sbom4python
sbom4python copied to clipboard
Consider using builtin importlib.metadata
Using pip show to collect package metadata only returns a select few metadata of a package.
Using importlib.metadata would allow accessing to all of them, such as Download-URL, Project-URL, and Maintainer. See https://packaging.python.org/en/latest/specifications/core-metadata/.
This should make the code slightly faster and more reliable.
Thanks for the suggestion.