dsmiley commented on code in PR #3751:
URL: https://github.com/apache/solr/pull/3751#discussion_r2440035313


##########
solr/licenses/cuvs-java-25.10.0.jar.sha1:
##########


Review Comment:
   Why would a renovate bot, setting out to update `onnxruntime` (this is in 
the title), touch a cuvs sha1?  Even if that sha1 update needs to happen for 
_separate_ reasons, I don't think a renovate bot should be modifying sha1s.  
I'm okay with it creating ones for new dependency versions but not modifying 
any.  Modifications should be exclusively done by us humans.
   
   CC @janhoy @chatman 
   Coincidentally, @aruggero tells me that this fixed her checkout from having 
wrong/bad sha1s for CUVS... okay great but what I said above stands nonetheless.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to