aboutcode-org / aboutcode-org/purldb

PypiVersionAPI.get_latest_date() crashes when a PyPI release entry is missing upload_time_iso_8601

Đang mở
#854 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
HTML
Star
67
Fork
69
Merge trung bình
8 ngày 8 giờ
Pull request đã merge (30 ngày)
1

Mô tả

While reviewing packagedb/package_managers.py, I noticed a bug in PypiVersionAPI.get_latest_date().

The function currently assumes that every download entry in a PyPI release contains upload_time_iso_8601. If one of the entries is missing that field, current_date is never assigned, but it is still used later in the loop. That can raise an UnboundLocalError instead of simply skipping the invalid entry.

Current code:

latest_date = None
for download in downloads:
upload_time = download.get("upload_time_iso_8601")
if upload_time:
current_date = dateparser.parse(upload_time)
if not latest_date:
latest_date = current_date
else:
if current_date > latest_date:
latest_date = current_date
return latest_date
A minimal example that can trigger this is:

downloads = [
{},
{"upload_time_iso_8601": "2010-12-23T05:14:23.509436Z"},
]
In this case, the function should ignore the first item and return the parsed date from the second one, but it can fail on the first item because current_date is undefined.

Expected behavior:

skip entries that do not have upload_time_iso_8601
continue processing the remaining valid entries
return the latest valid date
return None if none of the entries contain a usable timestamp
A simple fix would be to initialize current_date = None inside the loop and continue when upload_time_iso_8601 is missing.

Reference:
[PyPI JSON API documentation](https://docs.pypi.org/api/json/)

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.