Skip to content

Integrity check fails installing v3.0.2 due to recent PyPi upload #303

Description

@andrew-vts

We’re seeing integrity failures for v3.0.2, which appear to be a result of googlemaps-3.0.2-py3-none-any.whl being uploaded to PyPi on 2019-08-29. Since this upload has occurred quite some time after the actual release, we’d like to verify that the upload was intentional (did it perhaps happen as a result of #296?) and not malicious.

I would not expect new files to be uploaded for a release after-the-fact.

From our Pipfile.lock, expected sha256:

  • 7831f83f565fdf855421a4c6c4760fbfa80496fbf4b80ff7131707e03cd8d9da
  • e13d8f4101f033bc39d76ade52f99977f077814d79087794735d1bb71f35dcc2

And when installing, Pipenv got instead: 00f4ec8f079b17a8ea304a0b10868f02cb6430b15ce1ffb0068d635930bf1630

Metadata

Metadata

Assignees

Labels

priority: p0Highest priority. Critical issue. P0 implies highest priority.type: processA process-related concern. May include testing, release, or the like.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions