Skip to content

feat: add PyPI package metadata collector - #3165

Closed
ChrisJr404 wants to merge 1 commit into
guacsec:mainfrom
ChrisJr404:collector-pypi
Closed

ChrisJr404 wants to merge 1 commit into
guacsec:mainfrom
ChrisJr404:collector-pypi

Conversation

@ChrisJr404

Copy link
Copy Markdown

Adds a PyPI collector so GUAC can pull package metadata from the PyPI JSON API and feed it into the supply-chain graph, closing the gap for pypi purls that the deps.dev collector only covers indirectly.

It reads pypi purls from a collect data source and fetches each package's metadata from https://pypi.org/pypi/<name>/json, emitting one processor.Document per package. I modeled it on the deps.dev collector: RetrieveArtifacts runs once or loops on an interval when poll is set, packages already fetched are deduped across poll cycles, and non-pypi sources are skipped with a warning. Bare package names work too, not just purls. A new DocumentPyPI document type tags the emitted docs.

Scope here is the collector only. The processor/parser side (registering a document parser + guesser for DocumentPyPI) is a natural follow-up and I'm happy to send that separately.

Tests spin up an httptest server standing in for the PyPI API and serve fixtures from testdata/, so they run without network. Cases cover a single purl, a bare name, dedupe of a repeated package, a non-pypi purl getting skipped, and a missing package emitting nothing. go build ./..., go vet, and go test ./pkg/handler/collector/pypi/... all pass.

Refs #208

Adds a collector that reads pypi purls from a collect data source and
fetches each package's metadata from the PyPI JSON API
(https://pypi.org/pypi/<name>/json), emitting one document per package.
Mirrors the deps.dev collector: supports a one-shot run or a poll loop,
dedupes packages already fetched, and skips non-pypi sources.

Introduces a DocumentPyPI document type for the emitted documents. The
processor/parser side is left as a follow-up; this change is the collector
only. Tested with an httptest server standing in for the PyPI API against
testdata, covering purl and bare-name inputs, dedupe, non-pypi skips, and
a missing package.

Refs guacsec#208

Signed-off-by: Chris (ChrisJr404) <11917633+ChrisJr404@users.noreply.github.com>
@gaganhr94

Copy link
Copy Markdown
Member

Hi @ChrisJr404, closing this PR since this is not a change planned in the project roadmap.

@gaganhr94 gaganhr94 closed this Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants