mirror of
https://github.com/vinta/awesome-python.git
synced 2026-10-06 17:05:16 +08:00
Renaming the entry from "uv audit" to "uv-audit" made the name PyPI-shaped: normalize() leaves spaces alone, so "uv audit" failed PYPI_NAME_RE and collect_names skipped it, but "uv-audit" passes, so the next sweep would have queried PyPI for it.
A uv-audit package does exist on PyPI, but it is version 0.1.9 by Alekse Marusich of rocshers, an unrelated third-party tool whose summary ("uv Tool for checking dependencies for vulnerabilities") is close enough to be mistaken for Astral's built-in uv audit subcommand. Without the override the entry would have shown that stranger's download count and lost its Bundled badge.
The sweep now writes uv-audit as NOT_FOUND, which load_downloads skips, so the badge is unaffected.
Co-Authored-By: Claude <noreply@anthropic.com>