Give the hash-locked l10n install its own pip invocation

pip enables hash-checking for an entire invocation the moment any
requirement in it carries a hash, and then demands hashes for
everything else in that invocation. The combined install line mixed
requirements-l10n.txt with two unhashed files and an editable install,
so it fails now that the l10n pins are hash-locked -- and
requirements.txt cannot simply join hash mode, because hash-checking
rejects its git-pinned entries outright.

Splitting the install keeps the l10n file's hashes enforced while the
other files continue to install unhashed. The comment above the
split line records why it exists, so it doesn't get folded back into
the combined line and break CI later.
This commit is contained in:
kdmukai
2026-08-19 19:03:59 -05:00
parent 046948946f
commit 596528f117
+7 -1
View File
@@ -53,7 +53,13 @@ jobs:
run: | run: |
sudo apt-get install libzbar0 sudo apt-get install libzbar0
python -m pip install --upgrade pip python -m pip install --upgrade pip
pip install -r requirements.txt -r tests/requirements.txt -r l10n/requirements-l10n.txt pip install -r requirements.txt -r tests/requirements.txt
# requirements-l10n.txt is hash-locked (SeedSigner OS installs it
# during image builds). It needs its own pip invocation: one hashed
# requirement makes pip demand hashes for everything else in the
# same invocation, which the unhashed files above and `-e .` below
# can't satisfy.
pip install -r l10n/requirements-l10n.txt
pip install -e . pip install -e .
- name: Compile translations - name: Compile translations
run: python setup.py compile_catalog run: python setup.py compile_catalog