Skip to content

OSV.dev query API returns no advisory for a valid non-canonical package name (false negative across NuGet, crates.io, npm, and Packagist) #6039

Description

@kanokwut

Describe the bug
The query API compares package names exactly and only normalizes PyPI, so a valid but non-canonical spelling of a package returns no advisory even though it is the same package. NuGet, npm, and Packagist names are case-insensitive, and crates.io treats a dash and an underscore as equivalent.

To Reproduce

$ curl -s -X POST https://api.osv.dev/v1/query -d '{"package":{"name":"Newtonsoft.Json","ecosystem":"NuGet"},"version":"12.0.3"}'
{"vulns":[ ... ]}

$ curl -s -X POST https://api.osv.dev/v1/query -d '{"package":{"name":"newtonsoft.json","ecosystem":"NuGet"},"version":"12.0.3"}'
{}

Same result for crates.io (smallvec vs SmallVec, openssl-src vs openssl_src), Packagist (guzzlehttp/guzzle vs GuzzleHttp/Guzzle), and npm (lodash vs Lodash).

Expected behaviour
Both spellings resolve to the same package, so the query should return the same advisories for either one.

Additional context
NormalizePackageName (go/osv/ecosystem/ecosystem.go) leaves the name unchanged unless the ecosystem implements PackageNameNormalizer, which today only PyPI and Echo do. Both the query path and the namenormalize enricher call it, so a fix there covers both sides. I have a small fix with tests for NuGet, crates.io, npm, and Packagist. Existing stored records would need reprocessing through the enricher so old names normalize too.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions