Skip to content

Avoid crashing on Go package URLs without a version - #235

Open
codewithfourtix wants to merge 2 commits into
package-url:mainfrom
codewithfourtix:fix-golang-unversioned-download
Open

Avoid crashing on Go package URLs without a version#235
codewithfourtix wants to merge 2 commits into
package-url:mainfrom
codewithfourtix:fix-golang-unversioned-download

Conversation

@codewithfourtix

Copy link
Copy Markdown

An unversioned Go purl passes None to escape_golang_path() and crashes. Return early when the version is missing, allowing the existing download_url qualifier fallback to work.

Adds regression coverage for unversioned purls with and without a download qualifier. Fixes #220.

Signed-off-by: Ali Zulfiqar <codewithfourtix@gmail.com>
Copilot AI lite review requested due to automatic review settings September 5, 2026 17:02

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change directly addresses the reported crash and adds targeted regression coverage; remaining feedback is limited to minor maintainability improvements.

Pull request overview

Fixes a crash in purl2url.get_download_url() when handling Go package URLs that omit a version, allowing the existing download_url qualifier fallback to work as intended (per #220).

Changes:

  • Update the Go download URL builder to return early when version is missing (preventing escape_golang_path(None)).
  • Add regression tests covering unversioned Go purls with and without a download_url qualifier.
File summaries
File Description
src/packageurl/contrib/purl2url.py Prevents a None version from being passed into Go path escaping by returning early.
tests/contrib/test_purl2url.py Adds regression coverage for unversioned Go purls and qualifier fallback behavior.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/packageurl/contrib/purl2url.py
Comment thread tests/contrib/test_purl2url.py Outdated
Signed-off-by: Ali Zulfiqar <codewithfourtix@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

get_download_url fails for "pkg:golang/google.golang.org/genproto#googleapis/api/annotations"

2 participants