mirror of
https://github.com/qelectrotech/qelectrotech-source-mirror.git
synced 2026-10-09 21:54:13 +02:00
Pin fetched dependencies to commit hashes instead of git tags
CMake fetches pugixml, SingleApplication and the three KDE Frameworks modules by git tag. A tag is a mutable pointer that its owner can move, so two builds of the same QElectroTech commit can silently get different third-party sources, and a compromised upstream account can change what every builder downloads without anything changing in this repository. Pinning each dependency to the commit its tag currently points at closes that, while keeping the tag name in a trailing comment so the intended version stays readable. No versions change. Every pinned commit is the one its tag resolves to, checked with git ls-remote and confirmed by fetching each one and verifying that git describe reports exactly the tag. The three KDE modules live in separate repositories and therefore need separate commits, so the single KF_GIT_TAG variable becomes three per-module variables; passing -DKF_GIT_TAG=<ref> still selects one ref for all three, unpinned, exactly as before, and KF_GIT_TAG stays defined so the build summary in define_definitions.cmake is unaffected. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -31,9 +31,11 @@ if(EXISTS "${CMAKE_SOURCE_DIR}/SingleApplication/CMakeLists.txt")
|
||||
set(FETCHCONTENT_SOURCE_DIR_SINGLEAPPLICATION "${CMAKE_SOURCE_DIR}/SingleApplication")
|
||||
endif()
|
||||
|
||||
# Pinned to the commit v3.2.0 points at, not to the tag itself; see the note in
|
||||
# fetch_pugixml.cmake.
|
||||
FetchContent_Declare(
|
||||
SingleApplication
|
||||
GIT_REPOSITORY https://github.com/itay-grudev/SingleApplication.git
|
||||
GIT_TAG v3.2.0)
|
||||
GIT_TAG aede311d28d20179216c5419b581087be2a8409f) # v3.2.0
|
||||
set(QT_DEFAULT_MAJOR_VERSION 6)
|
||||
FetchContent_MakeAvailable(SingleApplication)
|
||||
|
||||
Reference in New Issue
Block a user