fix: add null pypi override for uv-audit

Renaming the entry from "uv audit" to "uv-audit" made the name PyPI-shaped: normalize() leaves spaces alone, so "uv audit" failed PYPI_NAME_RE and collect_names skipped it, but "uv-audit" passes, so the next sweep would have queried PyPI for it.

A uv-audit package does exist on PyPI, but it is version 0.1.9 by Alekse Marusich of rocshers, an unrelated third-party tool whose summary ("uv Tool for checking dependencies for vulnerabilities") is close enough to be mistaken for Astral's built-in uv audit subcommand. Without the override the entry would have shown that stranger's download count and lost its Bundled badge.

The sweep now writes uv-audit as NOT_FOUND, which load_downloads skips, so the badge is unaffected.

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
Vinta Chen
2026-08-23 01:30:53 +08:00
co-authored by Claude
parent e6fe7d165c
commit 8e7d2bc62c
+1
View File
@@ -36,6 +36,7 @@
"tkinter": { "package": null, "reason": "stdlib module" },
"tomllib": { "package": null, "reason": "stdlib module" },
"trailofbits-skills": { "package": null, "reason": "agent skills repo, not a package" },
"uv-audit": { "package": null, "reason": "part of uv (the `uv audit` subcommand); PyPI uv-audit is an unrelated third-party tool by rocshers" },
"warehouse": { "package": null, "reason": "the PyPI server itself; deployed, not pip-installed" },
"winpython": { "package": null, "reason": "distribution with its own installer; PyPI name is a 2012 relic" },
"zoneinfo": { "package": null, "reason": "stdlib module" }