docs: evaluate SPDX conjunctions and read every Python manifest

Reject a copyleft conjunct in an expression like '(MIT OR Apache-2.0)
AND GPL-3.0-only', which a permissive-alternative search accepted.
Discover python/*/pyproject.toml by glob, accept single-quoted TOML
literals, and fail on a requirement whose name cannot be read. Say that
the development tier records who declares a package rather than what a
build bundles, since a runtime dependency can pull one in transitively,
and sync the contributor guide's pre-commit list.
This commit is contained in:
ZiyaZhang
2026-07-30 19:54:27 -07:00
parent 9f9d6fc0e2
commit 421594472a
6 changed files with 52 additions and 23 deletions

View File

@@ -127,6 +127,11 @@ describe('parsePyprojectRequirements', () => {
.toEqual(['httpx', 'requests'])
})
it('reads single-quoted TOML literals and rejects an unreadable requirement', () => {
expect(parsePyprojectRequirements("[project]\ndependencies = ['requests', \"pydantic>=2\"]\n")).toEqual(['requests', 'pydantic'])
expect(() => parsePyprojectRequirements('[project]\ndependencies = ["!!broken"]\n')).toThrow(/cannot read a distribution name/)
})
it('reads a multi-line array', () => {
expect(parsePyprojectRequirements('[project]\ndependencies = [\n "pydantic>=2.12",\n "typing-extensions",\n]\n'))
.toEqual(['pydantic', 'typing-extensions'])
@@ -138,6 +143,13 @@ describe('isPermissive', () => {
expect(['MIT', 'ISC', 'BSD-3-Clause', 'Apache-2.0', 'MIT / Apache-2.0', '(MIT OR CC0-1.0)'].every(isPermissive)).toBe(true)
expect(['LGPL-3.0-only', 'MPL-2.0', 'GPL-3.0-or-later', 'SEE LICENSE IN LICENSE'].some(isPermissive)).toBe(false)
})
it('requires every operand of an AND, so a copyleft conjunct cannot ride along', () => {
expect(isPermissive('(MIT OR Apache-2.0) AND GPL-3.0-only')).toBe(false)
expect(isPermissive('MIT AND ISC')).toBe(true)
// An exception clause is not a recognized identifier, so it fails closed.
expect(isPermissive('GPL-2.0-only WITH Classpath-exception-2.0')).toBe(false)
})
})
describe('manifestPatterns', () => {