?um/p1-90`PURL stands for Package-URL.
A PURL is a URL composed of seven components:
scheme:type/namespace/name@version?qualifiers#subpath
Components are separated by a specific character for unambiguous parsing.
| Component | Requirement | Description |
|---|---|---|
| scheme | Required | The URL scheme with the constant value of "pkg". One of the primary reasons for this single scheme is to facilitate the future official registration of the "pkg" scheme for Package-URLs. |
| type | Required | The package "type" or package "protocol" such as maven, npm, nuget, gem, pypi, etc. |
| namespace | Optional | A name prefix such as a Maven groupid, a Docker image owner, a GitHub user or organization. Namespace is type-specific. |
| name | Required | The name of the package. |
| version | Optional | The version of the package. |
| qualifiers | Optional | Qualifier data for a package such as OS, architecture, repository, etc. Qualifiers are type-specific. |
| subpath | Optional | Subpath within a package, relative to the package root. |
Components are designed such that they form a hierarchy from the most significant on the left to the least significant components on the right.
A PURL shall not contain a URL Authority, i.e. there is no support for username, password, host and port components. A namespace segment may sometimes look like a host, but its interpretation is specific to a type.
pkg:deb/debian/curl@7.50.3-1?arch=i386&distro=jessie
pkg:maven/org.apache.xmlgraphics/batik-anim@1.9.1?packaging=sources
pkg:npm/foobar@12.3.1
A PURL is a valid URL and
The PURL components are mapped to these URL components:
scheme: this is a URL scheme with a constant value: pkg.type, namespace, name and version components: these are collectively mapped to a URL path.qualifiers: this maps to a URL query.subpath: this is a URL fragment.In a PURL, there is no support for a URL Authority (e.g. no username, password, host and port components).
Special URL schemes as defined in file://, https://, http:// and ftp:// are not valid PURL types. They are valid URL or
Version control system (VCS) URLs such as git://, svn://, hg:// or as defined in Python pip or SPDX download locations are not valid PURL types. They are valid URL or
A PURL should be a locator based on three paths to specify or derive a URL:
type.qualifier for a PURL type.A valid PURL is composed of these permitted ASCII characters:
A to Z, a to z, 0 to 9;.-_~ (period '.', dash '-', underscore '_', and tilde '~');% (percent sign '%');:/@?=&# (colon ':', slash '/', at sign '@', question mark '?', equal sign '=', ampersand '&', and hash sign '#').This is how each of the separator characters is used:
scheme and type.type, namespace and name.subpath segments.name and version.qualifiers.key and a value of a qualifier.qualifiers (each being a key=value pair).subpath.In the
When percent-encoding is required by a component definition, the component string shall first be encoded as
In the component string, each "data octet" shall be replaced by the percent-encoded "character triplet" applying the percent-encoding mechanism defined in
The following characters shall not be
Where the space ' ' is permitted, it shall be
With the exception of the percent-encoding mechanism, the rules regarding percent-encoding are defined by this Standard alone.
References to "lowercase" in this Standard refer to the culture-invariant full case mapping defined in Section 3.13.2 of the
When applied to the ASCII character set, this operation converts uppercase Latin letters (A to Z) to their corresponding lowercase forms (a to z). All other ASCII characters remain unchanged.
A PURL string is an ASCII URL string composed of seven components. Except as expressly stated otherwise in this Clause, each component:
The "
scheme is a constant with the value "pkg".scheme shall be followed by an unencoded colon ':'.scheme and colon ':' are followed by one or more slash '/' characters, such as 'pkg://', and should ignore and remove all such '/' characters.type shall be composed only of ASCII letters and numbers, period '.', and dash '-'.type shall start with an ASCII letter.type shall not be type is case-insensitive. The form is namespace is optional, unless required by the package's type definition.namespace may contain one or more segments, separated by a single unencoded slash '/' character.namespace.namespace segment shall be a type definition further restricts the allowed characters.namespace. Use instead a repository_url qualifier. Note however, that for some types, the namespace may look like a host.name is prefixed by a single slash '/' separator when the namespace is not empty.name.name shall be a name may contain any type definition further restricts the allowed characters.version is prefixed by a '@' separator when not empty.version.version shall be a version may contain any type definition further restricts the allowed characters.version is a plain and opaque string.qualifiers component shall be prefixed by an unencoded question mark '?' separator when not empty. This '?' separator is not part of the qualifiers component.qualifiers component is composed of one or more key=value pairs. Multiple key=value pairs shall be separated by an unencoded ampersand '&'. This '&' separator is not part of an individual qualifier.key and value shall be separated by the unencoded equal sign '=' character. This '=' separator is not part of the key or value.value shall not be an empty string: a key=value pair with an empty value is the same as if no key=value pair exists for this key.key=value pair:
key shall be composed only of key shall start with an ASCII letter.key shall not be key shall be unique among all the keys of the qualifiers component.value may contain any subpath string is prefixed by a '#' separator when not empty.subpath.subpath may contain one or more segments, each separated by a single unencoded slash '/' character.subpath segment shall be a type definition further restricts the allowed characters.subpath shall be interpreted as relative to the root of the package.This Standard includes the Package-URL Type Definition Schema, but it does not include the set of current "registered" PURL type (JSON format) definition files because there are ongoing additions and changes to these files. The set of current "registered" PURL type definition files are located at: https://www.packageurl.org/purl-types/. Registration refers to the Package-URL community process for adding a new PURL type.
There are two rules related to the set of registered PURL type definitions for conforming PURL implementations to validate the PURL type component of a PURL:
type is registered, then the PURL is invalid if it does not conform to all of the rules from the corresponding PURL type definition.type is not registered, then the type component is valid if it conforms to the rules stated in the type is not registered.