From 596528f11736c0974372d1dc753a479adefbb451 Mon Sep 17 00:00:00 2001 From: kdmukai <934746+kdmukai@users.noreply.github.com> Date: Wed, 19 Aug 2026 19:03:59 -0500 Subject: [PATCH] Give the hash-locked l10n install its own pip invocation pip enables hash-checking for an entire invocation the moment any requirement in it carries a hash, and then demands hashes for everything else in that invocation. The combined install line mixed requirements-l10n.txt with two unhashed files and an editable install, so it fails now that the l10n pins are hash-locked -- and requirements.txt cannot simply join hash mode, because hash-checking rejects its git-pinned entries outright. Splitting the install keeps the l10n file's hashes enforced while the other files continue to install unhashed. The comment above the split line records why it exists, so it doesn't get folded back into the combined line and break CI later. --- .github/workflows/tests.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 3ec94b71..821e1a22 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -53,7 +53,13 @@ jobs: run: | sudo apt-get install libzbar0 python -m pip install --upgrade pip - pip install -r requirements.txt -r tests/requirements.txt -r l10n/requirements-l10n.txt + pip install -r requirements.txt -r tests/requirements.txt + # requirements-l10n.txt is hash-locked (SeedSigner OS installs it + # during image builds). It needs its own pip invocation: one hashed + # requirement makes pip demand hashes for everything else in the + # same invocation, which the unhashed files above and `-e .` below + # can't satisfy. + pip install -r l10n/requirements-l10n.txt pip install -e . - name: Compile translations run: python setup.py compile_catalog