Skip to content

Preserve package names inside npm prerelease versions - #236

Open
codewithfourtix wants to merge 1 commit into
package-url:mainfrom
codewithfourtix:fix-npm-archive-version-prefix
Open

Preserve package names inside npm prerelease versions#236
codewithfourtix wants to merge 1 commit into
package-url:mainfrom
codewithfourtix:fix-npm-archive-version-prefix

Conversation

@codewithfourtix

Copy link
Copy Markdown

Parsing foo-1.0.0-foo.1.tgz currently drops both occurrences of foo, changing the version to 1.0.0-.1. Remove only the filename prefix so the prerelease version stays intact.

Adds regression coverage for scoped and unscoped npm downloads.

Signed-off-by: Ali Zulfiqar <codewithfourtix@gmail.com>
Copilot AI lite review requested due to automatic review settings September 5, 2026 17:02

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is small, targeted, and the added regression test directly covers the reported parsing bug for both scoped and unscoped npm tarball URLs.

Pull request overview

Fixes npm download URL parsing so that prerelease versions containing the package name (e.g., foo-1.0.0-foo.1.tgz) keep the full prerelease string instead of incorrectly removing embedded name occurrences.

Changes:

  • Update npm tarball version extraction to remove only the leading filename prefix (not all occurrences).
  • Add regression tests covering both unscoped and scoped npm download URLs for this prerelease pattern.
File summaries
File Description
src/packageurl/contrib/url2purl.py Switches version derivation from global replace() to prefix-only removal to preserve prerelease content.
tests/contrib/test_url2purl.py Adds a regression test ensuring scoped/unscoped npm tarball URLs keep -foo.1 in the parsed version.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants