Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

pin dependencies? #39

Open
meejah opened this issue May 20, 2023 · 0 comments
Open

pin dependencies? #39

meejah opened this issue May 20, 2023 · 0 comments

Comments

@meejah
Copy link
Member

meejah commented May 20, 2023

Since this is "a program" (only) now (after splitting from the magic-wormhole repository), we could follow the recommendations to more exactly pin the requirements, with hashes. (When a project can be used as a library, pinning requirements exactly is tough for downstream).

At least one consumer of this apparently wants something like this, although the exact ask doesn't have a corresponding ticket explaining the requirements: LeastAuthority/magic-wormhole-docker#30

Note that downstream consumer isn't actually checking hashes, it seems (so exact reproducibility must not be the use-case). I believe it's just so that exact versions of dependencies are known.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant