A wheel is a ZIP-based distribution artifact whose metadata describes its project, version, compatibility tags and installed-file records.
Python wheel metadata: inspect an owned built artifact before installation
Operation contract
The fixture builds one owned pure-Python wheel offline with a fixed project/version, then reads its single dist-info METADATA and WHEEL files without installing or importing its application package. Name and Version identify the distribution; the compatibility tag describes the built artifact. The printout confirms these recorded fields, but it is not a signature or a claim that every declared requirement can be resolved on another machine.
Failure and ownership boundary
This inspector reads only the artifact it just built. A received archive needs Python ZIP extraction: validate names and decompressed budgets before owned writes before inspection. A tag saying py3-none-any does not prove that the source avoids newer syntax or unavailable dependencies. Python wheel installation: test the built artifact outside its source directory, Python compatibility checks: parse syntax and execute contracts as separate evidence and Python pyproject.toml: build a wheel and inspect its metadata must agree with the claimed support range.
Tested environment
Dependency check: this program was executed on CPython 3.14.6 with build==1.6.1, setuptools==84.0.0. Install these versions in a separate virtual environment. The download includes the recorded environment snapshot; no third-party package is part of the website runtime.
Working program
import email.parser
from pathlib import Path
import subprocess
import sys
import tempfile
import zipfile
with tempfile.TemporaryDirectory() as directory:
project = Path(directory)
(project / "pyproject.toml").write_text('[build-system]\nrequires=["setuptools==84.0.0"]\nbuild-backend="setuptools.build_meta"\n[project]\nname="aitrove-owned-receipt"\nversion="0.1.0"\nrequires-python=">=3.11"\n[tool.setuptools]\npy-modules=["receipt_value"]\n')
(project / "receipt_value.py").write_text('AMOUNT = 125\n')
subprocess.run([sys.executable, "-I", "-m", "build", "--wheel", "--no-isolation", str(project)], check=True, capture_output=True, timeout=20)
artifact, = (project / "dist").glob("*.whl")
with zipfile.ZipFile(artifact) as archive:
metadata_name, = [name for name in archive.namelist() if name.endswith(".dist-info/METADATA")]
wheel_name, = [name for name in archive.namelist() if name.endswith(".dist-info/WHEEL")]
metadata = email.parser.Parser().parsestr(archive.read(metadata_name).decode("utf-8"))
wheel = email.parser.Parser().parsestr(archive.read(wheel_name).decode("utf-8"))
print("name:", metadata["Name"])
print("version:", metadata["Version"])
print("python:", metadata["Requires-Python"])
print("tag:", wheel["Tag"])Output
name: aitrove-owned-receipt
version: 0.1.0
python: >=3.11
tag: py3-none-anyCosts and limits
Build work depends on the backend and project size. Metadata parsing requires decoded file storage. The owned fixture has fixed small inputs; these costs are not an untrusted-wheel budget or a dependency supply-chain audit.
Common Mistakes
- Compatibility metadata is a declared support claim that still needs execution tests.
- Reading wheel metadata is different from installing or trusting its code.
Connected lessons
Python pyproject.toml: build a wheel and inspect its metadata, Python wheel installation: test the built artifact outside its source directory, Python editable installation: source changes and metadata changes have different lifetimes.
Follow the ownership and update boundary
Python artifact hashes: verify owned bytes against a separately trusted expectation.
Check this related boundary
Python wheel RECORD: verify member bytes before trusting a local archive.
