Ross ROSS = Recommend OSS · open-source software intelligence for agents

package-url/purl-spec resource

A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby observed · 2026-09-03

github.com/package-url/purl-spec · homepage · Python · NOASSERTION (other) observed · 2026-09-03

Health v2 · maintenance only

87/100

  • Activity 100
  • Release rhythm 64
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 227
  • age_days: 3217
  • days_rel: 30
  • days_push: 0
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

1108 stars · 241 forks observed · 2026-09-03

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

The Package-URL (PURL) specification defines a standardized URL-based syntax for uniquely identifying software packages across any ecosystem or package manager. It is an Ecma standard (ECMA-427) widely used in SBOMs (CycloneDX, SPDX), vulnerability databases, and package repositories.

Use cases

  • standardize package identifiers across ecosystems
  • generate purl identifiers for an SBOM
  • reference packages in vulnerability databases
  • identify dependencies unambiguously in supply chain security tooling
  • implement purl parsing in a package manager tool
  • define version ranges with VERS

When to choose

  • you need a uniform, ecosystem-agnostic way to identify software packages
  • you are building SBOM, SCA, or vulnerability management tooling
  • you want interoperability with CycloneDX, SPDX, OSV, and CVE record formats

When to avoid

  • you need a runnable library or CLI rather than a specification document
  • you only work within a single ecosystem with its own native identifiers

Facets

learning-resource · maturity stable

developer-tools documentation package-manager security developer-tools security version-control apis cross-platform purl package-url sbom cyclonedx spdx specification supply-chain-security package-identification ecma-427 vers

10 sources

Member repositories

RepositoryRoleHealth v2
package-url/purl-specmain87

For agents

markdown · JSON · MCP: product_card(name="package-url/purl-spec")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem