Registry · Analysis & measurement · Measure platforms longitudinally

package-url/purl-spec

Live AHK-0018

Identity

Repository id
110339177

Also filed on the survey's other hub.

Description

Editorial draft The package-URL specification: canonical coordinates for software packages across ecosystems. Adopted by the campaign for dependency identity.

The campaign that admitted it

2026-08-03__platform-ecosystem-longitudinal-measurement · · run type (the campaign's own designation) high-recall-map This campaign is placed on both hubs of this survey

High-coverage, effort-bounded map as of 2026-08-03 (AWAITING_INDEPENDENT_QA, action ceiling reached before two low-yield passes): supports a platform-native append-only panel design contract, but forbids treating current API values as history, absence as deletion, inactivity as exit, or namespaces as people.

Claim wording is the campaign's own, including its shorthand — see the methodology glossary.

1 ledger row cites this repository.

The claim is the campaign's own record — its coverage and its judgments — quoted word for word. It is not this site's assessment of the repository.

Current metrics

Stars
1090
Forks
238
Watchers
34
Language
Python
License
License present, not classified
Archived
No
Created
Last push
Topics
cyclonedxdependenciespackagepackage-managementpackage-urlpurlsbomspdxurl
Snapshot
· retrieved UTC

Counts only. This site never publishes stargazer, watcher or contributor identities.

Weekly movement

First snapshot 2026-08-10 — weekly movement begins with the second.

Star history

Not yet backfilled. Source will read: an independently collected archive of the same platform's public events, plus our snapshots.

Trust marks

Snapshot
· retrieved UTC
Entries hash (sha256, first 12)
46fcea8cb0e2 — this hub's served data file — verifiable at /api/entries.json
Snapshot hash (sha256, first 12)
5029a1dd0e77 — raw capture, shared by both hubs (not yet published)
Method version
supervised beta (v3.3 taxonomy)
Sealed record
2026-08-03__platform-ecosystem-longitudinal-measurement — named, not linked; the record is not public.

What we collect

Collected per entry, weekly, append-only and hash-attested — the full field list is on the data card. Aggregate public metrics only; no stargazer or contributor identities. The posted record is public and quotable; the collection run itself is not published.