Repository navigation
Releases: millsks/pixi-sbom
Release list
Release v1.7.0
1.7.0 - 2026-10-08
Features
- examples: Real projects for every non-pixi reader, written by the real tools (#363) (74a5660)
- input: Read pylock.toml (PEP 751) (#364) (aaa8ef0)
- input: Read uv.lock, and find it by the upward search (#366) (bd098da)
- input: Read poetry.lock (lock-version 2.x) (#367) (25abba3)
- input: Read pdm.lock (lock_version 4.x) (#368) (5c65fff)
- input: Read conda-lock.yml (unified, version 1) (#369) (2b82c59)
- input: Read explicit conda spec files (#370) (371cf6d)
- manifest: Declared dependencies beside non-pixi lockfiles (#371) (5978b18)
- pypi: Record Python extras as pixi:python-extras and pixi:via-extra (#372) (5f4599b)
- format: Dependency groups as CycloneDX scope and SPDX dev/optional relationships (#373) (632819a)
- prefix: Describe plain venvs and site-packages, not only conda environments (#374) (acee39e)
- prefix: Mark user-requested packages as direct from REQUESTED (#376) (9e22091)
- prefix: --infer-extras for venvs, labelled as inferred (#377) (7060a59)
- discover: Find every supported lockfile kind in the upward search and --scan (#378) (8e71644)
- diff: --against accepts every supported lockfile, for venv drift checks (#379) (447359b)
- Pre-commit hooks for writing the SBOM and the license gate (#382) (916524b)
- action: Prefix and from-sbom inputs, and a tested example for uv projects (#383) (e85cfc9)
Bug Fixes
- format: Lifecycle phase from the input, not always pre-build (#365) (a6a61e6)
- purl: VCS, local and editable installs no longer claim a PyPI purl (#375) (b1053f0)
- test: The never-consulted cache test no longer races the stale test (#387) (a3a7f9d)
- release: Attach the wheels to the release deterministically (#388) (28cfefc)
Documentation
- Using pixi-sbom without pixi, and a README that says what it reads (#385) (908f942)
- How to get a lockfile pixi-sbom reads, for every common setup (#390) (ecbc6c2)
- The Pipenv route is for Pipenv-managed projects; a pip venv uses --prefix (#391) (98bb4b8)
Testing
Release artifacts
| Artifact | Platform |
|---|---|
pixi-sbom-v1.7.0-linux-64.tar.gz |
Linux x86_64 |
pixi-sbom-v1.7.0-linux-aarch64.tar.gz |
Linux arm64 |
pixi-sbom-v1.7.0-osx-64.tar.gz |
macOS Intel |
pixi-sbom-v1.7.0-osx-arm64.tar.gz |
macOS Apple Silicon |
pixi-sbom-v1.7.0-win-64.zip |
Windows x86_64 |
Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.
The same binary is attached as Python wheels (pixi_sbom-*.whl, no Python code) for Linux glibc and musl
x86_64 and aarch64, macOS x86_64 and arm64, and Windows x86_64, published to PyPI (TestPyPI for a release
candidate) as well. Where PyPI is out of reach, install one straight from this release:
pip install https://github.com/millsks/pixi-sbom/releases/download/v1.7.0/<wheel>.
To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:
gh attestation verify pixi-sbom-v1.7.0-linux-64.tar.gz --repo millsks/pixi-sbom \
--signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
--source-ref refs/tags/v1.7.0 \
--deny-self-hosted-runnersAdd --bundle pixi-sbom-v1.7.0-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.
Full changelog: CHANGELOG.md
Release v1.7.0-rc.1
1.6.0 - 2026-10-07
Features
- vex: Machine-readable justification for not_affected assessments (#338) (e0ab8a9)
- vex: Write analysis.response, and say why the assessment dates are not (#350) (aeb6b0b)
- Default --conda-index-kind to prefix; anaconda stays selectable (#356) (84f9ff6)
Bug Fixes
- Let the changelog span prereleases instead of fragmenting on them (#316) (7c9f50e)
- vex: Refuse --vex with --format spdx instead of writing a VEX that links nowhere (#320) (adcf8e9)
- Batched prefix.dev queries never exceed --concurrency (#355) (907d389)
- Show --report outdated progress while prefix.dev batches are in flight (#359) (e02772c)
- Count a batched package as soon as its batch lands (#360) (6a23b9f)
Documentation
Testing
Release artifacts
| Artifact | Platform |
|---|---|
pixi-sbom-v1.7.0-rc.1-linux-64.tar.gz |
Linux x86_64 |
pixi-sbom-v1.7.0-rc.1-linux-aarch64.tar.gz |
Linux arm64 |
pixi-sbom-v1.7.0-rc.1-osx-64.tar.gz |
macOS Intel |
pixi-sbom-v1.7.0-rc.1-osx-arm64.tar.gz |
macOS Apple Silicon |
pixi-sbom-v1.7.0-rc.1-win-64.zip |
Windows x86_64 |
Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.
The same binary is attached as Python wheels (pixi_sbom-*.whl, no Python code) for Linux glibc and musl
x86_64 and aarch64, macOS x86_64 and arm64, and Windows x86_64, published to PyPI (TestPyPI for a release
candidate) as well. Where PyPI is out of reach, install one straight from this release:
pip install https://github.com/millsks/pixi-sbom/releases/download/v1.7.0-rc.1/<wheel>.
To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:
gh attestation verify pixi-sbom-v1.7.0-rc.1-linux-64.tar.gz --repo millsks/pixi-sbom \
--signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
--source-ref refs/tags/v1.7.0-rc.1 \
--deny-self-hosted-runnersAdd --bundle pixi-sbom-v1.7.0-rc.1-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.
Full changelog: CHANGELOG.md
Release v1.6.0
1.6.0 - 2026-10-07
Features
- vex: Machine-readable justification for not_affected assessments (#338) (e0ab8a9)
- vex: Write analysis.response, and say why the assessment dates are not (#350) (aeb6b0b)
- Default --conda-index-kind to prefix; anaconda stays selectable (#356) (84f9ff6)
Bug Fixes
- Let the changelog span prereleases instead of fragmenting on them (#316) (7c9f50e)
- vex: Refuse --vex with --format spdx instead of writing a VEX that links nowhere (#320) (adcf8e9)
- Batched prefix.dev queries never exceed --concurrency (#355) (907d389)
- Show --report outdated progress while prefix.dev batches are in flight (#359) (e02772c)
- Count a batched package as soon as its batch lands (#360) (6a23b9f)
Documentation
Testing
Release artifacts
| Artifact | Platform |
|---|---|
pixi-sbom-v1.6.0-linux-64.tar.gz |
Linux x86_64 |
pixi-sbom-v1.6.0-linux-aarch64.tar.gz |
Linux arm64 |
pixi-sbom-v1.6.0-osx-64.tar.gz |
macOS Intel |
pixi-sbom-v1.6.0-osx-arm64.tar.gz |
macOS Apple Silicon |
pixi-sbom-v1.6.0-win-64.zip |
Windows x86_64 |
Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.
To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:
gh attestation verify pixi-sbom-v1.6.0-linux-64.tar.gz --repo millsks/pixi-sbom \
--signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
--source-ref refs/tags/v1.6.0 \
--deny-self-hosted-runnersAdd --bundle pixi-sbom-v1.6.0-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.
Full changelog: CHANGELOG.md
Release v1.6.0-rc.2
1.5.0 - 2026-10-04
Features
- Retry a rate limit, and stop reporting an unasked index as no upstream (#304) (c3b352b)
- Add --concurrency and a concurrency configuration key (#307) (c2bc82e)
- Say in --doctor how many requests and which conda index (#308) (729812d)
Bug Fixes
- Count the network a run used, not the network it could have used (#300) (991b517)
- Keep the machine's own configuration out of the test suite (#303) (3bd9dfe)
- Stop a mistyped concurrency from hanging the run and then panicking (#305) (a46c1bc)
- Stop tying requests in flight to the core count (#306) (07eefcc)
- Date a batch's newer releases in parallel, not one after another (#313) (4bdd2f2)
- Count a batched fetch as a fetch, not as a cache hit (#314) (e8e7b75)
- ci: Release the version that was asked for, even with no new commits (#315) (3134602)
Performance
- Share one HTTP agent so connections are reused (#301) (c186101)
- Ask prefix.dev about ten packages per request (#309) (d7fd067)
Release artifacts
| Artifact | Platform |
|---|---|
pixi-sbom-v1.6.0-rc.2-linux-64.tar.gz |
Linux x86_64 |
pixi-sbom-v1.6.0-rc.2-linux-aarch64.tar.gz |
Linux arm64 |
pixi-sbom-v1.6.0-rc.2-osx-64.tar.gz |
macOS Intel |
pixi-sbom-v1.6.0-rc.2-osx-arm64.tar.gz |
macOS Apple Silicon |
pixi-sbom-v1.6.0-rc.2-win-64.zip |
Windows x86_64 |
Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.
To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:
gh attestation verify pixi-sbom-v1.6.0-rc.2-linux-64.tar.gz --repo millsks/pixi-sbom \
--signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
--source-ref refs/tags/v1.6.0-rc.2 \
--deny-self-hosted-runnersAdd --bundle pixi-sbom-v1.6.0-rc.2-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.
Full changelog: CHANGELOG.md
Release v1.6.0-rc.1
1.5.0 - 2026-10-04
Features
- Retry a rate limit, and stop reporting an unasked index as no upstream (#304) (c3b352b)
- Add --concurrency and a concurrency configuration key (#307) (c2bc82e)
- Say in --doctor how many requests and which conda index (#308) (729812d)
Bug Fixes
- Count the network a run used, not the network it could have used (#300) (991b517)
- Keep the machine's own configuration out of the test suite (#303) (3bd9dfe)
- Stop a mistyped concurrency from hanging the run and then panicking (#305) (a46c1bc)
- Stop tying requests in flight to the core count (#306) (07eefcc)
- Date a batch's newer releases in parallel, not one after another (#313) (4bdd2f2)
- Count a batched fetch as a fetch, not as a cache hit (#314) (e8e7b75)
- ci: Release the version that was asked for, even with no new commits (#315) (3134602)
Performance
- Share one HTTP agent so connections are reused (#301) (c186101)
- Ask prefix.dev about ten packages per request (#309) (d7fd067)
Release artifacts
| Artifact | Platform |
|---|---|
pixi-sbom-v1.6.0-rc.1-linux-64.tar.gz |
Linux x86_64 |
pixi-sbom-v1.6.0-rc.1-linux-aarch64.tar.gz |
Linux arm64 |
pixi-sbom-v1.6.0-rc.1-osx-64.tar.gz |
macOS Intel |
pixi-sbom-v1.6.0-rc.1-osx-arm64.tar.gz |
macOS Apple Silicon |
pixi-sbom-v1.6.0-rc.1-win-64.zip |
Windows x86_64 |
Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.
To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:
gh attestation verify pixi-sbom-v1.6.0-rc.1-linux-64.tar.gz --repo millsks/pixi-sbom \
--signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
--source-ref refs/tags/v1.6.0-rc.1 \
--deny-self-hosted-runnersAdd --bundle pixi-sbom-v1.6.0-rc.1-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.
Full changelog: CHANGELOG.md
Release v1.5.0
1.5.0 - 2026-10-04
Features
- Retry a rate limit, and stop reporting an unasked index as no upstream (#304) (c3b352b)
- Add --concurrency and a concurrency configuration key (#307) (c2bc82e)
- Say in --doctor how many requests and which conda index (#308) (729812d)
Bug Fixes
- Count the network a run used, not the network it could have used (#300) (991b517)
- Keep the machine's own configuration out of the test suite (#303) (3bd9dfe)
- Stop a mistyped concurrency from hanging the run and then panicking (#305) (a46c1bc)
- Stop tying requests in flight to the core count (#306) (07eefcc)
- Date a batch's newer releases in parallel, not one after another (#313) (4bdd2f2)
- Count a batched fetch as a fetch, not as a cache hit (#314) (e8e7b75)
- ci: Release the version that was asked for, even with no new commits (#315) (3134602)
Performance
- Share one HTTP agent so connections are reused (#301) (c186101)
- Ask prefix.dev about ten packages per request (#309) (d7fd067)
Release artifacts
| Artifact | Platform |
|---|---|
pixi-sbom-v1.5.0-linux-64.tar.gz |
Linux x86_64 |
pixi-sbom-v1.5.0-linux-aarch64.tar.gz |
Linux arm64 |
pixi-sbom-v1.5.0-osx-64.tar.gz |
macOS Intel |
pixi-sbom-v1.5.0-osx-arm64.tar.gz |
macOS Apple Silicon |
pixi-sbom-v1.5.0-win-64.zip |
Windows x86_64 |
Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.
To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:
gh attestation verify pixi-sbom-v1.5.0-linux-64.tar.gz --repo millsks/pixi-sbom \
--signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
--source-ref refs/tags/v1.5.0 \
--deny-self-hosted-runnersAdd --bundle pixi-sbom-v1.5.0-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.
Full changelog: CHANGELOG.md
Release v1.5.0-rc.3
1.5.0-rc.3 - 2026-10-04
Bug Fixes
Release artifacts
| Artifact | Platform |
|---|---|
pixi-sbom-v1.5.0-rc.3-linux-64.tar.gz |
Linux x86_64 |
pixi-sbom-v1.5.0-rc.3-linux-aarch64.tar.gz |
Linux arm64 |
pixi-sbom-v1.5.0-rc.3-osx-64.tar.gz |
macOS Intel |
pixi-sbom-v1.5.0-rc.3-osx-arm64.tar.gz |
macOS Apple Silicon |
pixi-sbom-v1.5.0-rc.3-win-64.zip |
Windows x86_64 |
Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.
To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:
gh attestation verify pixi-sbom-v1.5.0-rc.3-linux-64.tar.gz --repo millsks/pixi-sbom \
--signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
--source-ref refs/tags/v1.5.0-rc.3 \
--deny-self-hosted-runnersAdd --bundle pixi-sbom-v1.5.0-rc.3-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.
Full changelog: CHANGELOG.md
Release v1.5.0-rc.2
1.5.0-rc.2 - 2026-10-04
Bug Fixes
Release artifacts
| Artifact | Platform |
|---|---|
pixi-sbom-v1.5.0-rc.2-linux-64.tar.gz |
Linux x86_64 |
pixi-sbom-v1.5.0-rc.2-linux-aarch64.tar.gz |
Linux arm64 |
pixi-sbom-v1.5.0-rc.2-osx-64.tar.gz |
macOS Intel |
pixi-sbom-v1.5.0-rc.2-osx-arm64.tar.gz |
macOS Apple Silicon |
pixi-sbom-v1.5.0-rc.2-win-64.zip |
Windows x86_64 |
Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.
To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:
gh attestation verify pixi-sbom-v1.5.0-rc.2-linux-64.tar.gz --repo millsks/pixi-sbom \
--signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
--source-ref refs/tags/v1.5.0-rc.2 \
--deny-self-hosted-runnersAdd --bundle pixi-sbom-v1.5.0-rc.2-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.
Full changelog: CHANGELOG.md
Release v1.5.0-rc.1
1.5.0-rc.1 - 2026-10-03
Features
- Retry a rate limit, and stop reporting an unasked index as no upstream (#304) (c3b352b)
- Add --concurrency and a concurrency configuration key (#307) (c2bc82e)
- Say in --doctor how many requests and which conda index (#308) (729812d)
Bug Fixes
- Count the network a run used, not the network it could have used (#300) (991b517)
- Keep the machine's own configuration out of the test suite (#303) (3bd9dfe)
- Stop a mistyped concurrency from hanging the run and then panicking (#305) (a46c1bc)
- Stop tying requests in flight to the core count (#306) (07eefcc)
Performance
- Share one HTTP agent so connections are reused (#301) (c186101)
- Ask prefix.dev about ten packages per request (#309) (d7fd067)
Release artifacts
| Artifact | Platform |
|---|---|
pixi-sbom-v1.5.0-rc.1-linux-64.tar.gz |
Linux x86_64 |
pixi-sbom-v1.5.0-rc.1-linux-aarch64.tar.gz |
Linux arm64 |
pixi-sbom-v1.5.0-rc.1-osx-64.tar.gz |
macOS Intel |
pixi-sbom-v1.5.0-rc.1-osx-arm64.tar.gz |
macOS Apple Silicon |
pixi-sbom-v1.5.0-rc.1-win-64.zip |
Windows x86_64 |
Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.
To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:
gh attestation verify pixi-sbom-v1.5.0-rc.1-linux-64.tar.gz --repo millsks/pixi-sbom \
--signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
--source-ref refs/tags/v1.5.0-rc.1 \
--deny-self-hosted-runnersAdd --bundle pixi-sbom-v1.5.0-rc.1-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.
Full changelog: CHANGELOG.md
Release v1.4.0
1.4.0 - 2026-10-03
Features
- Let the configuration file choose the conda index (#286) (d8171ec)
- Read system and user configuration from pixi's directories (#289) (fa3dcd8)
Bug Fixes
- Confirm a mirrored package's channel by its hash, not its name (#281) (82df2d1)
- Match the installed build by its build string, not by scanning a page (#283) (e0c1f19)
- Stop blaming credentials for an answer the probe asked for (#290) (f428509)
Performance
Release artifacts
| Artifact | Platform |
|---|---|
pixi-sbom-v1.4.0-linux-64.tar.gz |
Linux x86_64 |
pixi-sbom-v1.4.0-linux-aarch64.tar.gz |
Linux arm64 |
pixi-sbom-v1.4.0-osx-64.tar.gz |
macOS Intel |
pixi-sbom-v1.4.0-osx-arm64.tar.gz |
macOS Apple Silicon |
pixi-sbom-v1.4.0-win-64.zip |
Windows x86_64 |
Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.
To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:
gh attestation verify pixi-sbom-v1.4.0-linux-64.tar.gz --repo millsks/pixi-sbom \
--signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
--source-ref refs/tags/v1.4.0 \
--deny-self-hosted-runnersAdd --bundle pixi-sbom-v1.4.0-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.
Full changelog: CHANGELOG.md