Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

_is_valid_dist_file doesn't discern where a PKG-INFO/WHEEL file is in the archive #16704

Open
di opened this issue Sep 12, 2024 · 0 comments
Open
Labels

Comments

@di
Copy link
Member

di commented Sep 12, 2024

Noticed in #16703 that _is_valid_dist_file currently checks for PKG-INFO or WHEEL files to be present in a sdist or wheel, but doesn't validate where they are in the archive, so putting any file with a matching name anywhere in the archive will allow it to pass.

Our tests currently place these at the root of the archive, but they should actually be within a specific top-level directory for both file types, and validation should fail if they exist but aren't in that directory.

@di di added requires triaging maintainers need to do initial inspection of issue bug 🐛 and removed requires triaging maintainers need to do initial inspection of issue labels Sep 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant