-
Notifications
You must be signed in to change notification settings - Fork 131
Description
Hi! 👋
I'm currently looking into upgrading the package for this project on Arch Linux.
We have updated the package to 2.1.0 on 2023-12-25:
https://gitlab.archlinux.org/archlinux/packaging/packages/python-email-validator/-/commit/39473a30a13a783b4f146da8e44d8dd151c17a45
Here a SHA-512 checksum of d285404f6735e0cd33385060c483a4dd4e12ace4b2e7027f8cd360901bc640ae999eb5d3ec2b98530e53af48f8e6c180d65cb53eec4de5a1617149ab76027901 was locked for the tarball.
Today I downloaded the sources and am met with a different checksum:
e2dfc9b025e95ee2528cb3598c4b77dc9feb6335737de6a621bb968c499a07da75315422df9ed29d9b7d6dcc6a89da73d4d1c646b62b6824050216e25377166a
The most plausible explanation is usually, that a tag has been deleted and recreated (somewhere else). Worst case this is a supply chain attack that we would likely want to guard ourselves against 😅
@JoshData can you provide some insight into this?