Refer to upstream sources via release artifacts rather than generated archives #2831
Labels
area/packaging
Issues related to the packages bundled in Bottlerocket
status/icebox
Things we think would be nice but are not prioritized
type/enhancement
New feature or request
GitHub recently disturbed several projects' build processes by accidentally changing the way archives are generated. The change retained all archive contents, but the structural change led to hash sum checks breaking. More on this can be found in this article on LWN. GitHub responded by promising some advance notice for future changes affecting archive hashes.
Since Bottlerocket refers to third-party packages via
https://github.com/${org}/$[repo}/archive/...
URLs it would have been similarly affected by this. Consider referring to third-party package sources via static release artifact files instead of archives that are generated on demand.The text was updated successfully, but these errors were encountered: