sonatype-nexus-community / sonatype-platform-browser-extension

The Sonatype Platform Browser Extension
https://sonatype-nexus-community.github.io/sonatype-platform-browser-extension/
Apache License 2.0
2 stars 3 forks source link

No remediation shown for old versions of the Python project `Twisted` #115

Open madpah opened 10 months ago

madpah commented 10 months ago

Describe the bug

Discovered whilst testing #113 and #111, and present in version 2.15.1.

Due to some Python projects not always historically adhering to Python Standards, the situation can currently arise whereby a user is viewing a Python Project version (e.g. https://pypi.org/project/Twisted/19.2.0/) and no Remediation is returned by Sonatype Lifecycle and thus no Remediation path is presented to the user.

Screenshot 2024-01-03 at 08 57 32

Conversely a working version is https://pypi.org/project/Twisted/22.8.0/. Screenshot 2024-01-03 at 08 57 16

This has been tracked to the fact that the source distributions for this Python project have changed extension over time, and when we ask Sonatype Lifecycle for the next safe version against pkg:pypi/twisted@19.2.0?extension=tar.bz2, there are none returned, as the next safe version of Twisted is pkg:pypi/twisted@23.10.0?extension=tar.gz - note the change in extension.