Skip to content

Image matches PyPI workflow treats regex-like tags as an exact version match #3416

Description

@ohdearquant

The has_tag helper at line 79 uses grep -qx "$1" rather than fixed-string matching. VERSION comes from PyPI and normally contains dots, which are regex wildcards in grep.

For example, with VERSION=0.35.1 and registry tags containing 0x35x1 but not 0.35.1, the helper returns success. The workflow then sets present=yes for a tag that is not the PyPI version and can report the registry as matching when the literal version tag is absent.

Use grep -qxF -- "$1" so the tag is compared literally, and add a test covering a tag that differs only at the dot positions.

Code at the merge commit:

has_tag() { printf '%s\n' "${tags}" | grep -qx "$1"; }

Merged change: #3412

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    regression-watchConfirmed regressions in merged changes

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions