aboutcode-org / aboutcode-org/scancode-toolkit

PoetryLockHandler incorrectly marks non-optional packages as optional

Đang mở
#5,294 0 bình luận 1 reaction 0 người được giao Xem trên GitHub
bug
Ngôn ngữ chính
Python
Star
2.6k
Fork
791
Merge trung bình
1 ngày 12 giờ
Pull request đã merge (30 ngày)
5

Mô tả

### Description

`PoetryLockHandler` incorrectly reports resolved Poetry lockfile packages as optional even when the package has `optional = false` in `poetry.lock`.

For example, the existing ScanCode Poetry fixture contains:

[[package]]
name = "attrs"
version = "21.4.0"
optional = false

However, ScanCode reports the corresponding resolved dependency with:

"is_optional": true

The issue appears to come from the `PoetryLockHandler` implementation in `src/packagedcode/pypi.py`, which currently uses:

is_optional = package.get("is_optional") or True

Poetry uses the `optional` field in the lockfile, not `is_optional`. Additionally, using `or True` causes an explicit `False` value to become `True`.

The expected behavior is for a Poetry lockfile entry with `optional = false` to result in `is_optional = false`, while `optional = true` should result in `is_optional = true`.

### How To Reproduce

The issue can be reproduced using the existing Poetry lockfile fixture:

tests/packagedcode/data/pypi/poetry/univers/poetry.lock

The fixture contains packages with:

optional = false

Run the existing Poetry lock parsing test:

.\venv\Scripts\pytest.exe tests\packagedcode\test_pypi.py::TestPoetryHandler::test_parse_poetry_lock_univers -q

Before the fix, the test fails because the parsed result reports the resolved packages as optional, while the Poetry lockfile specifies `optional = false`.

The behavior can also be reproduced with a minimal Poetry lockfile containing both `optional = false` and `optional = true`. The current implementation incorrectly reports the package with `optional = false` as optional.

### System configuration

* What OS are you running on? Windows
* What version of scancode-toolkit was used to generate the scan file? `commoncode-v32.5.2-14-g441f36f725`
* What installation method was used to install/run scancode? Source checkout with the project's virtual environment
* Python version: 3.14.0

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.