Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Include hash of pip wheel in ensurepip #112721

Closed
@sethmlarson

Description

@sethmlarson

Feature or enhancement

Proposal:

Include the SHA 256 hash of the pip wheel artifact used in ensurepip module and fail execution if the checksum doesn't match. This will serve as a protection mechanism allowing non-trusted contributors to contribute updates to artifacts and allow reviewers to quickly check in the PyPI UI whether the artifact has the correct checksum.

This feature request was spawned from this PR: #112517 which required a bit more reviewing work to be confident in the contributed artifact.

Has this already been discussed elsewhere?

I have already discussed this feature proposal on Discourse

Links to previous discussion of this feature:

Discussed in the release Discord channel.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions