PyPi packages and advisories are matched partially according to PEP503
What does this MR do?
-
Extends
pythonGlob
so that package names will match better with GLAD advisory paths. We do that by applying PEP503 between the dependencies scanned and the advisory paths. According to PEP503_-.
should be interpreted as-
and all letters should be lower case. We make sure that we add.
in the list of special characters. -
Adds Unit test case for this specific case.
What are the relevant issue numbers?
gitlab-org/gitlab#440392 (comment 1829828183)
Does this MR meet the acceptance criteria?
-
Changelog entry added -
Documentation created/updated for GitLab EE, if necessary -
Documentation created/updated for this project, if necessary -
Documentation reviewed by technical writer or follow-up review issue created -
Tests added for this feature/bug -
Job definition updated, if necessary -
Conforms to the code review guidelines -
Conforms to the Go guidelines -
Security reports checked/validated by reviewer
Edited by Nick Ilieskou