Skip to content

Conversation

@f-f
Copy link
Member

@f-f f-f commented Jan 18, 2026

In the same vein as purescript/registry-dev#723, we add hash verification for the lockfile hashes: the check between tarball hash and what we store in the metadata is error-worthy, but we currently say nothing if the lockfile doesn't have good hashes. This makes sense as those hashes were initially put there for tools such as Nix.

In any case, as we are approaching the Registry-regen, it might make sense to start warning about these mismatch and make them actionable. @thomashoneyman the current warning is not very actionable, I would like to tell users to regen the lockfile, do you have any ideas on how to not make it overly scary?

Copy link
Member

@thomashoneyman thomashoneyman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving, no strong opinion on what error you settle on!

@f-f f-f merged commit 3c89e30 into master Jan 31, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants