Skip to content

PoetryLockHandler incorrectly marks non-optional packages as optional #5294

Description

@Mars-60

Description

PoetryLockHandler incorrectly reports resolved Poetry lockfile packages as optional even when the package has optional = false in poetry.lock.

For example, the existing ScanCode Poetry fixture contains:

[[package]]
name = "attrs"
version = "21.4.0"
optional = false

However, ScanCode reports the corresponding resolved dependency with:

"is_optional": true

The issue appears to come from the PoetryLockHandler implementation in src/packagedcode/pypi.py, which currently uses:

is_optional = package.get("is_optional") or True

Poetry uses the optional field in the lockfile, not is_optional. Additionally, using or True causes an explicit False value to become True.

The expected behavior is for a Poetry lockfile entry with optional = false to result in is_optional = false, while optional = true should result in is_optional = true.

How To Reproduce

The issue can be reproduced using the existing Poetry lockfile fixture:

tests/packagedcode/data/pypi/poetry/univers/poetry.lock

The fixture contains packages with:

optional = false

Run the existing Poetry lock parsing test:

.\venv\Scripts\pytest.exe tests\packagedcode\test_pypi.py::TestPoetryHandler::test_parse_poetry_lock_univers -q

Before the fix, the test fails because the parsed result reports the resolved packages as optional, while the Poetry lockfile specifies optional = false.

The behavior can also be reproduced with a minimal Poetry lockfile containing both optional = false and optional = true. The current implementation incorrectly reports the package with optional = false as optional.

System configuration

  • What OS are you running on? Windows
  • What version of scancode-toolkit was used to generate the scan file? commoncode-v32.5.2-14-g441f36f725
  • What installation method was used to install/run scancode? Source checkout with the project's virtual environment
  • Python version: 3.14.0

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions