#10409: libuv-1.19.2
 Reporter:  bdubbs@…     |       Owner:  thomas
     Type:  enhancement  |      Status:  assigned
 Priority:  normal       |   Milestone:  8.3
Component:  BOOK         |     Version:  SVN
 Severity:  normal       |  Resolution:
 Keywords:               |

Comment (by pierre.labastie):

 Replying to [comment:4 thomas]:
 > how to find out where the real source is?

 Use "git clone", then "git checkout <tag>": that is the real ''source''.
 Other things are packages or releases...
 > https://dist.libuv.org/dist/v1.19.2/libuv-v1.19.2.tar.gz  differs from
 https://github.com/libuv/libuv/archive/v1.19.2.tar.gz, the first tarred a
 directory named `libuv-v1.19.2`, the seconds one is `libuv-1.19.2` and
 therefore, the md5sums does not match at all. I personally more and more
 untrust all that github projects.

 Well, I do not see what is less trustable on github than on any other site

 Upstream packaging is faulty when you cannot find a md5sum (or shaxsum) or
 pgp signature. But this is not github's fault (sometimes there are
 signature or hash on the "release" pages on github). There is a signature
 on `dist.libuv.org`...

 > If ok so far, i'd like to use the `dist.libuv.org` archive or is there a
 guideline to prefer github? I'd than use that of course.

 One cannot tell at first: it depends on how reliable the server is. In
 this case, I'd be inclined to go to `dist.libuv.org`
 > Btw, there was a typo in my URLs (1.9.2 instead of 1.19.2) but the resst
 of the issues remains.

 Normally, Armin's trick should work too. But as said above, it seems
 better to use `dist.libuv.org`

Ticket URL: <http://wiki.linuxfromscratch.org/blfs/ticket/10409#comment:6>
BLFS Trac <http://wiki.linuxfromscratch.org/blfs>
Beyond Linux From Scratch
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page

Reply via email to