JSON API
提示
本页面介绍了PyPI 特有的JSON API。如果您只需要一个 JSON 索引 API(例如用于检索软件包的所有发行版或所有版本),则可以使用索引 API。
路线
获取项目
路线:GET /pypi/<project>/json
返回单个项目最新版本的元数据(信息)、该项目的所有版本列表以及项目 URL。版本信息包括版本名称、URL 以及 MD5、SHA256 和 BLAKE2b-256 的哈希摘要,并以版本字符串作为键。返回的元数据来自上传时提供的值,不一定与上传文件的内容完全一致。系统仅存储版本首次上传的数据,后续上传不会更新这些数据。
每个文件对象还包含一个core-metadata键,用于描述
随发行版一起提供的核心元数据(参见PEP 658和
PEP 714)。当没有元数据文件可用时,该键的值为空;当有元数据文件可用时,该键false的值为哈希摘要对象(例如{"sha256": "..."})。这core-metadata与索引 API已公开的键相对应,使得镜像服务器无需额外请求即可发现并提供核心元数据。
此端点vulnerabilities提供的数组列出了最新版本中所有已知的漏洞(如上例所示,没有漏洞)。要精确控制此字段,请使用下文所述的特定于版本的端点。
已弃用的键
以下键已被视为已弃用:
releases项目应尽可能改用Index API来获取这些信息。downloads:此键始终-1不应使用。has_sig:此键始终false不应使用。bugtrack_url:此键始终null不应使用。
未来,这些键值可能会从 API 响应中完全移除。
状态码:
200 OK无错误
请求示例:
GET /pypi/sampleproject/json HTTP/1.1
Host: pypi.org
Accept: application/json
示例 JSON 响应
HTTP/1.1 200 OK
Content-Type: application/json; charset="UTF-8"
{
"info": {
"author": "",
"author_email": "\"A. Random Developer\" <author@example.com>",
"bugtrack_url": null,
"classifiers": [
"Development Status :: 3 - Alpha",
"Intended Audience :: Developers",
"License :: OSI Approved :: MIT License",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3 :: Only",
"Programming Language :: Python :: 3.10",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Programming Language :: Python :: 3.13",
"Programming Language :: Python :: 3.9",
"Topic :: Software Development :: Build Tools"
],
"description": "...",
"description_content_type": "text/markdown",
"docs_url": null,
"download_url": "",
"downloads": {
"last_day": -1,
"last_month": -1,
"last_week": -1
},
"dynamic": [
"requires_dist"
],
"home_page": "",
"keywords": "sample, setuptools, development",
"license": "...",
"license_expression": null,
"license_files": null,
"maintainer": "",
"maintainer_email": "\"A. Great Maintainer\" <maintainer@example.com>",
"name": "sampleproject",
"package_url": "https://pypi.org/project/sampleproject/",
"platform": null,
"project_url": "https://pypi.org/project/sampleproject/",
"project_urls": {
"Bug Reports": "https://github.com/pypa/sampleproject/issues",
"Funding": "https://donate.pypi.org",
"Homepage": "https://github.com/pypa/sampleproject",
"Say Thanks!": "http://saythanks.io/to/example",
"Source": "https://github.com/pypa/sampleproject/"
},
"provides_extra": [
"dev",
"test"
],
"release_url": "https://pypi.org/project/sampleproject/4.0.0/",
"requires_dist": [
"peppercorn",
"check-manifest ; extra == 'dev'",
"coverage ; extra == 'test'"
],
"requires_python": ">=3.9",
"summary": "A sample Python project",
"version": "4.0.0",
"yanked": false,
"yanked_reason": null
},
"last_serial": 25862117,
"releases": {
"1.0": [],
"1.2.0": [
{
"comment_text": "",
"core-metadata": false,
"digests": {
"blake2b_256": "3052547eb3719d0e872bdd6fe3ab60cef92596f95262e925e1943f68f840df88",
"md5": "bab8eb22e6710eddae3c6c7ac3453bd9",
"sha256": "7a7a8b91086deccc54cac8d631e33f6a0e232ce5775c6be3dc44f86c2154019d"
},
"downloads": -1,
"filename": "sampleproject-1.2.0-py2.py3-none-any.whl",
"has_sig": false,
"md5_digest": "bab8eb22e6710eddae3c6c7ac3453bd9",
"packagetype": "bdist_wheel",
"python_version": "2.7",
"requires_python": null,
"size": 3795,
"upload_time": "2015-06-14T14:38:05",
"upload_time_iso_8601": "2015-06-14T14:38:05.875222Z",
"url": "https://files.pythonhosted.org/packages/30/52/547eb3719d0e872bdd6fe3ab60cef92596f95262e925e1943f68f840df88/sampleproject-1.2.0-py2.py3-none-any.whl",
"yanked": false,
"yanked_reason": null
},
{
"comment_text": "",
"core-metadata": false,
"digests": {
"blake2b_256": "eb4579be82bdeafcecb9dca474cad4003e32ef8e4a0dec6abbd4145ccb02abe1",
"md5": "d3bd605f932b3fb6e91f49be2d6f9479",
"sha256": "3427a8a5dd0c1e176da48a44efb410875b3973bd9843403a0997e4187c408dc1"
},
"downloads": -1,
"filename": "sampleproject-1.2.0.tar.gz",
"has_sig": false,
"md5_digest": "d3bd605f932b3fb6e91f49be2d6f9479",
"packagetype": "sdist",
"python_version": "source",
"requires_python": null,
"size": 3148,
"upload_time": "2015-06-14T14:37:56",
"upload_time_iso_8601": "2015-06-14T14:37:56.383366Z",
"url": "https://files.pythonhosted.org/packages/eb/45/79be82bdeafcecb9dca474cad4003e32ef8e4a0dec6abbd4145ccb02abe1/sampleproject-1.2.0.tar.gz",
"yanked": false,
"yanked_reason": null
}
],
"1.3.0": [
"..."
],
"1.3.1": [
"..."
],
"2.0.0": [
"..."
],
"3.0.0": [
"..."
],
"4.0.0": [
{
"comment_text": "",
"core-metadata": {
"sha256": "a1d0c6e83f027327d8461063f4ac58a6e4a7a5d0a0e0d5b6c3b2e1f0a9b8c7d6"
},
"digests": {
"blake2b_256": "d773c16e5f3f0d37c60947e70865c255a58dc408780a6474de0523afd0ec553a",
"md5": "d3857a217dacbca9e40a85f06f2b34f1",
"sha256": "c23e447ea90d796d1e645c35c4b2de125040add12a845825546f91c93f391b6b"
},
"downloads": -1,
"filename": "sampleproject-4.0.0-py3-none-any.whl",
"has_sig": false,
"md5_digest": "d3857a217dacbca9e40a85f06f2b34f1",
"packagetype": "bdist_wheel",
"python_version": "py3",
"requires_python": ">=3.9",
"size": 4661,
"upload_time": "2024-11-06T22:37:09",
"upload_time_iso_8601": "2024-11-06T22:37:09.220617Z",
"url": "https://files.pythonhosted.org/packages/d7/73/c16e5f3f0d37c60947e70865c255a58dc408780a6474de0523afd0ec553a/sampleproject-4.0.0-py3-none-any.whl",
"yanked": false,
"yanked_reason": null
},
{
"comment_text": "",
"core-metadata": {
"sha256": "b2e1d7f94a138438e9572174a5bd69b7f5b8b6e1b1f1e6c7d4c3f2a1b0c9d8e7"
},
"digests": {
"blake2b_256": "488cc18d25735962870ccb6d1cd2ac7bde40008a332211055e260cb7ec4c6bab",
"md5": "9eab89661feaaf3b05b60fb1ed1f7171",
"sha256": "0ace7980f82c5815ede4cd7bf9f6693684cec2ae47b9b7ade9add533b8627c6b"
},
"downloads": -1,
"filename": "sampleproject-4.0.0.tar.gz",
"has_sig": false,
"md5_digest": "9eab89661feaaf3b05b60fb1ed1f7171",
"packagetype": "sdist",
"python_version": "source",
"requires_python": ">=3.9",
"size": 5760,
"upload_time": "2024-11-06T22:37:10",
"upload_time_iso_8601": "2024-11-06T22:37:10.868088Z",
"url": "https://files.pythonhosted.org/packages/48/8c/c18d25735962870ccb6d1cd2ac7bde40008a332211055e260cb7ec4c6bab/sampleproject-4.0.0.tar.gz",
"yanked": false,
"yanked_reason": null
}
]
},
"urls": [
{
"comment_text": "",
"core-metadata": {
"sha256": "a1d0c6e83f027327d8461063f4ac58a6e4a7a5d0a0e0d5b6c3b2e1f0a9b8c7d6"
},
"digests": {
"blake2b_256": "d773c16e5f3f0d37c60947e70865c255a58dc408780a6474de0523afd0ec553a",
"md5": "d3857a217dacbca9e40a85f06f2b34f1",
"sha256": "c23e447ea90d796d1e645c35c4b2de125040add12a845825546f91c93f391b6b"
},
"downloads": -1,
"filename": "sampleproject-4.0.0-py3-none-any.whl",
"has_sig": false,
"md5_digest": "d3857a217dacbca9e40a85f06f2b34f1",
"packagetype": "bdist_wheel",
"python_version": "py3",
"requires_python": ">=3.9",
"size": 4661,
"upload_time": "2024-11-06T22:37:09",
"upload_time_iso_8601": "2024-11-06T22:37:09.220617Z",
"url": "https://files.pythonhosted.org/packages/d7/73/c16e5f3f0d37c60947e70865c255a58dc408780a6474de0523afd0ec553a/sampleproject-4.0.0-py3-none-any.whl",
"yanked": false,
"yanked_reason": null
},
{
"comment_text": "",
"core-metadata": {
"sha256": "b2e1d7f94a138438e9572174a5bd69b7f5b8b6e1b1f1e6c7d4c3f2a1b0c9d8e7"
},
"digests": {
"blake2b_256": "488cc18d25735962870ccb6d1cd2ac7bde40008a332211055e260cb7ec4c6bab",
"md5": "9eab89661feaaf3b05b60fb1ed1f7171",
"sha256": "0ace7980f82c5815ede4cd7bf9f6693684cec2ae47b9b7ade9add533b8627c6b"
},
"downloads": -1,
"filename": "sampleproject-4.0.0.tar.gz",
"has_sig": false,
"md5_digest": "9eab89661feaaf3b05b60fb1ed1f7171",
"packagetype": "sdist",
"python_version": "source",
"requires_python": ">=3.9",
"size": 5760,
"upload_time": "2024-11-06T22:37:10",
"upload_time_iso_8601": "2024-11-06T22:37:10.868088Z",
"url": "https://files.pythonhosted.org/packages/48/8c/c18d25735962870ccb6d1cd2ac7bde40008a332211055e260cb7ec4c6bab/sampleproject-4.0.0.tar.gz",
"yanked": false,
"yanked_reason": null
}
],
"vulnerabilities": [],
"ownership": {
"roles": [
{"role": "Owner", "user": "theacodes"},
{"role": "Maintainer", "user": "pypa-bot"}
],
"organization": "pypa"
}
}
获得发布
路线:GET /pypi/<project>/<version>/json
返回有关特定版本中单个发行版的元数据,除此之外与 相同,只是/pypi/<project_name>/json缺少
releases键。
提示
之前的响应中包含密钥,其中包含该项目在 PyPI 上所有版本的所有releases文件的 URL 。出于稳定性考虑,我们不得不从版本特定页面中移除该密钥,现在该页面
仅提供与该版本相关的数据。
要访问所有文件,最好使用Index API,否则请使用项目级 JSON API /pypi/<project_name>/json。
已弃用的键
以下键已被视为已弃用:
downloads:此键始终-1不应使用。has_sig:此键始终false不应使用。bugtrack_url:此键始终null不应使用。
未来,这些键值可能会从 API 响应中完全移除。
状态码:
200 OK无错误
请求示例:
GET /pypi/sampleproject/4.0.0/json HTTP/1.1
Host: pypi.org
Accept: application/json
示例 JSON 响应
HTTP/1.1 200 OK
Content-Type: application/json; charset="UTF-8"
{
"info": {
"author": "",
"author_email": "\"A. Random Developer\" <author@example.com>",
"bugtrack_url": null,
"classifiers": [
"Development Status :: 3 - Alpha",
"Intended Audience :: Developers",
"License :: OSI Approved :: MIT License",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3 :: Only",
"Programming Language :: Python :: 3.10",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Programming Language :: Python :: 3.13",
"Programming Language :: Python :: 3.9",
"Topic :: Software Development :: Build Tools"
],
"description": "...",
"description_content_type": "text/markdown",
"docs_url": null,
"download_url": "",
"downloads": {
"last_day": -1,
"last_month": -1,
"last_week": -1
},
"dynamic": [
"requires_dist"
],
"home_page": "",
"keywords": "sample, setuptools, development",
"license": "... ",
"license_expression": null,
"license_files": null,
"maintainer": "",
"maintainer_email": "\"A. Great Maintainer\" <maintainer@example.com>",
"name": "sampleproject",
"package_url": "https://pypi.org/project/sampleproject/",
"platform": null,
"project_url": "https://pypi.org/project/sampleproject/",
"project_urls": {
"Bug Reports": "https://github.com/pypa/sampleproject/issues",
"Funding": "https://donate.pypi.org",
"Homepage": "https://github.com/pypa/sampleproject",
"Say Thanks!": "http://saythanks.io/to/example",
"Source": "https://github.com/pypa/sampleproject/"
},
"provides_extra": [
"dev",
"test"
],
"release_url": "https://pypi.org/project/sampleproject/4.0.0/",
"requires_dist": [
"peppercorn",
"check-manifest ; extra == 'dev'",
"coverage ; extra == 'test'"
],
"requires_python": ">=3.9",
"summary": "A sample Python project",
"version": "4.0.0",
"yanked": false,
"yanked_reason": null
},
"last_serial": 25862117,
"urls": [
{
"comment_text": "",
"core-metadata": {
"sha256": "a1d0c6e83f027327d8461063f4ac58a6e4a7a5d0a0e0d5b6c3b2e1f0a9b8c7d6"
},
"digests": {
"blake2b_256": "d773c16e5f3f0d37c60947e70865c255a58dc408780a6474de0523afd0ec553a",
"md5": "d3857a217dacbca9e40a85f06f2b34f1",
"sha256": "c23e447ea90d796d1e645c35c4b2de125040add12a845825546f91c93f391b6b"
},
"downloads": -1,
"filename": "sampleproject-4.0.0-py3-none-any.whl",
"has_sig": false,
"md5_digest": "d3857a217dacbca9e40a85f06f2b34f1",
"packagetype": "bdist_wheel",
"python_version": "py3",
"requires_python": ">=3.9",
"size": 4661,
"upload_time": "2024-11-06T22:37:09",
"upload_time_iso_8601": "2024-11-06T22:37:09.220617Z",
"url": "https://files.pythonhosted.org/packages/d7/73/c16e5f3f0d37c60947e70865c255a58dc408780a6474de0523afd0ec553a/sampleproject-4.0.0-py3-none-any.whl",
"yanked": false,
"yanked_reason": null
},
{
"comment_text": "",
"core-metadata": {
"sha256": "b2e1d7f94a138438e9572174a5bd69b7f5b8b6e1b1f1e6c7d4c3f2a1b0c9d8e7"
},
"digests": {
"blake2b_256": "488cc18d25735962870ccb6d1cd2ac7bde40008a332211055e260cb7ec4c6bab",
"md5": "9eab89661feaaf3b05b60fb1ed1f7171",
"sha256": "0ace7980f82c5815ede4cd7bf9f6693684cec2ae47b9b7ade9add533b8627c6b"
},
"downloads": -1,
"filename": "sampleproject-4.0.0.tar.gz",
"has_sig": false,
"md5_digest": "9eab89661feaaf3b05b60fb1ed1f7171",
"packagetype": "sdist",
"python_version": "source",
"requires_python": ">=3.9",
"size": 5760,
"upload_time": "2024-11-06T22:37:10",
"upload_time_iso_8601": "2024-11-06T22:37:10.868088Z",
"url": "https://files.pythonhosted.org/packages/48/8c/c18d25735962870ccb6d1cd2ac7bde40008a332211055e260cb7ec4c6bab/sampleproject-4.0.0.tar.gz",
"yanked": false,
"yanked_reason": null
}
],
"vulnerabilities": [],
"ownership": {
"roles": [
{"role": "Owner", "user": "theacodes"},
{"role": "Maintainer", "user": "pypa-bot"}
],
"organization": "pypa"
}
}
所有权
图例ownership提供有关项目角色和组织成员的信息。它包含两个字段:
roles{"role": "<role>", "user": "<username>"}:一个包含项目所有者和维护者对象的列表。角色列表Owner首先按优先级排序Maintainer,然后按每个角色内的用户名字母顺序排序。如果项目没有分配任何角色,则此列表为空。organization:拥有该项目的组织的 URL slug(例如"pypa"),或者null如果该项目不属于任何组织,则为 。
已知漏洞
在上面的示例中,所请求的项目和版本的组合没有已知的漏洞。
下面提供了一个针对已知存在漏洞的项目的响应示例,为了便于阅读,不相关的字段已折叠。
HTTP/1.1 200 OK
Content-Type: application/json; charset="UTF-8"
{
"info": {},
"last_serial": 12089094,
"releases": {},
"urls": [],
"vulnerabilities": [
{
"aliases": [
"CVE-2021-3281"
],
"details": "In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by \"startapp --template\" and \"startproject --template\") allows directory traversal via an archive with absolute paths or relative paths with dot segments.",
"summary": "A shorter summary of the vulnerability",
"fixed_in": [
"2.2.18",
"3.0.12",
"3.1.6"
],
"id": "PYSEC-2021-9",
"link": "https://osv.dev/vulnerability/PYSEC-2021-9",
"source": "osv",
"withdrawn": null
},
]
}
该withdrawn字段尤其值得关注:当其为非空值时null,它包含上游漏洞报告源撤回漏洞的 RFC 3339 时间戳。API 使用者可以使用此字段撤回后来被确定为无效的漏洞报告。
例如,以下是一个已撤回的漏洞示例:
{
"aliases": [
"CVE-2022-XXXXX"
],
"details": "A long description.",
"summary": "A shorter summary.",
"fixed_in": [
"1.2.3"
],
"id": "PYSEC-2022-XXX",
"link": "https://osv.dev/vulnerability/PYSEC-2022-XXX",
"source": "osv",
"withdrawn": "2022-06-28T16:39:06Z"
}