Describe the bug
The query API compares package names exactly and only normalizes PyPI, so a valid but non-canonical spelling of a package returns no advisory even though it is the same package. NuGet, npm, and Packagist names are case-insensitive, and crates.io treats a dash and an underscore as equivalent.
To Reproduce
$ curl -s -X POST https://api.osv.dev/v1/query -d '{"package":{"name":"Newtonsoft.Json","ecosystem":"NuGet"},"version":"12.0.3"}'
{"vulns":[ ... ]}
$ curl -s -X POST https://api.osv.dev/v1/query -d '{"package":{"name":"newtonsoft.json","ecosystem":"NuGet"},"version":"12.0.3"}'
{}
Same result for crates.io (smallvec vs SmallVec, openssl-src vs openssl_src), Packagist (guzzlehttp/guzzle vs GuzzleHttp/Guzzle), and npm (lodash vs Lodash).
Expected behaviour
Both spellings resolve to the same package, so the query should return the same advisories for either one.
Additional context
NormalizePackageName (go/osv/ecosystem/ecosystem.go) leaves the name unchanged unless the ecosystem implements PackageNameNormalizer, which today only PyPI and Echo do. Both the query path and the namenormalize enricher call it, so a fix there covers both sides. I have a small fix with tests for NuGet, crates.io, npm, and Packagist. Existing stored records would need reprocessing through the enricher so old names normalize too.
Describe the bug
The query API compares package names exactly and only normalizes PyPI, so a valid but non-canonical spelling of a package returns no advisory even though it is the same package. NuGet, npm, and Packagist names are case-insensitive, and crates.io treats a dash and an underscore as equivalent.
To Reproduce
Same result for crates.io (
smallvecvsSmallVec,openssl-srcvsopenssl_src), Packagist (guzzlehttp/guzzlevsGuzzleHttp/Guzzle), and npm (lodashvsLodash).Expected behaviour
Both spellings resolve to the same package, so the query should return the same advisories for either one.
Additional context
NormalizePackageName(go/osv/ecosystem/ecosystem.go) leaves the name unchanged unless the ecosystem implementsPackageNameNormalizer, which today only PyPI and Echo do. Both the query path and thenamenormalizeenricher call it, so a fix there covers both sides. I have a small fix with tests for NuGet, crates.io, npm, and Packagist. Existing stored records would need reprocessing through the enricher so old names normalize too.