3 ms·
I don't think they are talking about getting the artifact at the same time as the source or any such thing. They are saying, the metadata required to reproduce
by wakawaka28 1mo ago
I don't think they are talking about getting the artifact at the same time as the source or any such thing. They are saying, the metadata required to reproduce a build is not present in that sdist format, and there's no place to attach it. So, if you got an artifact and separately got the source, you couldn't verify it without another source of information about how to do the build itself in exactly the same way. It goes beyond pure reproducibility as well. Without that metadata to set up your environment, you may see bugs or other differences in your build that are not in the distributed artifact.
- crabbone 1mo agoOK. I see. But, even if this is the problem, the solution they are trying for is bad. What Python needs is a project definition (like what Ada has in GNAT Project Manager). PyPA repeatedly proved themselves incapable of coming up with something like this (first setup.cfg, then pyproject.toml), and I don't expect them to independently discover the solution to the problem that was discovered before Python was invented. They are not the kind of people that would be able to do that. They've been at it for some fifteen years and every time they roll out a new iteration it just gets worse.
- wakawaka28 1mo agoYeah I agree. The Python language sucks for stuff like this. Reproducibility is hardly a priority in a language where compatibility isn't even a priority. I like Python in spite of its many warts and wish it was possible to start a new language without the mistakes and have it be as popular as Python, but I don't see that ever happening. I think they've abandoned simple logic like the classic "There should be one-- and preferably only one --obvious way to do it." Nevertheless, I appreciate people trying to make the best of it.