On Tue, Aug 4, 2020 at 7:51 PM tastytea <tastytea+gen...@tastytea.de> wrote: > > This seems to affect only api.github.com, packages in ::guru use > https://github.com/<REPO>/archive/<COMMIT>.tar.gz instead, which is not > affected (just checked with net-wireless/rtl8192eu-0_pre20200123).
Ah, didn't notice that. This is the more common approach for Gentoo packages, if they use hashes at all. Usually tags are preferred. And if upstream actually has an official source tarball that is what gets used. The only reason anybody in Gentoo uses github links at all is either because upstream uses it officially, or upstream doesn't even bother to release source tarballs. -- Rich