PEP 751: now with graphs!

I think I may have convinced myself before you had a chance to convince me. The gist was:

  • lockers routinely regenerate the entire lock file anyway, so migrating to a new hash algorithm is straightforward even with a common algorithm required across the whole file
  • lockers already have to rehash all the artifacts to check their hashes anyway, so extra work is only needed for artifacts where the index doesn’t provide the artifact hash for the algorithm used in the lock file

Given those points, the auditing benefit of using a consistent hash algorithm across the whole lock file was considered a good trade-off (at least, the topic didn’t come up again until Armin asked about it).

Edit: I found the original exchange about this: Lock files, again (but this time w/ sdists!) - #300 by a-reich (a general Discuss search didn’t pick it up, but searching that thread specifically got there). Brett’s original recollection was correct: I changed my mind after considering a question he asked.

2 Likes