Issue while scanning pypi/pillow, causes ambiguous result when trying to match package
Currently scanning our project with gemnasium-python fails due to this error.
[FATA] [gemnasium-python] [2024-04-03T19:28:42Z] ▶ scanning file /src/poetry.lock: finding package affections for file /src/poetry.lock: fetching package advisories: ambiguous result when trying to match package pypi/pillow
I assume because of !27705 (merged), where a CVE was placed in a new directory under pypi/pillow
instead of the existing directory pypi/Pillow
.