Should we stop distributing source tarballs?

Sune Vuorela nospam at vuorela.dk
Thu Apr 4 10:47:50 BST 2024


On 2024-04-03, Albert Vaca Cintora <albertvaka at gmail.com> wrote:
> What's the advantage of providing tarballs?

I do think there is an advantage in being able to verify that the soure
tarball is the same across distributions. Using a checksum on the
tarball is an easy way of doing it. Different git invocations for git
archive, different tar options and so on can create different checksums
for the same content.

I do also think it is nice if we get someone else to verify that the
tarball we ship actually matches the tag. I think some people in
distributions have already started looking into verifying that.

Also, git tags can be moved.

/Sune



More information about the kde-devel mailing list