4 ms·
There is a minor note that technically there is a weak guarantee that checksums won't break after server update and recompression with different version / alter
by Lockal 3y ago
There is a minor note that technically there is a weak guarantee that checksums won't break after server update and recompression with different version / alternative implementation of gzip.
https://github.com/orgs/community/discussions/45830 https://github.com/orgs/community/discussions/45830
- Aissen 3y agoIt's not a minor note, it's a major reason that the github auto-generated tarballs are useless as-is, since they are not stable.
- rwmj 3y agogithub have (for the moment) backed down and currently the auto-generated tarballs are stable, but they have in the past and may in the future change this.
- colejohnson66 3y agoThis was not GitHub’s fault, but Git itself combined with cache pruning. Specifically, GitHub updating to Git 2.38 which changed the algorithm. Non-cached tarballs were regenerated on demand, and all hell broke loose: https://github.blog/2023-02-21-update-on-the-future-stability-of-source-code-archives-and-hashes/ https://github.blog/2023-02-21-update-on-the-future-stabilit...
- Aissen 3y agoIt was not the first instance of this happening; other times I'm not certain it was git's fault.
- Lockal 3y agoThank you for highlighting this. I've started a new discussion https://github.com/orgs/community/discussions/116557 https://github.com/orgs/community/discussions/116557 to provide strong guarantees for checksum stability for autogenerated tarballs attached to releases.