Repository navigation
Expand file tree
/
Copy pathNOTICE
More file actions
230 lines (204 loc) · 13.6 KB
/
Copy pathNOTICE
File metadata and controls
230 lines (204 loc) · 13.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
go-python-packaging
Copyright 2026 Posit Software, PBC
This product is licensed under the Apache License, Version 2.0, or the MIT
license, at your option. See LICENSE-APACHE and LICENSE-MIT.
The version/ package is derived from rstudio/go-pep440-version, itself a fork of
aquasecurity/go-pep440-version (https://github.com/aquasecurity/go-pep440-version),
Copyright (c) Aqua Security Software Ltd., licensed under the Apache License,
Version 2.0. The version/ package also directly adapts material from
pypa/packaging (https://github.com/pypa/packaging); see the version/-specific
paragraphs below (the letter-normalization tables, cmpkey, the
specifier-matching helpers, and the conformance test ports) for the exact
files, symbols, and pinned commit.
The distribution/ package is ported from rstudio/python-distribution-parser
(https://github.com/rstudio/python-distribution-parser), Copyright (c) 2024
Posit Software, PBC, originally MIT-licensed. That project in turn incorporates
material from two upstream projects, credited here because the credit was not
carried through either port:
- The Python `pkginfo` package, Copyright (c) 2009 Agendaless Consulting, Inc.
and Contributors, licensed under the MIT license. The METADATA header
tables and the header parsing and leading-whitespace handling in
distribution/internal/distributions/ derive from pkginfo's
pkginfo/distribution.py.
- pypa/twine (https://github.com/pypa/twine), Copyright (c) 2013 Donald
Stufft and individual contributors and Copyright (c) 2015 Ian Cordasco,
licensed under the Apache License, Version 2.0. The distribution-name
sanitization, the wheel filename pattern, the package-file metadata
dictionary, and the hash manager in distribution/ derive from twine.
Several packages below adapt material from pypa/packaging
(https://github.com/pypa/packaging), Copyright (c) Donald Stufft and individual
contributors. That project is dual-licensed: its LICENSE offers the terms of
EITHER the Apache License, Version 2.0, or the two-clause BSD license. Where a
paragraph below cites it as Apache-2.0, read that as shorthand for the dual
offer; material from it is taken under whichever arm applies.
The tags/ package adapts platform-compatibility-tag algorithms (manylinux and
musllinux glibc/musl floor tables, macOS format lists and version walks, the
CPython free-threaded and stable-ABI tiers, the non-CPython generic-ABI tier,
tag ordering) from pypa/packaging (https://github.com/pypa/packaging),
specifically packaging/tags.py's cpython_tags, generic_tags, compatible_tags,
sys_tags, mac_platforms and _mac_binary_formats, packaging/_manylinux.py's
platform_tags cross-major glibc walk and its _LAST_GLIBC_MINOR placeholder
value (pinned at commit 84a87ee42483d7352f9502d78a9553da8859aa7a, the release
26.2 tag's commit), and packaging/_musllinux.py; and from Astral's uv
(https://github.com/astral-sh/uv), specifically the uv-platform-tags crate,
dual-licensed under the Apache License, Version 2.0, or the MIT license.
The tags/ package's golden fixtures (tags/testdata/*.json) are the ordered tag
lists pypa/packaging 26.2 itself produces, generated by
tags/testdata/gen_goldens.py, which drives packaging.tags directly. They are
generated output rather than ported source, but the ordering they record is
pypa/packaging's.
The version/ package's frozen conformance fixtures
(version/testdata/*.ranked.gz) record the total order pypa/packaging 26.2
assigns to version strings, produced by sorting with packaging.version.Version
directly (the generation recipe is in the fixture test's doc comment). They
are generated output rather than ported source, but the ordering they record
is pypa/packaging's.
The tags/ package's embedded data/distro_baselines.json records the libc version
well-known Linux distribution releases ship. Those version numbers originate in
the distributions' own package repositories and were read through Repology's
project API (https://repology.org/api/v1/project/glibc and .../musl), which
aggregates them; see data/gen_distro_baselines.py for the derivation rules and
how to regenerate the file. Repology states no license for its aggregated data
(the Repology software itself is GPLv3+, which this module does not incorporate);
no Repology code or text is included here, only version numbers. Its API terms
of use are at https://repology.org/api.
The wheelname/ package adapts wheel-filename parsing from pypa/packaging
(https://github.com/pypa/packaging), specifically
packaging/utils.py's `parse_wheel_filename`, licensed under the Apache
License, Version 2.0; and from Astral's uv (https://github.com/astral-sh/uv),
specifically the uv-distribution-filename crate, dual-licensed under the
Apache License, Version 2.0, or the MIT license.
The extras/ package adapts PEP 685/503 name-canonicalization from
pypa/packaging (https://github.com/pypa/packaging), specifically
packaging/utils.py's `canonicalize_name`, licensed under the Apache
License, Version 2.0.
The internal/pep508 package's tokenizer adapts the lexer design of
pypa/packaging (https://github.com/pypa/packaging), specifically
packaging/_tokenizer.py's `Tokenizer`, `Token`, `ParserSyntaxError`, and
`DEFAULT_RULES`, licensed under the Apache License, Version 2.0.
The internal/pep508 package's marker-expression parser adapts the
recursive-descent grammar of pypa/packaging
(https://github.com/pypa/packaging), specifically packaging/_parser.py's
marker productions (`_parse_marker` and friends) and `process_env_var`,
licensed under the Apache License, Version 2.0.
The requirement/ package adapts the dependency-specifier grammar of
pypa/packaging (https://github.com/pypa/packaging), specifically
packaging/_parser.py's `_parse_requirement` and packaging/requirements.py's
`Requirement`, licensed under the Apache License, Version 2.0; and Astral
uv's (https://github.com/astral-sh/uv) `uv-pep508` crate. Unlike the rest of
uv's workspace, `uv-pep508` (and `uv-pep440`) override the workspace license
per-crate to the Apache License, Version 2.0, or the two-clause BSD license,
and ship their own License-Apache and License-BSD files; `uv-pep508`'s
License-BSD reads Copyright (c) 2023 konstin. `uv-pep508` began as konstin's
independent `pep508_rs` crate, later folded into uv, and pep508_rs's own test
suite already ported cases from pypa/packaging. Material from `uv-pep508` is
taken under whichever of its two arms applies.
The marker/ package's Environment platform mapping (os_name, sys_platform,
platform_system, platform_release, platform_version) adapts the
linux/macos/windows cases of Astral uv's platform-tag logic
(https://github.com/astral-sh/uv), specifically the uv-configuration crate's
`TargetTriple`, dual-licensed under the Apache License, Version 2.0, or the
MIT license.
The marker/ package's Evaluate adapts the marker-evaluation logic of
pypa/packaging (https://github.com/pypa/packaging), specifically
packaging/markers.py's `_eval_op` and its operator/specifier dispatch,
licensed under the Apache License, Version 2.0.
The reqtxt/ package adapts pip's requirements-file parsing behavior from
pip (https://github.com/pypa/pip), specifically
pip/_internal/req/req_file.py's `preprocess`/`join_lines` line-joining
pipeline, `break_args_options`, `COMMENT_RE`, `ENV_VAR_RE`, and
`_parse_and_recurse`'s include-following, licensed under the MIT license;
and from Astral's uv (https://github.com/astral-sh/uv), specifically its
uv-requirements crate, dual-licensed under the Apache License, Version
2.0, or the MIT license.
The license/ package is derived from rstudio/package-manager's PyPI license
derivation (getLicense/getLicenseTypes and the licenses package's PyPI path),
Copyright (c) Posit Software, PBC, contributed under the Apache License, Version
2.0, or the MIT license. The embedded data/pypi_licenses.json maps public PyPI
Trove classifiers to SPDX identifiers.
The requirement/ package's conformance tests port the dependency-specifier
cases of pypa/packaging (https://github.com/pypa/packaging), Copyright (c)
Donald Stufft and individual contributors, specifically
tests/test_requirements.py's test_basic_valid_requirement_parsing
cross-product parameters and the invalid-requirement cases of class
TestRequirementParsing, licensed under the Apache License, Version 2.0.
Translated from Python/pytest to Go table-driven tests; the parametrize
cross-product is expressed as a curated subset with equivalent coverage.
The version/ package's conformance tests port the PEP 440 version-specifier
cases of pypa/packaging (https://github.com/pypa/packaging), Copyright (c)
Donald Stufft and individual contributors, specifically
tests/test_specifiers.py's classes TestSpecifier and TestSpecifierSet, pinned
at commit 4eb0753dba8fcaaac8eb75463374e448f0931558 (pypa/packaging main,
2026-07-28, 128 commits after the 26.2 release). Both classes gained
unrelated tests and assertions after 26.2; the ported cross-product and
invalid-specifier tables themselves include a non-ASCII case added after
26.2, so 4eb0753 rather than the 26.2 release commit is the pin the ported
content actually matches. Licensed under the Apache License, Version 2.0.
Translated from Python/pytest to Go
table-driven tests, in version/specifier_conformance_test.go and
version/specifierset_conformance_test.go. Upstream tests resting on
implementation details with no counterpart here are not ported, and the reason
is recorded in each file's header: the interval subsystem behind is_subset /
is_superset / is_disjoint / is_unsatisfiable, pickling, __match_args__,
__hash__, the one-element specifier-version caches, construction laziness, and
the SpecifierSet.to_range equivalence class. Where a Go expectation differs
from upstream's literal assertion the divergence is annotated inline at its
table.
The version/ package's specifier-matching helpers (versionSplit, versionJoin,
isNotSuffix, numericPrefixLen, leftPad) and the pre-release, post-release and
local-version boundary rules in its comparison functions are ported from
pypa/packaging's packaging/specifiers.py, specifically _version_split,
_version_join, _is_not_suffix, _numeric_prefix_len, _left_pad,
_earliest_prerelease, _post_base, _public_version, and the bodies of
Specifier._compare_equal, _compare_compatible, _compare_less_than and
_compare_greater_than, licensed under the Apache License, Version 2.0.
The internal/proptest package's property tests are adapted from
pypa/packaging's Hypothesis property suite (https://github.com/pypa/packaging),
Copyright (c) Donald Stufft and individual contributors, specifically
tests/property/strategies.py's generators and the version-ordering,
version-normalization, version-release, and specifier-matching properties,
licensed under the Apache License, Version 2.0. Translated from
Python/Hypothesis to Go/pgregory.net/rapid; upstream properties that assert on
parsed-field structure have no counterpart here, since this module exports no
such accessors. The tests/property/test_ranges_*.py files are deliberately not
ported: no packaging.ranges counterpart exists in this module.
pgregory.net/rapid is licensed under the Mozilla Public License, Version 2.0.
It is a test-only dependency: internal/proptest contains only _test.go files,
so rapid does not appear in this module's non-test import graph and is not
built into any consumer that imports this library.
The marker/ package's conformance tests port the marker evaluation and parse
cases of pypa/packaging (https://github.com/pypa/packaging), Copyright (c)
Donald Stufft and individual contributors, specifically tests/test_markers.py's
classes TestOperatorEvaluation and TestMarker and its module-level and/or
evaluation tests, pinned at commit 4eb0753dba8fcaaac8eb75463374e448f0931558
(identical at release 26.3), licensed under the Apache License, Version 2.0.
Translated from Python/pytest to Go table-driven tests, in
marker/conformance_test.go. Upstream tests resting on implementation details
with no counterpart here are not ported, and the reason is recorded in the
file's header: TestNode, TestDefaultEnvironment (the live interpreter),
__str__/__repr__/__hash__/__eq__, the operator-overload tests, every
test_pickle_*, evaluate(context=...), and the set-valued "extras"/
"dependency_groups" marker variables (PEP 685/735), which this package's
grammar does not recognize at all. Where a Go expectation differs from
upstream's literal assertion the divergence is annotated inline at its table.
The extras/ package's conformance tests port the name-canonicalization cases
of pypa/packaging (https://github.com/pypa/packaging), Copyright (c) Donald
Stufft and individual contributors, specifically tests/test_utils.py's
test_canonicalize_name and the non-validating half of
test_canonicalize_name_invalid, pinned at commit
4eb0753dba8fcaaac8eb75463374e448f0931558, licensed under the Apache License,
Version 2.0. Translated from Python/pytest to Go table-driven tests, in
extras/conformance_test.go.
The internal/pep508 package's error-position conformance tests port input
strings and caret span offsets - not message text - from Astral uv's
uv-pep508 crate (https://github.com/astral-sh/uv), specifically
crates/uv-pep508/src/lib.rs's `mod tests` error_* cases, pinned at commit
01cb90c1a4f88af09906cb60de9766d2add4a062 (release 0.12.18). uv-pep508
overrides uv's workspace license to Apache-2.0 OR BSD-2-Clause (Copyright (c)
2023 konstin) and ships its own license files; this material is taken under
the Apache-2.0 arm. Translated from Rust/insta snapshots to Go table-driven
tests, in internal/pep508/error_position_test.go, asserting this package's own
byte offsets and message text throughout - never uv's prose, and never any
case behind uv's "non-pep508-extensions" cargo feature (unnamed
direct-reference requirements, which this module's grammar has no
counterpart for).