You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 08c71ff
Browse filesBrowse the repository at this point in the historyBrowse files
Fix lock-only PEP 440 pin spellings missing patches (#604) (#1334)
* Start v5 blocker fix (pypi-pep440-lockonly)
Empty commit to open the draft PR.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Find lock-only patches for PEP 440 pin spellings
On a fresh checkout (no venv), requirements.txt discovery sent a pin
as written: `six==1.16` became `pkg:pypi/six@1.16`, `==1.16.0.0`
became `@1.16.0.0`, `==01.16.0` became `@01.16.0`. pip installs the
registry release 1.16.0 for all three, but the patch API keys it
`@1.16.0`, so the scan said "No patches available" and the unpatched
release was installed. The same file with a venv holding six was
patched.
Scan now also asks the API for the other PEP 440 spellings of a
lockfile-only PyPI pure-release pin (leading zeros dropped, release
padded or trimmed to at least three segments). A patch returned under
another spelling is counted as that lockfile-only package, so
`notInstalled` and the vendored baseline pre-check see it. The
rewriters already match `==` pins under PEP 440 (#478).
Fixes#604
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
0 commit comments