From 046948946f90f1891b3c64b0ae7c85908196e91a Mon Sep 17 00:00:00 2001 From: kdmukai <934746+kdmukai@users.noreply.github.com> Date: Wed, 19 Aug 2026 19:03:40 -0500 Subject: [PATCH] Hash-lock the l10n requirements pins This file is not just a dev convenience: SeedSigner OS installs it during image builds to compile the .mo translation catalogs. A version pin alone only protects against drift -- it still trusts whatever artifact PyPI serves for that version. Recording sha256 hashes makes pip verify every downloaded file against the digests audited here, so a tampered artifact fails the install instead of entering the build. Each entry's hashes cover the full release (wheel and sdist), so installs work on any host. setuptools moves from >=82.0.0 to ==84.0.0 because hash-checking mode rejects range specifiers. 84.0.0 is what the floor resolves to today, and compile_catalog was verified working under it. Neither Babel nor setuptools pulls transitive dependencies on Python >= 3.10, so these two entries are the complete set pip needs. The file header records how to refresh a hash when bumping a pin, and warns that the file now needs its own pip invocation: any hashed requirement makes pip demand hashes for everything installed alongside it. CI's combined install trips over exactly that; the next commit splits it. --- l10n/requirements-l10n.txt | 21 +++++++++++++++++++-- 1 file changed, 19 insertions(+), 2 deletions(-) diff --git a/l10n/requirements-l10n.txt b/l10n/requirements-l10n.txt index d7821516..6c1e9fd6 100644 --- a/l10n/requirements-l10n.txt +++ b/l10n/requirements-l10n.txt @@ -1,2 +1,19 @@ -Babel==2.16.0 -setuptools>=82.0.0 +# Dependencies for the translation workflow (setup.py extract_messages / +# compile_catalog). Also installed during SeedSigner OS image builds to +# compile the .mo catalogs, so entries are pinned and hash-locked: pip +# refuses any artifact that does not match a hash below. Hashes cover every +# published file of each release (wheel + sdist). +# +# To update a pin: change the version, then refresh its hashes from +# https://pypi.org/pypi///json (or pip download + pip hash). +# +# NOTE: install this file in its own `pip install` invocation. Combining it +# with unhashed requirements files (or `-e .`) in one invocation fails, +# because any hash in an invocation makes pip require hashes for everything +# in it. +Babel==2.16.0 \ + --hash=sha256:368b5b98b37c06b7daf6696391c3240c938b37767d4584413e8438c5c435fa8b \ + --hash=sha256:d1f3554ca26605fe173f3de0c65f750f5a42f924499bf134de6423582298e316 +setuptools==84.0.0 \ + --hash=sha256:51a52592b3b99e102b609654876bd65f19f999935166d1352678931132b0c670 \ + --hash=sha256:f4695c21257f0d9b537ec2692c941d02ee143b7cc1276941349a546573b2ef73