mirror of
https://github.com/vinta/awesome-python.git
synced 2026-10-06 17:05:16 +08:00
The uv-audit bug had no automated guard: pypi_name_overrides.json is a manual registry, so a wrong-package mapping is only caught if someone already suspects it. Two broader checks were measured against the real list and rejected. Checking that PyPI metadata links back to the entry's GitHub repo would not have caught uv-audit, since that package declares no home_page or project_urls, landing it in a 26-entry bucket of packages that simply don't declare a repo (numba, selenium, pyglet, etc.), plus 10 benign cases of orgs moving or splitting bindings. Flagging display-name/repo-name mismatches yields 46 hits, all legitimate python-X-repo-to-X-package pairs, with uv-build sitting among them despite being a real Astral package with the identical shape to uv-audit. What discriminates is the bundled marker itself: a "(part of X)" entry ships inside something else and has no package of its own, so the sweep must never query it. This test walks the real README and requires a null override for every bundled entry whose normalized name is PyPI-shaped. Verified it fails with exactly the uv-audit message when that override is removed, and passes with it restored, across the three current bundled entries with no false positives. It runs offline, fitting the existing network-less CI. Co-Authored-By: Claude <noreply@anthropic.com>