Skip to content

Do not fetch untagged components in a build of a release version of Vix #754

Description

@Kubiyak

Summary

I have disabled the Vix ORM module in my build because its dependency resolution contains an unpinned Git fetch from the mutable main branch.

The relevant code is in:

modules/orm/CMakeLists.txt

if (VIX_ORM_FETCH_VIX_DEPS)
  FetchContent_Declare(vix_src
    GIT_REPOSITORY https://github.com/vixcpp/vix.git
    GIT_TAG main
  )
endif()

I currently build vix at commit 4a858cc

Please support strict versioning and easy bill of materials generation. This is important for libraries which will be used in networrk and security adjacent contexts.

FYI there are other packages as welll which fall into this category in the main Vix core modules.

Vix releases should pin not just the vix head source but all submodules / external libs to a specific release / tag / commit

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesVix Engine issue classificationreleaseRelease preparation, tagging, and version alignmentreproducibilityVix issue classificationtype: bugSomething is broken

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions