You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 7917c6c
Browse filesBrowse the repository at this point in the historyBrowse files
The ambiguity check in and only looked at vendor
ledger keys, but selection also matches via
VendorEntry::matches_target. For golang packages, keys are case-encoded
(e.g., ) while is decoded (e.g., ), so a name
like could appear unique during ambiguity checking but then match
multiple packages during selection.
The fix includes both the ledger key AND the in the
ambiguity check candidates, ensuring that ambiguous names are properly
detected and refused before any mutation occurs.
0 commit comments