Skip to content

Releases: millsks/pixi-sbom

Release v1.7.0

Choose a tag to compare

@millsks-release-helper millsks-release-helper released this 08 Oct 02:29

1.7.0 - 2026-10-08

Features

  • examples: Real projects for every non-pixi reader, written by the real tools (#363) (74a5660)
  • input: Read pylock.toml (PEP 751) (#364) (aaa8ef0)
  • input: Read uv.lock, and find it by the upward search (#366) (bd098da)
  • input: Read poetry.lock (lock-version 2.x) (#367) (25abba3)
  • input: Read pdm.lock (lock_version 4.x) (#368) (5c65fff)
  • input: Read conda-lock.yml (unified, version 1) (#369) (2b82c59)
  • input: Read explicit conda spec files (#370) (371cf6d)
  • manifest: Declared dependencies beside non-pixi lockfiles (#371) (5978b18)
  • pypi: Record Python extras as pixi:python-extras and pixi:via-extra (#372) (5f4599b)
  • format: Dependency groups as CycloneDX scope and SPDX dev/optional relationships (#373) (632819a)
  • prefix: Describe plain venvs and site-packages, not only conda environments (#374) (acee39e)
  • prefix: Mark user-requested packages as direct from REQUESTED (#376) (9e22091)
  • prefix: --infer-extras for venvs, labelled as inferred (#377) (7060a59)
  • discover: Find every supported lockfile kind in the upward search and --scan (#378) (8e71644)
  • diff: --against accepts every supported lockfile, for venv drift checks (#379) (447359b)
  • Pre-commit hooks for writing the SBOM and the license gate (#382) (916524b)
  • action: Prefix and from-sbom inputs, and a tested example for uv projects (#383) (e85cfc9)

Bug Fixes

  • format: Lifecycle phase from the input, not always pre-build (#365) (a6a61e6)
  • purl: VCS, local and editable installs no longer claim a PyPI purl (#375) (b1053f0)
  • test: The never-consulted cache test no longer races the stale test (#387) (a3a7f9d)
  • release: Attach the wheels to the release deterministically (#388) (28cfefc)

Documentation

  • Using pixi-sbom without pixi, and a README that says what it reads (#385) (908f942)
  • How to get a lockfile pixi-sbom reads, for every common setup (#390) (ecbc6c2)
  • The Pipenv route is for Pipenv-managed projects; a pip venv uses --prefix (#391) (98bb4b8)

Testing

  • Every report, enrichment and gate on every input kind (#384) (83b4166)

Release artifacts

Artifact Platform
pixi-sbom-v1.7.0-linux-64.tar.gz Linux x86_64
pixi-sbom-v1.7.0-linux-aarch64.tar.gz Linux arm64
pixi-sbom-v1.7.0-osx-64.tar.gz macOS Intel
pixi-sbom-v1.7.0-osx-arm64.tar.gz macOS Apple Silicon
pixi-sbom-v1.7.0-win-64.zip Windows x86_64

Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.

The same binary is attached as Python wheels (pixi_sbom-*.whl, no Python code) for Linux glibc and musl
x86_64 and aarch64, macOS x86_64 and arm64, and Windows x86_64, published to PyPI (TestPyPI for a release
candidate) as well. Where PyPI is out of reach, install one straight from this release:
pip install https://github.com/millsks/pixi-sbom/releases/download/v1.7.0/<wheel>.

To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:

gh attestation verify pixi-sbom-v1.7.0-linux-64.tar.gz --repo millsks/pixi-sbom \
  --signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
  --source-ref refs/tags/v1.7.0 \
  --deny-self-hosted-runners

Add --bundle pixi-sbom-v1.7.0-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.

Full changelog: CHANGELOG.md

Release v1.7.0-rc.1

Release v1.7.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

1.6.0 - 2026-10-07

Features

  • vex: Machine-readable justification for not_affected assessments (#338) (e0ab8a9)
  • vex: Write analysis.response, and say why the assessment dates are not (#350) (aeb6b0b)
  • Default --conda-index-kind to prefix; anaconda stays selectable (#356) (84f9ff6)

Bug Fixes

  • Let the changelog span prereleases instead of fragmenting on them (#316) (7c9f50e)
  • vex: Refuse --vex with --format spdx instead of writing a VEX that links nowhere (#320) (adcf8e9)
  • Batched prefix.dev queries never exceed --concurrency (#355) (907d389)
  • Show --report outdated progress while prefix.dev batches are in flight (#359) (e02772c)
  • Count a batched package as soon as its batch lands (#360) (6a23b9f)

Documentation

  • Why the two conda index kinds disagree on dates, and on the newest hours (#352) (b62c0ed)

Testing

  • A local HTTP server, so request behaviour is asserted rather than timed by hand (#351) (86db1a8)

Release artifacts

Artifact Platform
pixi-sbom-v1.7.0-rc.1-linux-64.tar.gz Linux x86_64
pixi-sbom-v1.7.0-rc.1-linux-aarch64.tar.gz Linux arm64
pixi-sbom-v1.7.0-rc.1-osx-64.tar.gz macOS Intel
pixi-sbom-v1.7.0-rc.1-osx-arm64.tar.gz macOS Apple Silicon
pixi-sbom-v1.7.0-rc.1-win-64.zip Windows x86_64

Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.

The same binary is attached as Python wheels (pixi_sbom-*.whl, no Python code) for Linux glibc and musl
x86_64 and aarch64, macOS x86_64 and arm64, and Windows x86_64, published to PyPI (TestPyPI for a release
candidate) as well. Where PyPI is out of reach, install one straight from this release:
pip install https://github.com/millsks/pixi-sbom/releases/download/v1.7.0-rc.1/<wheel>.

To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:

gh attestation verify pixi-sbom-v1.7.0-rc.1-linux-64.tar.gz --repo millsks/pixi-sbom \
  --signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
  --source-ref refs/tags/v1.7.0-rc.1 \
  --deny-self-hosted-runners

Add --bundle pixi-sbom-v1.7.0-rc.1-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.

Full changelog: CHANGELOG.md

Release v1.6.0

Choose a tag to compare

@millsks-release-helper millsks-release-helper released this 07 Oct 10:54

1.6.0 - 2026-10-07

Features

  • vex: Machine-readable justification for not_affected assessments (#338) (e0ab8a9)
  • vex: Write analysis.response, and say why the assessment dates are not (#350) (aeb6b0b)
  • Default --conda-index-kind to prefix; anaconda stays selectable (#356) (84f9ff6)

Bug Fixes

  • Let the changelog span prereleases instead of fragmenting on them (#316) (7c9f50e)
  • vex: Refuse --vex with --format spdx instead of writing a VEX that links nowhere (#320) (adcf8e9)
  • Batched prefix.dev queries never exceed --concurrency (#355) (907d389)
  • Show --report outdated progress while prefix.dev batches are in flight (#359) (e02772c)
  • Count a batched package as soon as its batch lands (#360) (6a23b9f)

Documentation

  • Why the two conda index kinds disagree on dates, and on the newest hours (#352) (b62c0ed)

Testing

  • A local HTTP server, so request behaviour is asserted rather than timed by hand (#351) (86db1a8)

Release artifacts

Artifact Platform
pixi-sbom-v1.6.0-linux-64.tar.gz Linux x86_64
pixi-sbom-v1.6.0-linux-aarch64.tar.gz Linux arm64
pixi-sbom-v1.6.0-osx-64.tar.gz macOS Intel
pixi-sbom-v1.6.0-osx-arm64.tar.gz macOS Apple Silicon
pixi-sbom-v1.6.0-win-64.zip Windows x86_64

Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.

To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:

gh attestation verify pixi-sbom-v1.6.0-linux-64.tar.gz --repo millsks/pixi-sbom \
  --signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
  --source-ref refs/tags/v1.6.0 \
  --deny-self-hosted-runners

Add --bundle pixi-sbom-v1.6.0-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.

Full changelog: CHANGELOG.md

Release v1.6.0-rc.2

Release v1.6.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

1.5.0 - 2026-10-04

Features

  • Retry a rate limit, and stop reporting an unasked index as no upstream (#304) (c3b352b)
  • Add --concurrency and a concurrency configuration key (#307) (c2bc82e)
  • Say in --doctor how many requests and which conda index (#308) (729812d)

Bug Fixes

  • Count the network a run used, not the network it could have used (#300) (991b517)
  • Keep the machine's own configuration out of the test suite (#303) (3bd9dfe)
  • Stop a mistyped concurrency from hanging the run and then panicking (#305) (a46c1bc)
  • Stop tying requests in flight to the core count (#306) (07eefcc)
  • Date a batch's newer releases in parallel, not one after another (#313) (4bdd2f2)
  • Count a batched fetch as a fetch, not as a cache hit (#314) (e8e7b75)
  • ci: Release the version that was asked for, even with no new commits (#315) (3134602)

Performance

  • Share one HTTP agent so connections are reused (#301) (c186101)
  • Ask prefix.dev about ten packages per request (#309) (d7fd067)

Release artifacts

Artifact Platform
pixi-sbom-v1.6.0-rc.2-linux-64.tar.gz Linux x86_64
pixi-sbom-v1.6.0-rc.2-linux-aarch64.tar.gz Linux arm64
pixi-sbom-v1.6.0-rc.2-osx-64.tar.gz macOS Intel
pixi-sbom-v1.6.0-rc.2-osx-arm64.tar.gz macOS Apple Silicon
pixi-sbom-v1.6.0-rc.2-win-64.zip Windows x86_64

Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.

To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:

gh attestation verify pixi-sbom-v1.6.0-rc.2-linux-64.tar.gz --repo millsks/pixi-sbom \
  --signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
  --source-ref refs/tags/v1.6.0-rc.2 \
  --deny-self-hosted-runners

Add --bundle pixi-sbom-v1.6.0-rc.2-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.

Full changelog: CHANGELOG.md

Release v1.6.0-rc.1

Release v1.6.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

1.5.0 - 2026-10-04

Features

  • Retry a rate limit, and stop reporting an unasked index as no upstream (#304) (c3b352b)
  • Add --concurrency and a concurrency configuration key (#307) (c2bc82e)
  • Say in --doctor how many requests and which conda index (#308) (729812d)

Bug Fixes

  • Count the network a run used, not the network it could have used (#300) (991b517)
  • Keep the machine's own configuration out of the test suite (#303) (3bd9dfe)
  • Stop a mistyped concurrency from hanging the run and then panicking (#305) (a46c1bc)
  • Stop tying requests in flight to the core count (#306) (07eefcc)
  • Date a batch's newer releases in parallel, not one after another (#313) (4bdd2f2)
  • Count a batched fetch as a fetch, not as a cache hit (#314) (e8e7b75)
  • ci: Release the version that was asked for, even with no new commits (#315) (3134602)

Performance

  • Share one HTTP agent so connections are reused (#301) (c186101)
  • Ask prefix.dev about ten packages per request (#309) (d7fd067)

Release artifacts

Artifact Platform
pixi-sbom-v1.6.0-rc.1-linux-64.tar.gz Linux x86_64
pixi-sbom-v1.6.0-rc.1-linux-aarch64.tar.gz Linux arm64
pixi-sbom-v1.6.0-rc.1-osx-64.tar.gz macOS Intel
pixi-sbom-v1.6.0-rc.1-osx-arm64.tar.gz macOS Apple Silicon
pixi-sbom-v1.6.0-rc.1-win-64.zip Windows x86_64

Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.

To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:

gh attestation verify pixi-sbom-v1.6.0-rc.1-linux-64.tar.gz --repo millsks/pixi-sbom \
  --signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
  --source-ref refs/tags/v1.6.0-rc.1 \
  --deny-self-hosted-runners

Add --bundle pixi-sbom-v1.6.0-rc.1-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.

Full changelog: CHANGELOG.md

Release v1.5.0

Choose a tag to compare

@millsks-release-helper millsks-release-helper released this 04 Oct 03:07

1.5.0 - 2026-10-04

Features

  • Retry a rate limit, and stop reporting an unasked index as no upstream (#304) (c3b352b)
  • Add --concurrency and a concurrency configuration key (#307) (c2bc82e)
  • Say in --doctor how many requests and which conda index (#308) (729812d)

Bug Fixes

  • Count the network a run used, not the network it could have used (#300) (991b517)
  • Keep the machine's own configuration out of the test suite (#303) (3bd9dfe)
  • Stop a mistyped concurrency from hanging the run and then panicking (#305) (a46c1bc)
  • Stop tying requests in flight to the core count (#306) (07eefcc)
  • Date a batch's newer releases in parallel, not one after another (#313) (4bdd2f2)
  • Count a batched fetch as a fetch, not as a cache hit (#314) (e8e7b75)
  • ci: Release the version that was asked for, even with no new commits (#315) (3134602)

Performance

  • Share one HTTP agent so connections are reused (#301) (c186101)
  • Ask prefix.dev about ten packages per request (#309) (d7fd067)

Release artifacts

Artifact Platform
pixi-sbom-v1.5.0-linux-64.tar.gz Linux x86_64
pixi-sbom-v1.5.0-linux-aarch64.tar.gz Linux arm64
pixi-sbom-v1.5.0-osx-64.tar.gz macOS Intel
pixi-sbom-v1.5.0-osx-arm64.tar.gz macOS Apple Silicon
pixi-sbom-v1.5.0-win-64.zip Windows x86_64

Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.

To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:

gh attestation verify pixi-sbom-v1.5.0-linux-64.tar.gz --repo millsks/pixi-sbom \
  --signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
  --source-ref refs/tags/v1.5.0 \
  --deny-self-hosted-runners

Add --bundle pixi-sbom-v1.5.0-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.

Full changelog: CHANGELOG.md

Release v1.5.0-rc.3

Release v1.5.0-rc.3 Pre-release
Pre-release

Choose a tag to compare

1.5.0-rc.3 - 2026-10-04

Bug Fixes

  • Count a batched fetch as a fetch, not as a cache hit (#314) (e8e7b75)

Release artifacts

Artifact Platform
pixi-sbom-v1.5.0-rc.3-linux-64.tar.gz Linux x86_64
pixi-sbom-v1.5.0-rc.3-linux-aarch64.tar.gz Linux arm64
pixi-sbom-v1.5.0-rc.3-osx-64.tar.gz macOS Intel
pixi-sbom-v1.5.0-rc.3-osx-arm64.tar.gz macOS Apple Silicon
pixi-sbom-v1.5.0-rc.3-win-64.zip Windows x86_64

Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.

To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:

gh attestation verify pixi-sbom-v1.5.0-rc.3-linux-64.tar.gz --repo millsks/pixi-sbom \
  --signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
  --source-ref refs/tags/v1.5.0-rc.3 \
  --deny-self-hosted-runners

Add --bundle pixi-sbom-v1.5.0-rc.3-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.

Full changelog: CHANGELOG.md

Release v1.5.0-rc.2

Release v1.5.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

1.5.0-rc.2 - 2026-10-04

Bug Fixes

  • Date a batch's newer releases in parallel, not one after another (#313) (4bdd2f2)

Release artifacts

Artifact Platform
pixi-sbom-v1.5.0-rc.2-linux-64.tar.gz Linux x86_64
pixi-sbom-v1.5.0-rc.2-linux-aarch64.tar.gz Linux arm64
pixi-sbom-v1.5.0-rc.2-osx-64.tar.gz macOS Intel
pixi-sbom-v1.5.0-rc.2-osx-arm64.tar.gz macOS Apple Silicon
pixi-sbom-v1.5.0-rc.2-win-64.zip Windows x86_64

Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.

To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:

gh attestation verify pixi-sbom-v1.5.0-rc.2-linux-64.tar.gz --repo millsks/pixi-sbom \
  --signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
  --source-ref refs/tags/v1.5.0-rc.2 \
  --deny-self-hosted-runners

Add --bundle pixi-sbom-v1.5.0-rc.2-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.

Full changelog: CHANGELOG.md

Release v1.5.0-rc.1

Release v1.5.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

1.5.0-rc.1 - 2026-10-03

Features

  • Retry a rate limit, and stop reporting an unasked index as no upstream (#304) (c3b352b)
  • Add --concurrency and a concurrency configuration key (#307) (c2bc82e)
  • Say in --doctor how many requests and which conda index (#308) (729812d)

Bug Fixes

  • Count the network a run used, not the network it could have used (#300) (991b517)
  • Keep the machine's own configuration out of the test suite (#303) (3bd9dfe)
  • Stop a mistyped concurrency from hanging the run and then panicking (#305) (a46c1bc)
  • Stop tying requests in flight to the core count (#306) (07eefcc)

Performance

  • Share one HTTP agent so connections are reused (#301) (c186101)
  • Ask prefix.dev about ten packages per request (#309) (d7fd067)

Release artifacts

Artifact Platform
pixi-sbom-v1.5.0-rc.1-linux-64.tar.gz Linux x86_64
pixi-sbom-v1.5.0-rc.1-linux-aarch64.tar.gz Linux arm64
pixi-sbom-v1.5.0-rc.1-osx-64.tar.gz macOS Intel
pixi-sbom-v1.5.0-rc.1-osx-arm64.tar.gz macOS Apple Silicon
pixi-sbom-v1.5.0-rc.1-win-64.zip Windows x86_64

Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.

To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:

gh attestation verify pixi-sbom-v1.5.0-rc.1-linux-64.tar.gz --repo millsks/pixi-sbom \
  --signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
  --source-ref refs/tags/v1.5.0-rc.1 \
  --deny-self-hosted-runners

Add --bundle pixi-sbom-v1.5.0-rc.1-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.

Full changelog: CHANGELOG.md

Release v1.4.0

Choose a tag to compare

@millsks-release-helper millsks-release-helper released this 03 Oct 17:58

1.4.0 - 2026-10-03

Features

  • Let the configuration file choose the conda index (#286) (d8171ec)
  • Read system and user configuration from pixi's directories (#289) (fa3dcd8)

Bug Fixes

  • Confirm a mirrored package's channel by its hash, not its name (#281) (82df2d1)
  • Match the installed build by its build string, not by scanning a page (#283) (e0c1f19)
  • Stop blaming credentials for an answer the probe asked for (#290) (f428509)

Performance

  • Resolve a mirrored channel once, not once per package (#282) (c05ed68)

Release artifacts

Artifact Platform
pixi-sbom-v1.4.0-linux-64.tar.gz Linux x86_64
pixi-sbom-v1.4.0-linux-aarch64.tar.gz Linux arm64
pixi-sbom-v1.4.0-osx-64.tar.gz macOS Intel
pixi-sbom-v1.4.0-osx-arm64.tar.gz macOS Apple Silicon
pixi-sbom-v1.4.0-win-64.zip Windows x86_64

Each archive has a .sha256 and a signed .sigstore.json provenance bundle beside it.

To check an archive was built by this repository's release workflow, from this tag, on a GitHub-hosted runner:

gh attestation verify pixi-sbom-v1.4.0-linux-64.tar.gz --repo millsks/pixi-sbom \
  --signer-workflow millsks/pixi-sbom/.github/workflows/release-artifacts.yml \
  --source-ref refs/tags/v1.4.0 \
  --deny-self-hosted-runners

Add --bundle pixi-sbom-v1.4.0-linux-64.tar.gz.sigstore.json to verify without reaching GitHub.

Full changelog: CHANGELOG.md