Files
seedsigner/.github
kdmukai 175db636e6 Hash-lock the remaining requirements pins
Cover requirements.txt, tests/requirements.txt, and
requirements-raspi.txt like the l10n pins: every entry now carries the
sha256 of every published file for its release, so pip refuses any
unverified artifact.

Hash-checking mode can't verify git checkouts, so the pyzbar and
urtypes deps become commit-pinned GitHub archive tarballs. The mode
also demands pins for everything in the invocation, so pytest's
transitive deps are pinned too, and coverage is pinned as
coverage[toml]: older pips (e.g. the docker dev image's) won't accept
a plain pin as satisfying pytest-cov's extra-qualified dependency.
2026-08-22 07:11:27 -05:00
..