We’re seeing integrity failures for v3.0.2, which appear to be a result of googlemaps-3.0.2-py3-none-any.whl being uploaded to PyPi on 2019-08-29. Since this upload has occurred quite some time after the actual release, we’d like to verify that the upload was intentional (did it perhaps happen as a result of #296?) and not malicious.
I would not expect new files to be uploaded for a release after-the-fact.
From our Pipfile.lock, expected sha256:
7831f83f565fdf855421a4c6c4760fbfa80496fbf4b80ff7131707e03cd8d9da
e13d8f4101f033bc39d76ade52f99977f077814d79087794735d1bb71f35dcc2
And when installing, Pipenv got instead: 00f4ec8f079b17a8ea304a0b10868f02cb6430b15ce1ffb0068d635930bf1630
We’re seeing integrity failures for v3.0.2, which appear to be a result of
googlemaps-3.0.2-py3-none-any.whlbeing uploaded to PyPi on 2019-08-29. Since this upload has occurred quite some time after the actual release, we’d like to verify that the upload was intentional (did it perhaps happen as a result of #296?) and not malicious.I would not expect new files to be uploaded for a release after-the-fact.
From our
Pipfile.lock, expected sha256:7831f83f565fdf855421a4c6c4760fbfa80496fbf4b80ff7131707e03cd8d9dae13d8f4101f033bc39d76ade52f99977f077814d79087794735d1bb71f35dcc2And when installing, Pipenv got instead:
00f4ec8f079b17a8ea304a0b10868f02cb6430b15ce1ffb0068d635930bf1630