CycloneDX / CycloneDX/cyclonedx-python

feat: support poetry v2

Open
#839 16 comments 17 reactions 0 assignees View on GitHub
enhancement help wanted source: poetry
Dominant language
Python
Stars
390
Forks
98
Avg merge
2d 23h
Merged PRs (30d)
2

Description

`poetry` v2 just got released: https://github.com/python-poetry/poetry/releases/tag/2.0.0

Let's add support for it and it's new features, if any
- new lock file format?
- any new `pytproject.toml` declarations
- support for PEP621 - metadata and dependencies
Goal: not either/or, but simultaneously the "old" `tool.poetry` and the "new" `project`
> Add support for the `project` section in the `pyproject.toml` file according to PEP 621
-- https://github.com/python-poetry/poetry/pull/9135
-- https://github.com/python-poetry/poetry/pull/9917
- investigate what else is new ... TBC ...
- ... TBC ...
- tests
- since poetry v2 there is a new lock file format in town: `2.1`. this means we can keep current test structures and add a new folder for each lockfile thing where needed.
- some new cases may not be available for older poetry - like the PEP621 in all its variants... -

[⤴ this list will be updated continuously based on comments below, until the initial feature was provided eventually]

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the existing Poetry parsing and test structure, then compare the Poetry v2 release notes and the linked PEP 621 changes. Identify how pyproject.toml metadata and dependencies and the 2.1 lock file are currently handled. Done means Poetry v2 inputs are supported alongside existing tool.poetry cases, with new lock-file folders and tests for applicable PEP 621 variants.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.