We don't ship hashed dependencies under either a signed tag nor in a signed release. Dependencies should be pinned and hashed and subject to a signature. Could explore poetry or pipenv for this?
The text was updated successfully, but these errors were encountered:
Context: tor ticket 28682 http://ea5faa5po25cf7fb.onion/projects/tor/ticket/28682
We don't ship hashed dependencies under either a signed tag nor in a signed release. Dependencies should be pinned and hashed and subject to a signature. Could explore
poetryorpipenvfor this?The text was updated successfully, but these errors were encountered: