test: assert bundled entries have a null PyPI override

The uv-audit bug had no automated guard: pypi_name_overrides.json is
a manual registry, so a wrong-package mapping is only caught if
someone already suspects it.

Two broader checks were measured against the real list and rejected.
Checking that PyPI metadata links back to the entry's GitHub repo
would not have caught uv-audit, since that package declares no
home_page or project_urls, landing it in a 26-entry bucket of
packages that simply don't declare a repo (numba, selenium, pyglet,
etc.), plus 10 benign cases of orgs moving or splitting bindings.
Flagging display-name/repo-name mismatches yields 46 hits, all
legitimate python-X-repo-to-X-package pairs, with uv-build sitting
among them despite being a real Astral package with the identical
shape to uv-audit.

What discriminates is the bundled marker itself: a "(part of X)"
entry ships inside something else and has no package of its own, so
the sweep must never query it. This test walks the real README and
requires a null override for every bundled entry whose normalized
name is PyPI-shaped. Verified it fails with exactly the uv-audit
message when that override is removed, and passes with it restored,
across the three current bundled entries with no false positives. It
runs offline, fitting the existing network-less CI.

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
Vinta Chen
2026-08-23 01:46:13 +08:00
co-authored by Claude
parent 8e7d2bc62c
commit b7313dcffc
+21
View File
@@ -1,10 +1,12 @@
"""Tests for the readme_parser module."""
import re
import textwrap
from pathlib import Path
import pytest
from fetch_pypi_downloads_via_clickpy import PYPI_NAME_RE, load_overrides, normalize
from readme_parser import (
_find_inline,
_parse_section_entries,
@@ -470,6 +472,25 @@ class TestParseRealReadme:
bad.append(f"{cat['name']}: [{see['name']}] (also_see) has invalid url: {see['url']!r}")
assert bad == [], "Entries with invalid URLs:\n" + "\n".join(bad)
def test_bundled_entries_are_never_queried_on_pypi(self):
"""A "(part of X)" entry ships inside something else, so it has no package of its own.
If its display name happens to be PyPI-shaped and no null override
records that, the download sweep queries PyPI and silently measures
whatever unrelated project owns the name. That is how uv-audit picked
up a third-party package after being renamed from "uv audit".
"""
overrides = load_overrides()
bad = []
for cat in self.cats:
for entry in cat["entries"]:
if not re.match(r"^\(part of ", entry["description"]):
continue
name = normalize(entry["name"])
if PYPI_NAME_RE.match(name) and overrides.get(name, name) is not None:
bad.append(f"[{entry['name']}] needs a null entry in pypi_name_overrides.json")
assert bad == [], "Bundled entries the download sweep would query:\n" + "\n".join(bad)
def test_no_malformed_entry_lines(self):
"""Detect list items that look like entries but have broken link syntax.