From 7ec13cbc1a5b970c4c7f6d13c39e7d2ae7314c95 Mon Sep 17 00:00:00 2001 From: Beat Hangartner Date: Sat, 19 Sep 2026 23:05:39 +0200 Subject: [PATCH] Pin fetched dependencies to commit hashes instead of git tags CMake fetches pugixml, SingleApplication and the three KDE Frameworks modules by git tag. A tag is a mutable pointer that its owner can move, so two builds of the same QElectroTech commit can silently get different third-party sources, and a compromised upstream account can change what every builder downloads without anything changing in this repository. Pinning each dependency to the commit its tag currently points at closes that, while keeping the tag name in a trailing comment so the intended version stays readable. No versions change. Every pinned commit is the one its tag resolves to, checked with git ls-remote and confirmed by fetching each one and verifying that git describe reports exactly the tag. The three KDE modules live in separate repositories and therefore need separate commits, so the single KF_GIT_TAG variable becomes three per-module variables; passing -DKF_GIT_TAG= still selects one ref for all three, unpinned, exactly as before, and KF_GIT_TAG stays defined so the build summary in define_definitions.cmake is unaffected. Co-Authored-By: Claude Opus 5 (1M context) --- cmake/fetch_kdeaddons.cmake | 24 +++++++++++++++++++----- cmake/fetch_pugixml.cmake | 5 ++++- cmake/fetch_singleapplication.cmake | 4 +++- 3 files changed, 26 insertions(+), 7 deletions(-) diff --git a/cmake/fetch_kdeaddons.cmake b/cmake/fetch_kdeaddons.cmake index 76df0a3f4..7ba66392c 100644 --- a/cmake/fetch_kdeaddons.cmake +++ b/cmake/fetch_kdeaddons.cmake @@ -23,8 +23,22 @@ if(BUILD_WITH_KF) if(BUILD_KF) - if(NOT DEFINED KF_GIT_TAG) - # this is a more or less random version, taken as an conservative approach + # v6.10.0 is a more or less random version, taken as an conservative + # approach. Pinned to the commits those tags point at, not to the tags + # themselves; see the note in fetch_pugixml.cmake. Each module lives in its + # own repository, so the same release is a different commit in each. + set(KF_ECM_GIT_COMMIT 7dd28cc56c339c3f8fb356f7c53c0e8f61433d81) # v6.10.0 + set(KF_KCOREADDONS_GIT_COMMIT c569f974dab24b4784ad186a3db4b76b2fa36612) # v6.10.0 + set(KF_KWIDGETSADDONS_GIT_COMMIT 1abbed8a280d6626c59fb197f2c4667d2b1e7445) # v6.10.0 + + if(DEFINED KF_GIT_TAG) + # Explicit override: -DKF_GIT_TAG= selects one ref for all three + # modules, unpinned, exactly as it did before. + set(KF_ECM_GIT_COMMIT ${KF_GIT_TAG}) + set(KF_KCOREADDONS_GIT_COMMIT ${KF_GIT_TAG}) + set(KF_KWIDGETSADDONS_GIT_COMMIT ${KF_GIT_TAG}) + else() + # Keep KF_GIT_TAG defined: define_definitions.cmake reports it. set(KF_GIT_TAG v6.10.0) endif() # using a function in order to limit the scope of the variables @@ -53,19 +67,19 @@ if(BUILD_WITH_KF) FetchContent_Declare( ecm GIT_REPOSITORY https://invent.kde.org/frameworks/extra-cmake-modules.git - GIT_TAG ${KF_GIT_TAG}) + GIT_TAG ${KF_ECM_GIT_COMMIT}) FetchContent_MakeAvailable(ecm) FetchContent_Declare( kcoreaddons GIT_REPOSITORY https://invent.kde.org/frameworks/kcoreaddons.git - GIT_TAG ${KF_GIT_TAG}) + GIT_TAG ${KF_KCOREADDONS_GIT_COMMIT}) FetchContent_MakeAvailable(kcoreaddons) FetchContent_Declare( kwidgetsaddons GIT_REPOSITORY https://invent.kde.org/frameworks/kwidgetsaddons.git - GIT_TAG ${KF_GIT_TAG}) + GIT_TAG ${KF_KWIDGETSADDONS_GIT_COMMIT}) FetchContent_MakeAvailable(kwidgetsaddons) endfunction() qet_make_kf_available() diff --git a/cmake/fetch_pugixml.cmake b/cmake/fetch_pugixml.cmake index 6aef219f7..11bf33872 100644 --- a/cmake/fetch_pugixml.cmake +++ b/cmake/fetch_pugixml.cmake @@ -22,10 +22,13 @@ option(BUILD_PUGIXML "Build pugixml library, use system one otherwise" YES) if(BUILD_PUGIXML) + # Pinned to the commit v1.15 points at, not to the tag itself: a tag is a + # mutable pointer that the upstream owner can move, so fetching by tag means + # a future build can silently get different code than this one did. FetchContent_Declare( pugixml GIT_REPOSITORY https://github.com/zeux/pugixml.git - GIT_TAG v1.15) + GIT_TAG ee86beb30e4973f5feffe3ce63bfa4fbadf72f38) # v1.15 set(PUGIXML_INSTALL OFF CACHE INTERNAL "") FetchContent_MakeAvailable(pugixml) else() diff --git a/cmake/fetch_singleapplication.cmake b/cmake/fetch_singleapplication.cmake index c54de59ef..8685eea43 100644 --- a/cmake/fetch_singleapplication.cmake +++ b/cmake/fetch_singleapplication.cmake @@ -31,9 +31,11 @@ if(EXISTS "${CMAKE_SOURCE_DIR}/SingleApplication/CMakeLists.txt") set(FETCHCONTENT_SOURCE_DIR_SINGLEAPPLICATION "${CMAKE_SOURCE_DIR}/SingleApplication") endif() +# Pinned to the commit v3.2.0 points at, not to the tag itself; see the note in +# fetch_pugixml.cmake. FetchContent_Declare( SingleApplication GIT_REPOSITORY https://github.com/itay-grudev/SingleApplication.git - GIT_TAG v3.2.0) + GIT_TAG aede311d28d20179216c5419b581087be2a8409f) # v3.2.0 set(QT_DEFAULT_MAJOR_VERSION 6) FetchContent_MakeAvailable(SingleApplication)