NuGet/Home

Use a deterministic order for files when calculating psmdcp hash

已關閉

#14,916 建立於 2026年5月23日

 (0 則留言) (0 個反應) (0 位負責人)HTML (292 個分叉)batch import
Functionality:PackPriority:2Type:Featurehelp wanted

倉庫指標

星標
 (1,459 顆星)
PR 合併指標
 (平均合併 464天 23小時) (30 天內合併 1 個 PR)

描述

NuGet Product(s) Involved

dotnet.exe

The Elevator Pitch

With reproducible builds, software can become more trustworthy, transparent and secure. It becomes easier to verify that binaries have not been tampered with it, and easier to identify some types of security attacks.

As part of that, it would be great if nupkgs were fully reproducible.

One current area of non-reproducibility, missed in https://github.com/NuGet/Home/issues/14448, is the order of files used to generate the psmdcp hash in PackageBuilder .

NuGet.Client's PackageBuilder.CalcPsmdcpName relies on the order the files defined in the manifest. The order is non-deterministic when file globs are used (example). We should make this order well-defined.

Additional Context and Details

Relates to https://github.com/dotnet/source-build/issues/4963

貢獻者指南