deletions distribution/internal/distributions/sdist.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,14 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/twine
// (https://github.com/pypa/twine), Copyright (c) 2013 Donald Stufft and
// individual contributors and Copyright (c) 2015 Ian Cordasco, specifically
// its SDist class's read() logic that picks the shortest PKG-INFO path
// containing a "Metadata-Version" line, used under the Apache License,
// Version 2.0. See NOTICE for full license and copyright detail.
// Changed: translated from Python to Go; archive reading goes through this
// package's own archiver.ArchiveReader abstraction instead of Python's
// tarfile/zipfile.

package distributions

Expand Down
11 changes: 11 additions & 0 deletions distribution/internal/distributions/wheel.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,15 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/twine
// (https://github.com/pypa/twine), Copyright (c) 2013 Donald Stufft and
// individual contributors and Copyright (c) 2015 Ian Cordasco, specifically
// its Wheel class: the WHEEL_FILE_RE pattern (wheelFileRe below) and the
// read()/python_version logic that picks the shortest dist-info/METADATA
// path containing a "Metadata-Version" line, used under the Apache License,
// Version 2.0. See NOTICE for full license and copyright detail.
// Changed: translated from Python to Go; archive reading goes through this
// package's own archiver.ArchiveReader abstraction instead of Python's
// zipfile.

package distributions

Expand Down
10 changes: 10 additions & 0 deletions distribution/internal/packages/hash_manager.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,14 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/twine
// (https://github.com/pypa/twine), Copyright (c) 2013 Donald Stufft and
// individual contributors and Copyright (c) 2015 Ian Cordasco, specifically
// its HashManager class (md5/sha256/blake2 digests computed over chunked
// file reads), used under the Apache License, Version 2.0. See NOTICE for
// full license and copyright detail.
// Changed: translated from Python's hashlib/hashlib.blake2b to Go's
// crypto/md5, crypto/sha256, and golang.org/x/crypto/blake2b; nil-receiver
// guards on md5Hasher/blake2Hasher replace Python's Optional handling.

package packages

Expand Down
10 changes: 10 additions & 0 deletions distribution/parse.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,14 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/twine
// (https://github.com/pypa/twine), Copyright (c) 2013 Donald Stufft and
// individual contributors and Copyright (c) 2015 Ian Cordasco, specifically
// its upload command's find_dists and group_wheel_files_first
// (findDistributions and groupWheelFilesFirst below), used under the Apache
// License, Version 2.0. See NOTICE for full license and copyright detail.
// Changed: translated from Python to Go; findDistributions/Parse return Go
// errors instead of raising, and glob expansion goes through filepath.Glob
// instead of Python's glob.glob.

package distribution

Expand Down
10 changes: 10 additions & 0 deletions distribution/types/types.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,14 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/twine
// (https://github.com/pypa/twine), Copyright (c) 2013 Donald Stufft and
// individual contributors and Copyright (c) 2015 Ian Cordasco, specifically
// the package-file metadata dictionary its upload command builds for a
// multipart request (PackageFile and MetadataMap below), used under the
// Apache License, Version 2.0. See NOTICE for full license and copyright
// detail.
// Changed: translated from Python to Go; PackageFile is a typed struct
// rather than a dict, with json tags standing in for twine's dict keys.

package types

Expand Down
10 changes: 10 additions & 0 deletions extras/extras.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,14 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/packaging
// (https://github.com/pypa/packaging), specifically packaging/utils.py's
// canonicalize_name, used under the Apache License, Version 2.0
// (dual-licensed Apache-2.0 OR BSD-2-Clause; see NOTICE for full license and
// copyright detail).
// Changed: translated from a single re.sub regex into an explicit
// rune-by-rune loop, since extra-name normalization sits on a
// per-dependency hot path; behavior (lowercase, collapse -/_/. runs to one
// "-") is unchanged.

package extras

Expand Down
8 changes: 8 additions & 0 deletions internal/pep508/grammar_conformance_test.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,12 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file port test cases from pypa/packaging
// (https://github.com/pypa/packaging), specifically
// tests/test_requirements.py's class TestRequirementParsing, used under the
// Apache License, Version 2.0 (dual-licensed Apache-2.0 OR BSD-2-Clause; see
// NOTICE for full license and copyright detail).
// Changed: translated from Python/pytest parametrized cases into Go
// table-driven subtests; case selection and pin SHA are noted per-test below.

package pep508

Expand Down
10 changes: 10 additions & 0 deletions internal/pep508/marker.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,14 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/packaging
// (https://github.com/pypa/packaging), specifically packaging/_parser.py's
// marker productions (_parse_marker and friends) and process_env_var, used
// under the Apache License, Version 2.0 (dual-licensed Apache-2.0 OR
// BSD-2-Clause; see NOTICE for full license and copyright detail).
// Changed: translated the recursive-descent parser from Python's generator-
// based token iteration into Go functions returning (Expr, error); "and"/
// "or" precedence grouping, built implicitly by upstream's AST shape, is
// rebuilt explicitly here.

package pep508

Expand Down
10 changes: 10 additions & 0 deletions internal/pep508/requirement.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,14 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/packaging
// (https://github.com/pypa/packaging), specifically packaging/_parser.py's
// _parse_requirement and packaging/requirements.py's Requirement, used
// under the Apache License, Version 2.0 (dual-licensed Apache-2.0 OR
// BSD-2-Clause; see NOTICE for full license and copyright detail).
// Changed: translated from Python's exception-raising parse functions into
// Go functions returning (RawRequirement, error); name canonicalization,
// extras normalization, and marker evaluation are deferred to the callers
// in package requirement and package marker rather than done inline here.

package pep508

Expand Down
10 changes: 10 additions & 0 deletions internal/pep508/tokenizer.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,14 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/packaging
// (https://github.com/pypa/packaging), specifically packaging/_tokenizer.py's
// Tokenizer, Token, ParserSyntaxError, and DEFAULT_RULES, used under the
// Apache License, Version 2.0 (dual-licensed Apache-2.0 OR BSD-2-Clause; see
// NOTICE for full license and copyright detail).
// Changed: translated from Python's re.match-at-position calls into Go's
// regexp.FindStringIndex on a byte-offset substring; DEFAULT_RULES' string
// keys become a typed Kind enum, and ParserSyntaxError becomes *SyntaxError
// returned as a Go error rather than raised.

package pep508

Expand Down
11 changes: 11 additions & 0 deletions marker/environment.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,15 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from Astral's uv
// (https://github.com/astral-sh/uv), specifically the uv-configuration
// crate's TargetTriple (the linux/macos/windows cases of its platform-tag
// logic, adapted to fill os_name, sys_platform, platform_system,
// platform_release, and platform_version), used under the Apache License,
// Version 2.0 (uv workspace dual-licensed Apache-2.0 OR MIT; see NOTICE for
// full license and copyright detail).
// Changed: translated from Rust to Go; returns a Go error
// (ErrUnsupportedTarget) instead of Rust's Result/panic, and reads a
// tags.Target plus InterpreterIdentity instead of TargetTriple's own enum.

package marker

Expand Down
11 changes: 11 additions & 0 deletions marker/evaluate.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,15 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/packaging
// (https://github.com/pypa/packaging), specifically packaging/markers.py's
// _eval_op and its operator/specifier dispatch (including
// MARKERS_REQUIRING_VERSION, reflected below as versionTypedVars), used
// under the Apache License, Version 2.0 (dual-licensed Apache-2.0 OR
// BSD-2-Clause; see NOTICE for full license and copyright detail).
// Changed: translated from Python to Go; an unresolvable comparison records
// an Undecidable value instead of raising UndefinedEnvironmentName, and
// version-typed comparisons delegate to package version instead of
// packaging.specifiers.

package marker

Expand Down
8 changes: 8 additions & 0 deletions reqtxt/classify.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,12 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pip
// (https://github.com/pypa/pip), specifically pip/_internal/utils/misc.py's
// is_url and is_archive_file, and the VCS scheme registration in
// pip/_internal/vcs/{git,mercurial,subversion,bazaar}.py, used under the MIT
// license; see NOTICE for full license and copyright detail.
// Changed: translated from Python to Go as a pure, shape-only string
// classifier that never touches the filesystem, unlike pip's originals.

package reqtxt

Expand Down
9 changes: 9 additions & 0 deletions reqtxt/flatten.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,13 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pip
// (https://github.com/pypa/pip), specifically the include-following of
// pip/_internal/req/req_file.py's RequirementsFileParser._parse_and_recurse,
// used under the MIT license; see NOTICE for full license and copyright
// detail.
// Changed: translated from Python's recursive parser-instance walk into an
// explicit Go recursion building a single flattened File value; the
// nested_constraint propagation rule is reproduced as a plain bool parameter.

package reqtxt

Expand Down
9 changes: 9 additions & 0 deletions reqtxt/parse.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,13 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pip
// (https://github.com/pypa/pip), specifically pip/_internal/req/req_file.py's
// SUPPORTED_OPTIONS, SUPPORTED_OPTIONS_REQ, break_args_options, and
// process_line, used under the MIT license; see NOTICE for full license and
// copyright detail.
// Changed: translated from Python's optparse-based option handling into
// explicit Go dispatch functions; pip's non-fatal warnings (e.g. --hash with
// no value) are represented as returned errors or dropped values instead.

package reqtxt

Expand Down
9 changes: 9 additions & 0 deletions reqtxt/preprocess.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,13 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pip
// (https://github.com/pypa/pip), specifically pip/_internal/req/req_file.py's
// COMMENT_RE, ENV_VAR_RE, join_lines, and the preprocess line-joining
// pipeline, used under the MIT license; see NOTICE for full license and
// copyright detail.
// Changed: translated from Python to Go; join_lines' backslash-continuation
// guard is expressed with explicit byte-offset scanning instead of Python's
// regex match objects.

package reqtxt

Expand Down
9 changes: 9 additions & 0 deletions reqtxt/shlex.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,13 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pip
// (https://github.com/pypa/pip), specifically the POSIX-mode
// shlex.split(line, comments=False, posix=True) behavior pip's
// pip/_internal/req/req_file.py relies on for a requirements-file line,
// used under the MIT license; see NOTICE for full license and copyright
// detail.
// Changed: reimplemented Python's shlex POSIX-mode splitting rules directly
// in Go, since Go has no shlex equivalent in its standard library.

package reqtxt

Expand Down
9 changes: 9 additions & 0 deletions reqtxt/types.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,13 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pip
// (https://github.com/pypa/pip), specifically the include-following
// bookkeeping (nested_constraint, source file tracking) of
// pip/_internal/req/req_file.py's RequirementsFileParser._parse_and_recurse,
// used under the MIT license; see NOTICE for full license and copyright
// detail.
// Changed: translated from Python's parser-instance state into explicit Go
// struct fields (UnnamedEntry, OptionEntry) carried on each entry value.

package reqtxt

Expand Down
12 changes: 12 additions & 0 deletions requirement/conformance_test.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,16 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/packaging
// (https://github.com/pypa/packaging), specifically
// tests/test_requirements.py's test_basic_valid_requirement_parsing
// cross-product parameters and the invalid-requirement cases of class
// TestRequirementParsing, used under the Apache License, Version 2.0
// (dual-licensed Apache-2.0 OR BSD-2-Clause; see NOTICE for full license and
// copyright detail).
// Changed: translated from Python/pytest to Go table-driven tests; the
// parametrize cross-product is expressed as a curated subset with
// equivalent coverage. See the divergence notes below for cases where the
// Go expectation intentionally differs from upstream's literal assertion.

// This file contains ONLY cases ported from pypa/packaging's test suite, one
// Go table per upstream test function. Hand-written cases belong in
Expand Down
10 changes: 10 additions & 0 deletions requirement/requirement.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,14 @@
// SPDX-License-Identifier: Apache-2.0 OR MIT
//
// Portions of this file are ported from pypa/packaging
// (https://github.com/pypa/packaging), specifically
// packaging/requirements.py's Requirement.__str__ rendering rule (the
// " ; " vs "; " marker separator, chosen so a bare ";" is never ambiguous
// with a ";" inside a URL), used under the Apache License, Version 2.0
// (dual-licensed Apache-2.0 OR BSD-2-Clause; see NOTICE for full license and
// copyright detail).
// Changed: translated from Python to Go; Parse itself is original glue over
// the already-attributed internal/pep508 parser rather than a further port.

package requirement

Expand Down
Loading
Loading