aboutcode-org / aboutcode-org/python-publicsuffix2

Including upstream list as submodule/subtree would be more transparent

Aperta
#13 3 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Python
Stelle
30
Fork
16
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

~~During packaging of python-publicsuffix2 I realized, that downloading the publicsuffix list during build time makes it unreproducible (any time the package is rebuilt, it will have a different list).~~

My suggestion would be to include the publicsuffix list from [upstream](https://github.com/publicsuffix/list/blob/master/public_suffix_list.dat) directly as e.g. a [git submodule](https://github.com/publicsuffix/list/blob/master/public_suffix_list.dat) or [git subtree](https://git-memo.readthedocs.io/en/latest/subtree.html) (the latter is preferred as this way the files actually end up in an automatically generated tarball on github when tagging a release) and not download it ~~during build time~~ at all to ~~ensure reproducibility~~ raise transparency.
The data lives in this repository already, so it could also be copied manually, but IMHO a subtree or submodule is the more transparent way of dealing with this.

~~Currently only the wheel on pypi.org is really ensured to carry the currently bundled version of the publicsuffix list. For anyone else building this package, this assumption is not valid.~~

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.