You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PyPI package names are case insensitive. When search vulnerability by ID GHSA-jwqp-28gf-p498, here are two affected packages: Scrapy and scrapy, but they are the same one package.
Thanks for reporting this. This is a known issue (ossf/osv-schema#42) on the GitHub advisories side. My understanding is that this may take some time to fix on their end.
We could also potentially normalize this ourselves, so I'll keep this open as a FR for that.
oliverchang
changed the title
PyPI package names are case insensitive
Normalize PyPI packages from sources.
Jul 12, 2022
Description
PyPI package names are case insensitive. When search vulnerability by ID GHSA-jwqp-28gf-p498, here are two affected packages: Scrapy and scrapy, but they are the same one package.
https://osv.dev/list?ecosystem=&q=GHSA-jwqp-28gf-p498

The text was updated successfully, but these errors were encountered: