mirror of
https://github.com/SeedSigner/seedsigner.git
synced 2026-10-05 15:08:25 +00:00
Cover requirements.txt, tests/requirements.txt, and requirements-raspi.txt like the l10n pins: every entry now carries the sha256 of every published file for its release, so pip refuses any unverified artifact. Hash-checking mode can't verify git checkouts, so the pyzbar and urtypes deps become commit-pinned GitHub archive tarballs. The mode also demands pins for everything in the invocation, so pytest's transitive deps are pinned too, and coverage is pinned as coverage[toml]: older pips (e.g. the docker dev image's) won't accept a plain pin as satisfying pytest-cov's extra-qualified dependency.