Skip to content

Checksum of GitHub releases' tarballs changing (v6.0.2)? #4067

Closed Answered by ssbarnea
Antiz96 asked this question in Q&A
Discussion options

You must be logged in to vote

If you want immutable archives, use PyPi ones as they are like this by definition. GitHub based ones may change, either due to GitHub changes or because we might do a retagging at some point. We don't plan to do that, but we also offer no guarantees on immutability of the uploaded artifacts, we never did. In fact these artifacts are in general a blend of auto-generated and managed by github and some manually uploaded, and there is no clear way to distinguish between them.

The original post was bit misleading in regards to what setuptool-scm needs, as it does need those files. The reality is that molecule itself had an outdated file, one that will be fixed by #4071 - I hope that this will …

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@dvzrv
Comment options

@Torxed
Comment options

@ssbarnea
Comment options

Answer selected by ssbarnea
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants