[ 
https://issues.apache.org/jira/browse/THRIFT-5218?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17279124#comment-17279124
 ] 

Christopher Tubbs commented on THRIFT-5218:
-------------------------------------------

[~hukeping] - the archive on GitHub that you are pointing to is automatically 
generated by GitHub, and has nothing to do with the artifacts provided by the 
Apache Thrift PMC that they have officially voted on and released and published 
with links on https://thrift.apache.org

For what it's worth, you can use GitHub's archive mechanism to get *any* git 
commit as a tarball, whether it's a branch name, a tag name, or a sha1. These 
won't necessarily even match each other, because of differences in timestamp, 
compression, or other archive metadata.

https://github.com/apache/thrift/archive/518163afbd7c4f6733d12fa6f2de3db612fda947.tar.gz
https://github.com/apache/thrift/archive/master.tar.gz

This is a GitHub feature that has nothing to do with official releases. This 
issue should be closed, since there is no problem here. Trust the checksums 
provided by the Thrift PMC on their website only, and use the links there to 
download the release artifacts.

> Automated Github release artifacts do not match checksums provided
> ------------------------------------------------------------------
>
>                 Key: THRIFT-5218
>                 URL: https://issues.apache.org/jira/browse/THRIFT-5218
>             Project: Thrift
>          Issue Type: Question
>          Components: Build Process
>            Reporter: Hu Keping
>            Assignee: Jens Geyer
>            Priority: Major
>             Fix For: 0.14.0
>
>
> The released tarball from apache.com and github.com/apache are different, 
> which one should I trust and use?
>  
> [https://github.com/apache/thrift/archive/v0.13.0.tar.gz]
> [http://www.apache.org/dyn/closer.cgi?path=/thrift/0.13.0/thrift-0.13.0.tar.gz]
>  
> MD5SUM of these two tarball:
> 38a27d391a2b03214b444cb13d5664f1 thrift-0.13.0.tar.gz
>  d03a4582a947bf932f30a2c9ea2a9c00 v0.13.0.tar.gz



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to