Skip to content

forc-pkg: source checksums #7075

Open
Open
@kayagokalp

Description

@kayagokalp

Currently fetched sources, does not have a mechanism to ensure they are not tampered with. So a user can simply go and change things and create bugs/hard to debug scenerios as forc will not have a way to understand the cache that it is using needs to be invalidated.

We should have a mechanism in hand to check if a fetched source is changed or not. This is related to:

  1. git
  2. registry (as of feat: registry source resolution and builds #7038)
  3. ipfs
    sources.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestforc-pkgEverything related to the `forc-pkg` crate.forc-registryEverything to do with forc-registry; IPFS sourcing, package registeryteam:toolingTooling Team

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions