Hacker News new | ask | show | jobs
by aepiepaey 2445 days ago
> Update the signing script to save the tarball to disk (previously, it lived in a pipe) and upload these alongside the releases…

This should have been done from the start.

GitHub does not guarantee checksums for the generated source archives to be stable, so they can change when GitHub updates their software (and yes, this has happened).