-
-
Notifications
You must be signed in to change notification settings - Fork 24
Expand file tree
/
Copy pathcomposer.py
More file actions
57 lines (44 loc) · 1.94 KB
/
Copy pathcomposer.py
File metadata and controls
57 lines (44 loc) · 1.94 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
# fetchcode is a free software tool from nexB Inc. and others.
# Visit https://github.com/aboutcode-org/fetchcode for support and download.
#
# Copyright (c) nexB Inc. and others. All rights reserved.
# http://nexb.com and http://aboutcode.org
#
# This software is licensed under the Apache License version 2.0.
#
# You may not use this software except in compliance with the License.
# You may obtain a copy of the License at:
# http://apache.org/licenses/LICENSE-2.0
# Unless required by applicable law or agreed to in writing, software distributed
# under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR
# CONDITIONS OF ANY KIND, either express or implied. See the License for the
# specific language governing permissions and limitations under the License.
from packageurl import PackageURL
from fetchcode import fetch_json_response
class Composer:
purl_pattern = "pkg:composer/.*"
base_url = "https://repo.packagist.org"
@classmethod
def get_download_url(cls, purl):
"""
Return the download URL for a Composer PURL.
"""
purl = PackageURL.from_string(purl)
if not purl.name or not purl.version:
raise ValueError("Composer PURL must specify a name and version")
name = f"{purl.namespace}/{purl.name}" if purl.namespace else purl.name
url = f"{cls.base_url}/p2/{name}.json"
data = fetch_json_response(url)
if "packages" not in data:
return
if name not in data["packages"]:
return
for package in data["packages"][name]:
if (
package.get("version") == purl.version
or package.get("version") == f"v{purl.version}"
or package.get("version_normalized") == purl.version
or package.get("version_normalized") == f"v{purl.version}"
):
download_url = package["dist"].get("url")
return download_url