[GH-ISSUE #1122] Bundle composer vendor dependencies with released tarballs to support reproducible build system packaging #578

Closed
opened 2026-02-25 21:35:24 +03:00 by kerem · 7 comments
Owner

Originally created by @amessina on GitHub (Jul 16, 2024).
Original GitHub issue: https://github.com/cypht-org/cypht/issues/1122

Originally assigned to: @Shadow243 on GitHub.

🚀 Feature

Bundling composer vendor dependencies with released tarballs supports build system (like Koji) packaging that doesn't enable network connections. This is in support of reproducible builds.

Originally created by @amessina on GitHub (Jul 16, 2024). Original GitHub issue: https://github.com/cypht-org/cypht/issues/1122 Originally assigned to: @Shadow243 on GitHub. ## 🚀 Feature Bundling composer vendor dependencies with released tarballs supports build system (like Koji) packaging that doesn't enable network connections. This is in support of reproducible builds.
kerem 2026-02-25 21:35:24 +03:00
  • closed this issue
  • added the
    strategic
    label
Author
Owner

@marclaporte commented on GitHub (Jul 17, 2024):

Related: https://github.com/cypht-org/cypht/issues/597

<!-- gh-comment-id:2232368621 --> @marclaporte commented on GitHub (Jul 17, 2024): Related: https://github.com/cypht-org/cypht/issues/597
Author
Owner

@marclaporte commented on GitHub (Jul 22, 2024):

@kroky what do you think?

<!-- gh-comment-id:2243876399 --> @marclaporte commented on GitHub (Jul 22, 2024): @kroky what do you think?
Author
Owner

@kroky commented on GitHub (Jul 23, 2024):

Yes, +1 for bundling the vendor packages with the release tarballs.

<!-- gh-comment-id:2245001174 --> @kroky commented on GitHub (Jul 23, 2024): Yes, +1 for bundling the vendor packages with the release tarballs.
Author
Owner

@Shadow243 commented on GitHub (Aug 15, 2024):

It seams like the GITHUB_TOKEN provided by GitHub Actions has limited permissions by default. I'l review it and create a new one with right access permission.

<!-- gh-comment-id:2291041263 --> @Shadow243 commented on GitHub (Aug 15, 2024): It seams like the GITHUB_TOKEN provided by GitHub Actions has limited permissions by default. I'l review it and create a new one with right access permission.
Author
Owner

@Shadow243 commented on GitHub (Jan 4, 2025):

@marclaporte @kroky @amessina Can we close this since the PR is already merged ?

<!-- gh-comment-id:2571417370 --> @Shadow243 commented on GitHub (Jan 4, 2025): @marclaporte @kroky @amessina Can we close this since the PR is already merged ?
Author
Owner

@marclaporte commented on GitHub (Jan 5, 2025):

I'l review it and create a new one with white access permission

Is it done?

<!-- gh-comment-id:2571477943 --> @marclaporte commented on GitHub (Jan 5, 2025): > I'l review it and create a new one with white access permission Is it done?
Author
Owner

@Shadow243 commented on GitHub (Jan 5, 2025):

I'l review it and create a new one with white access permission

Is it done?

since the last release we have cypht.tar.gz which is added to the release and which contains the vendor folder already with the dependencies

https://github.com/cypht-org/cypht/pull/1142

I just checked, the token has expired since like a week. I will have to renew that

<!-- gh-comment-id:2571487376 --> @Shadow243 commented on GitHub (Jan 5, 2025): > > I'l review it and create a new one with white access permission > > > > Is it done? since the last release we have cypht.tar.gz which is added to the release and which contains the vendor folder already with the dependencies https://github.com/cypht-org/cypht/pull/1142 I just checked, the token has expired since like a week. I will have to renew that
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/cypht#578
No description provided.