aboutcode-org / aboutcode-org/univers

Properly handle the pre-release versions in VersionRange

Aberta
#130 1 comentário 0 reações 0 responsáveis Ver no GitHub
3-next enhancement
Linguagem predominante
Python
Estrelas
50
Forks
29
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

The current univers `VersionRange` includes the pre-release versions. While this behavior is desirable when dealing with version ranges in a security advisory, it is not appropriate for the version range present in package manifests.

### Scenario:
Consider the following release versions for an npm package:
1.0.0, 1.2.0, 2.0.0-rc.1, 2.0.0, 2.1.0, and 3.0.0

#### Desired Behavior:

- When dealing with version ranges in a security advisory:
`2.0.0-rc.1` in `vers:npm/>=1.2.0|<2.0.0` => True

- When dealing with version ranges in manifest files:
`2.0.0-rc.1` in `vers:npm/>=1.2.0|<2.0.0` => False

Guia de contribuição

Nenhum guia de contribuição indexado para este repositório

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.