diff options
| author | Winter <winter@winter.cafe> | 2023-01-28 12:48:24 -0500 |
|---|---|---|
| committer | Lily Foster <lily@lily.flowers> | 2023-04-28 18:09:39 -0400 |
| commit | 7efebca89c10c8b075790d31dad12c31beb23383 (patch) | |
| tree | 16633650ac9cc4abe78a82cef3861bd8217309dc /pkgs/development/python-modules/python-openstackclient | |
| parent | d6b863fd9b7bb962e6f9fdf292419a775e772891 (diff) | |
prefetch-npm-deps: fix reproducibility
v1 lockfiles can contain multiple references to the same version of a
package, and these references can contain different `integrity` values,
such as one having SHA-1 and SHA-512, while another just has SHA-512.
Given that HashMap iteration order isn't defined, this causes
reproducibility issues, as a different integrity value could be chosen
each time.
Thanks to @lilyinstarlight for discovering this issue originally, as well
as the idea for the sorting-based implementation.
Diffstat (limited to 'pkgs/development/python-modules/python-openstackclient')
0 files changed, 0 insertions, 0 deletions
