[RFC] New ports idea: github / gitorious / bitbucket direct support.

perryh at pluto.rain.com perryh at pluto.rain.com
Sat Sep 10 07:11:45 UTC 2011


Baptiste Daroussin <bapt at freebsd.org> wrote:

> The main problem with that is: we have no way to keep a valid sum
> of the distfiles if it is autogenerated (in particular with github)
> and this sum is really important.

No question about the importance of the checksum, to prevent trojans
and other problems if the distfile were to change "silently".

If I am understanding correctly, you seem to be saying that two
distfiles autogenerated from the _same_ tag etc. in the _same_
repository, and actually containing exactly the same code, can
nevertheless generate different checksums!?  Wouldn't that be a
bug in the DVCS?


More information about the freebsd-ports mailing list