
Preferably use the above download link, not the below links to download the source tarball, as the release tarballs are generated deterministically whereas GitHub's are not.
But all links are above. The rewording is required.
cc: @laanwj
Preferably a wording that does not depend on the GitHub UI should be picked
Edit: Changed it to "Preferably use the above download link, not the links provided by GitHub to download the source tarball, as the release tarballs are generated deterministically whereas GitHub's are not." Sounds better?
Can we close this issue since it is fixed?
FYI, the Github release tarballs are now deterministic. The problem was fixed some years ago, it was caused by a bug in git archive. Reference answer by @eli-schwartz: https://lists.reproducible-builds.org/pipermail/rb-general/2021-October/002422.html
To avoid confusion for users, what about removing the wrong statement and simply have Preferably use the above download link, not the below links to download the source tarball?
Changed to
Preferably use the above download link, not the links provided by GitHub to download the source tarball. The release tarballs are generated deterministically and signed whereas GitHub's are not.
Thanks @MarcoFalke that's a clear and useful improvement.
We may even be more direct:
Do not use the links provided by GitHub below, rather use the above download links, they are guaranteed to be generated deterministically and signed.
Thanks, switched to that.
Thanks.