Skip to content

Has 2.1.0 been retagged (some time after 2023-12-25)? #133

@dvzrv

Description

@dvzrv

Hi! 👋

I'm currently looking into upgrading the package for this project on Arch Linux.
We have updated the package to 2.1.0 on 2023-12-25:
https://gitlab.archlinux.org/archlinux/packaging/packages/python-email-validator/-/commit/39473a30a13a783b4f146da8e44d8dd151c17a45

Here a SHA-512 checksum of d285404f6735e0cd33385060c483a4dd4e12ace4b2e7027f8cd360901bc640ae999eb5d3ec2b98530e53af48f8e6c180d65cb53eec4de5a1617149ab76027901 was locked for the tarball.

Today I downloaded the sources and am met with a different checksum:
e2dfc9b025e95ee2528cb3598c4b77dc9feb6335737de6a621bb968c499a07da75315422df9ed29d9b7d6dcc6a89da73d4d1c646b62b6824050216e25377166a

The most plausible explanation is usually, that a tag has been deleted and recreated (somewhere else). Worst case this is a supply chain attack that we would likely want to guard ourselves against 😅

@JoshData can you provide some insight into this?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions