Skip to content

Conversation

@nodivbyzero
Copy link
Contributor

@nodivbyzero nodivbyzero commented Jan 7, 2026

Related to similar changes made in Twine: pypa/twine#1262

Related to: https://github.com/rstudio/package-manager/issues/16763

@posit-snyk-bot
Copy link

posit-snyk-bot commented Jan 7, 2026

Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@nodivbyzero nodivbyzero requested review from glin and jmwoliver January 8, 2026 00:00
Copy link

@glin glin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me, but can you explain how this relates to the license-file error? I'm not making the connection there 🤔

@nodivbyzero
Copy link
Contributor Author

@glin
Our tests compare the output of publishing a package via Twine with the results from our internal parsing logic.
Twine has removed this field, causing existing snapshots to become invalid.
I removed md5_digest from the PackageFile struct and regenerated the snapshots, license-file error has also been resolved.

@nodivbyzero nodivbyzero merged commit 63c8878 into main Jan 8, 2026
4 checks passed
@nodivbyzero nodivbyzero deleted the rm-md5-digest branch January 8, 2026 15:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants