# package-url/purl-spec

A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby

Repository: https://github.com/package-url/purl-spec
Canonical: https://ross.abutalabs.com/products/purl-spec
Homepage: https://packageurl.org/
Language: Python
License: NOASSERTION
License Family: other
Topics: purl, package-url, package, url, cyclonedx, dependencies, package-management, sbom, spdx
Last push: 2026-09-02T19:13:35+00:00

## Health v2 (maintenance only)
Score: 87/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 100, release rhythm 64, longevity 100
- inputs: {"age_days": 3217, "days_push": 0, "days_rel": 30, "gap_med": 227, "n_releases_24m": 2}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1108, forks 241 (observed 2026-09-03T02:15:16.691663+00:00)

## What it is
The Package-URL (PURL) specification defines a standardized URL-based syntax for uniquely identifying software packages across any ecosystem or package manager. It is an Ecma standard (ECMA-427) widely used in SBOMs (CycloneDX, SPDX), vulnerability databases, and package repositories.

## Use cases
- standardize package identifiers across ecosystems
- generate purl identifiers for an SBOM
- reference packages in vulnerability databases
- identify dependencies unambiguously in supply chain security tooling
- implement purl parsing in a package manager tool
- define version ranges with VERS

## When to choose
- you need a uniform, ecosystem-agnostic way to identify software packages
- you are building SBOM, SCA, or vulnerability management tooling
- you want interoperability with CycloneDX, SPDX, OSV, and CVE record formats

## When to avoid
- you need a runnable library or CLI rather than a specification document
- you only work within a single ecosystem with its own native identifiers

## Facets
- artifact type: learning-resource
- maturity: stable
- function: developer-tools, documentation, package-manager, security
- domain: developer-tools, security, version-control, apis
- platform: cross-platform
- tags: purl, package-url, sbom, cyclonedx, spdx, specification, supply-chain-security, package-identification, ecma-427, vers

## Member repositories
- package-url/purl-spec (main) score 87

## Provenance
- Observed fields: from GitHub, fetched 2026-09-03T02:15:16.691663+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:45:34.042866+00:00, confidence not recorded.
  - readme: https://github.com/package-url/purl-spec (fetched 2026-09-03T02:15:16.691663+00:00, sha 654057c633c0)
  - homepage: https://packageurl.org/ (fetched 2026-08-29T12:48:41.824989+00:00, sha 02cf130ce6ab)
  - site_page: https://packageurl.org/docs/purl/specification-folder (fetched 2026-08-29T12:48:41.837026+00:00, sha 02cf130ce6ab)
  - site_page: https://packageurl.org/docs/purl/tests-folder (fetched 2026-08-29T12:48:41.838851+00:00, sha 02cf130ce6ab)
  - site_page: https://packageurl.org/docs/purl/purl-types (fetched 2026-08-29T12:48:41.840611+00:00, sha 02cf130ce6ab)
  - site_page: https://packageurl.org/docs/purl/schemas (fetched 2026-08-29T12:48:41.842367+00:00, sha 02cf130ce6ab)
  - site_page: https://packageurl.org/docs/purl/introduction (fetched 2026-08-29T12:48:41.834936+00:00, sha 02cf130ce6ab)
  - site_page: https://packageurl.org/docs/vers/introduction (fetched 2026-08-29T12:48:41.844152+00:00, sha 02cf130ce6ab)
  - site_page: https://packageurl.org/docs/vers/specification-folder (fetched 2026-08-29T12:48:41.845984+00:00, sha 02cf130ce6ab)
  - site_page: https://packageurl.org/docs/vers/tests-folder (fetched 2026-08-29T12:48:41.847723+00:00, sha 02cf130ce6ab)
- Data as of 2026-08-30T08:39:29.467469+00:00.
