Skip to content

Fix Cargo native ranges and add include_prerelease flag - #41

Open
andrew wants to merge 2 commits into
mainfrom
fix-cargo-comma-and-prerelease-flag
Open

andrew wants to merge 2 commits into
mainfrom
fix-cargo-comma-and-prerelease-flag

Conversation

@andrew

@andrew andrew commented Sep 16, 2026

Copy link
Copy Markdown
Owner

Cargo native ranges: accept , as the AND separator and treat a bare version as ^version (Cargo's documented default), instead of routing both through npm's exact-match/whitespace-only path. Fixes #37.

Vers.satisfies? and VersionRange#contains? take an include_prerelease: keyword that bypasses the node-semver prerelease gate on npm/cargo ranges, for advisory-style matching where a prerelease inside a vulnerable range should match even when no bound carries a prerelease tag. Fixes #38.

Unblocks the vers 2.x half of ecosyste-ms/advisories#1106.

Accept comma as the AND separator per Cargo's documented requirement
syntax, and treat a bare version as a caret requirement (Cargo's
default) instead of an exact match.

Fixes #37
Lets callers opt out of the node-semver prerelease gate on npm/cargo
ranges so advisory-style matching can include prereleases whose bounds
carry no prerelease tag.

Fixes #38

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Option to include prereleases when matching npm/cargo ranges Cargo native ranges with comma-separated comparators are rejected in 2.0

2 participants