aboutcode-org / aboutcode-org/purldb

PypiVersionAPI.get_latest_date() crashes when a release entry is missing upload_time_iso_8601

Open
#863 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
HTML
Stars
67
Forks
69
Avg merge
8d 8h
Merged PRs (30d)
1

Description

## Summary

`PypiVersionAPI.get_latest_date()` in `packagedb/package_managers.py` can fail when a PyPI release entry is missing `upload_time_iso_8601`.

The current implementation only assigns `current_date` when that field is present, but still uses `current_date` later in the loop even when it was never set. That can raise `UnboundLocalError` instead of skipping the malformed entry.

## Current behavior

A case like this can fail:

```python
downloads = [
{},
{"upload_time_iso_8601": "2010-12-23T05:14:23.509436Z"},
]

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.