Skip to content

SHA1 sum of package dists should be more reliable than a SHA1 on the zip result #2540

@Seldaek

Description

@Seldaek

(Replacing #1496 which has become a mess, references #5940)

If multiple servers create archives, then those archives can have different SHA1s which is problematic. Potential solutions:

  • hash the contents in a reproducible way (might be very slow)
  • just avoid recreating archives all the time (depends on ecosystem but preferable)

Metadata

Metadata

Assignees

Labels

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions