4 ms·
Another reason to include commit ids in the url when fetching files from external repos. I think you should do this anyways in case the external repo maintainer
by 1lint 3y ago
Another reason to include commit ids in the url when fetching files from external repos. I think you should do this anyways in case the external repo maintainer makes a change that silently breaks your build script
- slimsag 3y agoThat won't help you very much. There's no guarantee the commit belongs to the named repository with e.g. raw links[0]. [0] https://twitter.com/slimsag/status/1672421999698903043 https://twitter.com/slimsag/status/1672421999698903043
- faangsticle 3y agoOf course it will, since you'll either get the commit you wanted at the time you wrote the script, or an error.
- bqmjjx0kac 3y agoUnless someone is very good at finding SHA1 collisions.
- glandium 3y agoIf you clone the repo, it won't be there.
- ewhauser421 3y agoJust verify the SHA of the tarball a la Bazel?
- glandium 3y agoRemember when git archive changed its format and that affected archives downloaded from github?