Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

of distros, they usually refer to an upstream by hash

https://src.fedoraproject.org/rpms/conky/blob/rawhide/f/sour...

also of flathub

https://github.com/flathub/com.belmoussaoui.ashpd.demo/blob/...

"they are not lockfiles!" is a debatable separate topic, but for a wider disconnected ecosystem of sources, you can't really rely on versions being useful for reproducibility



> they usually refer to an upstream by hash

exactly the same thing as a lockfile




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: