steveriggins,
@steveriggins@mastodon.social avatar

So yeah you can pin a package manager package to a reference, but that doesn’t pin any dependencies it has.

How are people locking down the entire SPM tree for security purposes?

finestructure,
@finestructure@mastodon.social avatar

@steveriggins Commit your Package.resolved and compile with --disable-automatic-resolution. This will make the build break if there's drift between what the manifest specifies and what resolved has locked in.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • swift
  • DreamBathrooms
  • magazineikmin
  • ethstaker
  • khanakhh
  • rosin
  • Youngstown
  • everett
  • slotface
  • ngwrru68w68
  • mdbf
  • GTA5RPClips
  • kavyap
  • thenastyranch
  • cisconetworking
  • JUstTest
  • cubers
  • Leos
  • InstantRegret
  • Durango
  • tacticalgear
  • tester
  • osvaldo12
  • normalnudes
  • anitta
  • modclub
  • megavids
  • provamag3
  • lostlight
  • All magazines