aboutcode-org / aboutcode-org/python-publicsuffix2

Including upstream list as submodule/subtree would be more transparent

Open
#13 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
30
Forks
16
PR merge metrics
No merged PRs in 30d

Description

~~During packaging of python-publicsuffix2 I realized, that downloading the publicsuffix list during build time makes it unreproducible (any time the package is rebuilt, it will have a different list).~~

My suggestion would be to include the publicsuffix list from [upstream](https://github.com/publicsuffix/list/blob/master/public_suffix_list.dat) directly as e.g. a [git submodule](https://github.com/publicsuffix/list/blob/master/public_suffix_list.dat) or [git subtree](https://git-memo.readthedocs.io/en/latest/subtree.html) (the latter is preferred as this way the files actually end up in an automatically generated tarball on github when tagging a release) and not download it ~~during build time~~ at all to ~~ensure reproducibility~~ raise transparency.
The data lives in this repository already, so it could also be copied manually, but IMHO a subtree or submodule is the more transparent way of dealing with this.

~~Currently only the wheel on pypi.org is really ensured to carry the currently bundled version of the publicsuffix list. For anyone else building this package, this assumption is not valid.~~

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.