Fix querying osv
/pypa
, handle withdrawn CVEs and update pre-commit
hooks.
#115
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Proposed Changes
osv
andpypa
again.Dropped handling of
ranges
since the OSV 1.3 Schema is now garantueed to be backwards-compatible; thepypa/advisory-database
only usesECOSYSTEM
which requires the presence ofversions
-data and is less error-prone than parsing version ranges and we don't handleGIT
at the moment. Fixes Latest OSV schema update breakspypa
andosv
sources. #67, Fixes Latest schema update breakspypa
source. #68, Fixes False Positive for Patched pyyaml Fromosv
Source #69.(,0)
) forgemnasium
. Fixes checkingpyspark
againstgemnasium
throws an exception #90.0.910
to0.930
to fix broken wheel install on M1.