Skip to content

P1: Replace development SHA pins with released X.Y artifacts #100

Description

@sfloess

Reduce reproducibility fragility identified in the Grok/TUI-002 review.

Acceptance criteria:

  • Inventory all git+https SHA pins in runtime/development dependencies.
  • Replace pins with released X.Y artifacts or a documented internal distribution mechanism when the dependency is release-worthy.
  • Retain immutable pinning only where there is a deliberate security/reproducibility reason, documented in the repo.
  • Bootstrap installation remains deterministic without requiring a source checkout.
  • Add CI validation preventing accidental reintroduction of unreviewed SHA-only runtime dependencies.
  • Preserve the X.Y release convention.

Program tracker: FlossWare/FlossWare#4

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions