aboutcode-org / aboutcode-org/purldb

PypiVersionAPI.get_latest_date() crashes when a PyPI release entry is missing upload_time_iso_8601

オープン
#854 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
HTML
スター
67
フォーク
69
平均マージ
8日 8時間
マージ済み PR(30日)
1

説明

While reviewing packagedb/package_managers.py, I noticed a bug in PypiVersionAPI.get_latest_date().

The function currently assumes that every download entry in a PyPI release contains upload_time_iso_8601. If one of the entries is missing that field, current_date is never assigned, but it is still used later in the loop. That can raise an UnboundLocalError instead of simply skipping the invalid entry.

Current code:

latest_date = None
for download in downloads:
upload_time = download.get("upload_time_iso_8601")
if upload_time:
current_date = dateparser.parse(upload_time)
if not latest_date:
latest_date = current_date
else:
if current_date > latest_date:
latest_date = current_date
return latest_date
A minimal example that can trigger this is:

downloads = [
{},
{"upload_time_iso_8601": "2010-12-23T05:14:23.509436Z"},
]
In this case, the function should ignore the first item and return the parsed date from the second one, but it can fail on the first item because current_date is undefined.

Expected behavior:

skip entries that do not have upload_time_iso_8601
continue processing the remaining valid entries
return the latest valid date
return None if none of the entries contain a usable timestamp
A simple fix would be to initialize current_date = None inside the loop and continue when upload_time_iso_8601 is missing.

Reference:
[PyPI JSON API documentation](https://docs.pypi.org/api/json/)

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。