You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardexpand all lines: versions.sh
-30
Original file line number
Diff line number
Diff line change
@@ -40,36 +40,6 @@ check_file() {
40
40
return 0
41
41
fi
42
42
43
-
# TODO is this even necessary/useful? the sigstore-based version above is *much* faster, supports all current versions (not just 3.12+ like this), *and* should be more reliable 🤔
44
-
local sbom
45
-
if sbom="$(
46
-
wget -qO- -o/dev/null "$url.spdx.json" \
47
-
| jq --arg filename "$filename"'
48
-
first(
49
-
.packages[]
50
-
| select(
51
-
.name == "CPython"
52
-
and .packageFileName == $filename
53
-
)
54
-
)
55
-
| .checksums
56
-
| map({
57
-
key: (.algorithm // empty | ascii_downcase),
58
-
value: (.checksumValue // empty),
59
-
})
60
-
| if length < 1 then
61
-
error("no checksums found for \($filename)")
62
-
else . end
63
-
| from_entries
64
-
| if has("sha256") then . else
65
-
error("missing sha256 for \($filename); have \(.)")
0 commit comments