package-url/purl-spec resource
A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby observed · 2026-09-03
Health v2 · maintenance only
87/100
- Activity 100
- Release rhythm 64
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 227
- age_days: 3217
- days_rel: 30
- days_push: 0
- n_releases_24m: 2
Adoption not part of the score
1108 stars · 241 forks observed · 2026-09-03
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
The Package-URL (PURL) specification defines a standardized URL-based syntax for uniquely identifying software packages across any ecosystem or package manager. It is an Ecma standard (ECMA-427) widely used in SBOMs (CycloneDX, SPDX), vulnerability databases, and package repositories.
Use cases
- standardize package identifiers across ecosystems
- generate purl identifiers for an SBOM
- reference packages in vulnerability databases
- identify dependencies unambiguously in supply chain security tooling
- implement purl parsing in a package manager tool
- define version ranges with VERS
When to choose
- you need a uniform, ecosystem-agnostic way to identify software packages
- you are building SBOM, SCA, or vulnerability management tooling
- you want interoperability with CycloneDX, SPDX, OSV, and CVE record formats
When to avoid
- you need a runnable library or CLI rather than a specification document
- you only work within a single ecosystem with its own native identifiers
Facets
learning-resource · maturity stable
developer-tools documentation package-manager security developer-tools security version-control apis cross-platform purl package-url sbom cyclonedx spdx specification supply-chain-security package-identification ecma-427 vers
10 sources
- readme: https://github.com/package-url/purl-spec · fetched 2026-09-03 · 654057c633c0
- homepage: https://packageurl.org/ · fetched 2026-08-29 · 02cf130ce6ab
- site_page: https://packageurl.org/docs/purl/specification-folder · fetched 2026-08-29 · 02cf130ce6ab
- site_page: https://packageurl.org/docs/purl/tests-folder · fetched 2026-08-29 · 02cf130ce6ab
- site_page: https://packageurl.org/docs/purl/purl-types · fetched 2026-08-29 · 02cf130ce6ab
- site_page: https://packageurl.org/docs/purl/schemas · fetched 2026-08-29 · 02cf130ce6ab
- site_page: https://packageurl.org/docs/purl/introduction · fetched 2026-08-29 · 02cf130ce6ab
- site_page: https://packageurl.org/docs/vers/introduction · fetched 2026-08-29 · 02cf130ce6ab
- site_page: https://packageurl.org/docs/vers/specification-folder · fetched 2026-08-29 · 02cf130ce6ab
- site_page: https://packageurl.org/docs/vers/tests-folder · fetched 2026-08-29 · 02cf130ce6ab
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| package-url/purl-spec | main | 87 |
For agents
markdown · JSON · MCP: product_card(name="package-url/purl-spec")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem