GitHub's auto-generated archive tarballs (/archive/refs/tags/*.tar.gz) are not byte-stable — GitHub can regenerate them at any time, producing a different SHA-256 even when the underlying git content hasn't changed. This has caused brew install failures at least twice:
v1.1.30 — e3cb66f manual SHA fix
v1.1.45 — 5cafee0 manual SHA fix
Proposed fix: Switch the formula from a tarball URL with sha256 to a git-based url with tag and revision:
# Before
url "https://github.com/buildio/cli/archive/refs/tags/v1.1.45.tar.gz"
sha256 "e7a6c7504c73f769995b8778766b62f65f897ba06ae8b12b54a2328628a9081f"
# After
url "https://github.com/buildio/cli.git",
tag: "v1.1.45",
revision: "24bb4e60b8e7d4fbbf65a8e6761b9afdefa4e88e"
This also requires updating update-formula.yml to resolve the tag to a commit SHA (via git ls-remote) and write the tag/revision fields instead of downloading the tarball and computing a hash.
GitHub's auto-generated archive tarballs (
/archive/refs/tags/*.tar.gz) are not byte-stable — GitHub can regenerate them at any time, producing a different SHA-256 even when the underlying git content hasn't changed. This has caused brew install failures at least twice:v1.1.30 — e3cb66f manual SHA fix
v1.1.45 — 5cafee0 manual SHA fix
Proposed fix: Switch the formula from a tarball URL with sha256 to a git-based url with tag and revision:
This also requires updating update-formula.yml to resolve the tag to a commit SHA (via git ls-remote) and write the tag/revision fields instead of downloading the tarball and computing a hash.