Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "pitloom",
"version": "0.20.0",
"version": "0.20.1",
"description": "Generate, enrich, and validate SPDX 3 SBOMs/AIBOMs for Python projects and AI models using Pitloom.",
"author": {
"name": "Arthit Suriyawongkul",
Expand Down
12 changes: 7 additions & 5 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,9 +18,9 @@ and this project adheres to
[Semantic Versioning](https://semver.org/spec/v2.0.0.html).

- Full release notes: <https://github.com/bact/pitloom/releases>
- Commit history: <https://github.com/bact/pitloom/compare/v0.20.0...HEAD>
- Commit history: <https://github.com/bact/pitloom/compare/v0.20.1...HEAD>

## [Unreleased]
## [0.20.1] - 2026-10-07

### Changed

Expand All @@ -39,6 +39,10 @@ and this project adheres to
line, embed `WHEEL=` record on stderr; `embed-wheel -o -` no longer writes
a file named `-` ([#288])

[#287]: https://github.com/bact/pitloom/pull/287
[#288]: https://github.com/bact/pitloom/pull/288
[#289]: https://github.com/bact/pitloom/pull/289

## [0.20.0] - 2026-10-05

### Added
Expand Down Expand Up @@ -355,9 +359,6 @@ and this project adheres to
[#283]: https://github.com/bact/pitloom/pull/283
[#284]: https://github.com/bact/pitloom/pull/284
[#286]: https://github.com/bact/pitloom/pull/286
[#287]: https://github.com/bact/pitloom/pull/287
[#288]: https://github.com/bact/pitloom/pull/288
[#289]: https://github.com/bact/pitloom/pull/289

## [0.19.0] - 2026-09-18

Expand All @@ -376,5 +377,6 @@ and this project adheres to

---

[0.20.1]: https://github.com/bact/pitloom/compare/v0.20.0...v0.20.1
[0.20.0]: https://github.com/bact/pitloom/compare/v0.19.0...v0.20.0
[0.19.0]: https://github.com/bact/pitloom/compare/v0.18.1...v0.19.0
4 changes: 2 additions & 2 deletions CITATION.cff
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ abstract: Generate SPDX 3 SBOMs for Python projects and AI models, with native H
repository-code: "https://github.com/bact/pitloom"
type: software
doi: 10.5281/zenodo.19246283
version: 0.20.0
version: 0.20.1
license-url: "https://spdx.org/licenses/Apache-2.0"
keywords:
- sbom
Expand All @@ -27,4 +27,4 @@ keywords:
- safetensors
- ai sbom
- software supply chain security
date-released: 2026-10-05
date-released: 2026-10-07
10 changes: 5 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,7 +114,7 @@ wheel built ([PEP 770], compact canonical JSON). Needs Hatchling **1.29.0+**:

```toml
[build-system]
requires = ["hatchling>=1.29.0", "pitloom>=0.20.0"]
requires = ["hatchling>=1.29.0", "pitloom>=0.20.1"]
build-backend = "hatchling.build"

[tool.hatch.build.hooks.pitloom]
Expand Down Expand Up @@ -183,7 +183,7 @@ SBOM generation in CI, for any Python build backend:
- uses: actions/setup-python@v7
with:
python-version: "3.x"
- uses: bact/pitloom@v0.20.0
- uses: bact/pitloom@v0.20.1
```

Add `embed-wheel: "dist/*.whl"` to embed the SBOM into built wheels. See
Expand Down Expand Up @@ -280,18 +280,18 @@ gh attestation verify <file> -R bact/pitloom \

If you use this software, please cite it as follows:

> Suriyawongkul, A. (2026). Pitloom - SBOM generator for AI models and Python projects (Version 0.20.0) [Computer software]. <https://doi.org/10.5281/zenodo.19246283>
> Suriyawongkul, A. (2026). Pitloom - SBOM generator for AI models and Python projects (Version 0.20.1) [Computer software]. <https://doi.org/10.5281/zenodo.19246283>

BibTeX:

```bibtex
@software{Suriyawongkul_Pitloom_SBOM_2026,
author = {Suriyawongkul, Arthit},
doi = {10.5281/zenodo.19246283},
month = aug,
month = oct,
title = {{Pitloom - SBOM generator for AI models and Python projects}},
url = {https://github.com/bact/pitloom},
version = {0.20.0},
version = {0.20.1},
year = {2026}
}
```
Expand Down
2 changes: 1 addition & 1 deletion action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -195,7 +195,7 @@ inputs:
default: ""
pitloom-version:
description: >-
Pitloom version or version specifier to install, e.g. "0.20.0" or
Pitloom version or version specifier to install, e.g. "0.20.1" or
">=0.20,<1.0". Empty (default) installs the version of the ref this
action is pinned to; fails if that version is not on PyPI.
required: false
Expand Down
6 changes: 3 additions & 3 deletions codemeta.json
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,8 @@
"codeRepository": "https://github.com/bact/pitloom",
"copyrightYear": 2026,
"dateCreated": "2026-03-27",
"dateModified": "2026-10-05",
"datePublished": "2026-10-05",
"dateModified": "2026-10-07",
"datePublished": "2026-10-07",
"description": "Generate SPDX 3 SBOMs for Python projects and AI models, with native Hatchling build-hook support and GitHub Action integration.",
"developmentStatus": "active",
"downloadUrl": "https://github.com/bact/pitloom/releases",
Expand Down Expand Up @@ -60,5 +60,5 @@
"programmingLanguage": "Python 3",
"readme": "https://github.com/bact/pitloom/blob/main/README.md",
"url": "https://github.com/bact/pitloom",
"version": "0.20.0"
"version": "0.20.1"
}
2 changes: 1 addition & 1 deletion docs/agent-skills.md
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ Pitloom ships three Skills:

The three Skills refer to each other, so install all three together.

**Requirements.** A shell, Python 3.10 or later and `pitloom` 0.20.0 or
**Requirements.** A shell, Python 3.10 or later and `pitloom` 0.20.1 or
later (pip, `uvx` or `pipx`; earlier releases lack `--id-registry`,
`loom id` and `--build-timeout`, which the Skills use); network access to
install it and, for PyPI and Hugging Face lookups, at run time. AI model
Expand Down
22 changes: 11 additions & 11 deletions docs/github-action.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ Standalone SBOM artifact:
- uses: actions/setup-python@v7
with:
python-version: "3.x"
- uses: bact/pitloom@v0.20.0
- uses: bact/pitloom@v0.20.1
```

Set up Python first: the action uses the Python on `PATH`. See
Expand All @@ -32,7 +32,7 @@ Set up Python first: the action uses the Python on `PATH`. See
Generate and embed PEP 770 SBOM into built wheels:

```yaml
- uses: bact/pitloom@v0.20.0
- uses: bact/pitloom@v0.20.1
with:
embed-wheel: "dist/*.whl"
```
Expand All @@ -50,21 +50,21 @@ jobs:
- uses: actions/setup-python@v7
with:
python-version: "3.x"
- uses: bact/pitloom@v0.20.0
- uses: bact/pitloom@v0.20.1
```

Pin a release tag (`@v0.20.0`) or a full commit SHA (`@<sha> # v0.20.0`),
Pin a release tag (`@v0.20.1`) or a full commit SHA (`@<sha> # v0.20.1`),
not a branch. The pin also selects the Pitloom version: see
[What the pin covers](#what-the-pin-covers).

## What the pin covers

- **Pitloom version:** with `pitloom-version` empty, the action installs the
version carried by the pinned ref (tag or SHA) from PyPI. `@v0.20.0` and that
tag's commit SHA both give 0.20.0. It fails if the version is not on PyPI: an
version carried by the pinned ref (tag or SHA) from PyPI. `@v0.20.1` and that
tag's commit SHA both give 0.20.1. It fails if the version is not on PyPI: an
unreleased commit, a branch between a version bump and its release, or a tag
pushed before the upload finishes.
- **`pitloom-version`** overrides it: a version (`0.20.0`) or a specifier
- **`pitloom-version`** overrides it: a version (`0.20.1`) or a specifier
(`>=0.20,<1.0`).
- Pitloom's own dependencies are resolved by pip at run time, not pinned.

Expand All @@ -90,7 +90,7 @@ logic `loom project` uses directly). Point it at an AI model instead of a
project directory with `model:`:

```yaml
- uses: bact/pitloom@v0.20.0
- uses: bact/pitloom@v0.20.1
with:
model: path/to/model.safetensors
```
Expand All @@ -109,7 +109,7 @@ Pass extra raw CLI flags through with `args:` (shell-quoted, e.g. for
[creator/creation metadata](creation-metadata.md)):

```yaml
- uses: bact/pitloom@v0.20.0
- uses: bact/pitloom@v0.20.1
with:
args: '--creator-name "CI Bot" --creator-type software-agent'
```
Expand Down Expand Up @@ -166,7 +166,7 @@ Inputs (all optional):
| `no-build-isolation` | `false` | With `allow-build: "true"`, skip creating an isolated build environment and use the runner's already-installed build backend instead. No effect without `allow-build`; explicitly set in model mode, it also logs `::warning::no-build-isolation has no effect in model mode (no project-directory file discovery there)`. |
| `build-timeout` | *(empty)* | Seconds or `h`/`m`/`s` duration, e.g. `900` or `1h30m`, capping how long an `allow-build` build may run before Pitloom kills it and falls back to static discovery. Passed verbatim to `loom --build-timeout`, which validates it -- no shell-side parsing. Empty uses Pitloom's own default of 20 minutes. No effect without `allow-build`; explicitly set in model mode, it also logs `::warning::build-timeout has no effect in model mode (no project-directory file discovery there)`. See [`--build-timeout`](allow-build.md#timing-out-a-build). |
| `args` | *(empty)* | Extra raw flags passed through to the `loom` command, e.g. `--verify --validate` when `embed-wheel` is set. |
| `pitloom-version` | *(empty)* | Pitloom version or specifier, e.g. `0.20.0` or `>=0.20,<1.0`. Empty installs the version of the pinned ref; see [What the pin covers](#what-the-pin-covers). |
| `pitloom-version` | *(empty)* | Pitloom version or specifier, e.g. `0.20.1` or `>=0.20,<1.0`. Empty installs the version of the pinned ref; see [What the pin covers](#what-the-pin-covers). |
| `python-version` | *(empty)* | Passed to `actions/setup-python`. Empty uses the Python on `PATH`, falling back to `3.x` with a warning; see [Python selection](#python-selection). |
| `install` | `true` | Set `false` to skip installing Python/Pitloom and assume `loom` is already on `PATH`. |
| `upload-artifact` | `true` | Upload the generated SBOM via `actions/upload-artifact`. |
Expand Down Expand Up @@ -199,7 +199,7 @@ jobs:

# 2. Generate and embed PEP 770 SBOM into built wheels
- name: Embed PEP 770 SBOM
uses: bact/pitloom@v0.20.0
uses: bact/pitloom@v0.20.1
with:
embed-wheel: "dist/*.whl"

Expand Down
2 changes: 1 addition & 1 deletion docs/hatchling-build-hook.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ only), as compact canonical JSON.

```toml
[build-system]
requires = ["hatchling>=1.29.0", "pitloom>=0.20.0"]
requires = ["hatchling>=1.29.0", "pitloom>=0.20.1"]
build-backend = "hatchling.build"

[tool.hatch.build.hooks.pitloom]
Expand Down
4 changes: 2 additions & 2 deletions docs/id-registry.md
Original file line number Diff line number Diff line change
Expand Up @@ -199,7 +199,7 @@ jobs:
with:
python-version: "3.x"
# Same release as the action below, which installs its own pinned version.
- run: pip install pitloom==0.20.0
- run: pip install pitloom==0.20.1

# Extras-free, stem-keyed -- the only path that keeps ai_AIPackage
# spdxIds stable regardless of whether "ai" extras are installed
Expand All @@ -210,7 +210,7 @@ jobs:
- name: Seed/refresh AI model registry entries
run: loom id generate --id-registry loom-id-registry.json

- uses: bact/pitloom@v0.20.0
- uses: bact/pitloom@v0.20.1
with:
project-path: .
# Required: nothing auto-discovers a registry -- declare it.
Expand Down
6 changes: 3 additions & 3 deletions docs/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -99,18 +99,18 @@ please read our [Security policy][security].

If you use Pitloom in your academic work, please cite it as follows:

> Suriyawongkul, A. (2026). Pitloom - SBOM generator for AI models and Python projects (Version 0.20.0) [Computer software]. <https://doi.org/10.5281/zenodo.19246283>
> Suriyawongkul, A. (2026). Pitloom - SBOM generator for AI models and Python projects (Version 0.20.1) [Computer software]. <https://doi.org/10.5281/zenodo.19246283>

BibTeX:

```bibtex
@software{Suriyawongkul_Pitloom_SBOM_2026,
author = {Suriyawongkul, Arthit},
doi = {10.5281/zenodo.19246283},
month = aug,
month = oct,
title = {{Pitloom - SBOM generator for AI models and Python projects}},
url = {https://github.com/bact/pitloom},
version = {0.20.0},
version = {0.20.1},
year = {2026}
}
```
2 changes: 1 addition & 1 deletion scripts/action/pitloom-install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
# Installs Pitloom for action.yml's "Install Pitloom" step.
#
# Env: PL_EXTRAS comma-separated pip extras (may be empty)
# PL_VERSION pitloom-version input: a bare version ("0.20.0"), a
# PL_VERSION pitloom-version input: a bare version ("0.20.1"), a
# specifier (">=0.20,<1.0"), or empty to install the version
# carried by this pinned action checkout.
#
Expand Down
16 changes: 8 additions & 8 deletions skills/sbom-enrich/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ description: >-
2026 minimum elements"), sbom-generate triggers and hands off here.
license: Apache-2.0
compatibility: >-
Requires a shell, Python 3.10+ and pitloom >= 0.20.0 (pip, uvx or pipx);
Requires a shell, Python 3.10+ and pitloom >= 0.20.1 (pip, uvx or pipx);
a local AI model file needs pitloom[ai] and the post-merge check needs
pitloom[validate]. Needs an existing Pitloom SBOM (sbom-generate) and file
write access to the project. Needs network access to install pitloom;
Expand Down Expand Up @@ -71,11 +71,11 @@ See `references/examples.md` for a full worked example.

## Requirements

Python >= 3.10 and **pitloom >= 0.20.0** (earlier releases lack
Python >= 3.10 and **pitloom >= 0.20.1** (earlier releases lack
`--id-registry`, `loom id` and `--build-timeout`), the `loom`/`pitloom`
entry point: `pip install "pitloom>=0.20.0"`; an AI model file needs
`pip install "pitloom[ai]>=0.20.0"`; the mandatory post-merge check needs
`pip install "pitloom[validate]>=0.20.0"`. Ephemeral runs and the pin
entry point: `pip install "pitloom>=0.20.1"`; an AI model file needs
`pip install "pitloom[ai]>=0.20.1"`; the mandatory post-merge check needs
`pip install "pitloom[validate]>=0.20.1"`. Ephemeral runs and the pin
spelling: `sbom-generate`'s "Run without installing anything persistent".

Snippets are POSIX shell. On Windows use `python` or `py` for `python3`,
Expand Down Expand Up @@ -292,8 +292,8 @@ Steps:
```

With no persistent install, replace `python3` by `uvx --from
"pitloom>=0.20.0" python` (or, with pipx, `pipx run --spec
"pitloom>=0.20.0" python`; its "already on your PATH" notice is
"pitloom>=0.20.1" python` (or, with pipx, `pipx run --spec
"pitloom>=0.20.1" python`; its "already on your PATH" notice is
harmless). With `pipx install`, use the venv's
interpreter (`$(pipx environment --value PIPX_LOCAL_VENVS)/pitloom/bin/python`;
`Scripts\python.exe` on Windows); on Windows otherwise use `py` or
Expand Down Expand Up @@ -328,7 +328,7 @@ Steps:
`<merged-sbom-file>` -- a syntactically valid fragment can still miss
a required property or use the wrong relationship type, which only
shape/SHACL validation catches. Minimal fallback: `pip install
"pitloom[validate]>=0.20.0"` then `loom fragment validate
"pitloom[validate]>=0.20.1"` then `loom fragment validate
<merged-sbom-file>`.
11. Tell the user what was found deterministically (step 2), what was
inferred from prose (step 6), and what the SBOM author supplied
Expand Down
4 changes: 2 additions & 2 deletions skills/sbom-enrich/references/examples.md
Original file line number Diff line number Diff line change
Expand Up @@ -193,7 +193,7 @@ Read both fragments -- `model.enrich.spdx3.json` from step 1 and
`fragments/agent-enrichment.spdx3.json` from step 2 -- with the SPDX 3
JSON-LD deserialiser `merge_fragments()` itself uses, as `../SKILL.md`'s
step 7 describes: run its one-line snippet (with the interpreter Pitloom
is installed in; `uvx --from "pitloom>=0.20.0" python` for a `uvx` run) on
is installed in; `uvx --from "pitloom>=0.20.1" python` for a `uvx` run) on
those two files. Exit 0 is a pass.

Do not run `loom fragment validate` on a fragment: it names the base
Expand Down Expand Up @@ -235,7 +235,7 @@ CreationInfo, the agent-inferred one via its `comment`).
Use the `sbom-validate` skill on `sbom.spdx3.json` -- this catches
SPDX-shape/SHACL problems (e.g. a missing required property or the wrong
relationship type) that plain JSON-syntax validity would miss. Minimal fallback:
`pip install "pitloom[validate]>=0.20.0"` then
`pip install "pitloom[validate]>=0.20.1"` then
`loom fragment validate sbom.spdx3.json`.

## 7. Report back to the user
Expand Down
2 changes: 1 addition & 1 deletion skills/sbom-enrich/references/minimum-elements.md
Original file line number Diff line number Diff line change
Expand Up @@ -196,5 +196,5 @@ run themselves -- it is not wired into this skill, and its absence shouldn't
block anything here. The mandatory validation step remains the `sbom-validate`
skill
(<https://github.com/bact/pitloom/blob/main/skills/sbom-validate/SKILL.md>;
minimal fallback: `pip install "pitloom[validate]>=0.20.0"` then
minimal fallback: `pip install "pitloom[validate]>=0.20.1"` then
`loom fragment validate <file>`).
14 changes: 7 additions & 7 deletions skills/sbom-generate/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ description: >-
one is sbom-enrich.
license: Apache-2.0
compatibility: >-
Requires a shell, Python 3.10+ and pitloom >= 0.20.0 (pip, uvx or pipx).
Requires a shell, Python 3.10+ and pitloom >= 0.20.1 (pip, uvx or pipx).
AI model targets need pitloom[ai] (or a format extra such as
pitloom[gguf]); --allow-build needs pitloom[build]; --content-type needs
pitloom[content-type]. Needs network access to install pitloom and for
Expand Down Expand Up @@ -68,11 +68,11 @@ See `references/examples.md` for copy-paste recipes.

## Requirements

- Python >= 3.10 and **pitloom >= 0.20.0** (earlier releases lack
- Python >= 3.10 and **pitloom >= 0.20.1** (earlier releases lack
`--id-registry`, `loom id` and `--build-timeout`), the `loom`/`pitloom`
entry point -- `pip install "pitloom>=0.20.0"`, or run ephemeral via
entry point -- `pip install "pitloom>=0.20.1"`, or run ephemeral via
`uvx`/`pipx`. Extras take the floor after the extra:
`"pitloom[ai]>=0.20.0"`.
`"pitloom[ai]>=0.20.1"`.
- AI model targets, and any project or wheel that ships model files,
need the `ai` extra (`pitloom[ai]`) or a
format-specific one (`pitloom[huggingface_hub]`, `pitloom[gguf]`,
Expand All @@ -89,19 +89,19 @@ and PowerShell equivalents (PowerShell 5.1 has no `&&`: run the commands
one per line):

```bash
uvx --from "pitloom>=0.20.0" loom generate <target> -o sbom.spdx3.json
uvx --from "pitloom>=0.20.1" loom generate <target> -o sbom.spdx3.json
```

or

```bash
pipx run --spec "pitloom>=0.20.0" loom generate <target> -o sbom.spdx3.json
pipx run --spec "pitloom>=0.20.1" loom generate <target> -o sbom.spdx3.json
```

Fall back to a normal install only if neither `uv` nor `pipx` is available:

```bash
pip install "pitloom>=0.20.0"
pip install "pitloom>=0.20.1"
loom generate <target> -o sbom.spdx3.json
```

Expand Down
Loading
Loading