# Update on the future stability of source code archives and hashes

DevFeed: [Update on the future stability of source code archives and hashes](<https://devfeed.tech/articles/update-on-the-future-stability-of-source-code-archives-and-hashes-68088.md>)

Original publisher: [Read original article](<https://github.blog/open-source/git/update-on-the-future-stability-of-source-code-archives-and-hashes/>)

Author: Matt Cooper

Published: 2023-02-21T17:00:45Z

Content type: article

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [reproducibility](<https://devfeed.tech/topics/reproducibility.md>), [Git](<https://devfeed.tech/topics/git.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [changelog](<https://devfeed.tech/tags/changelog.md>), [compression](<https://devfeed.tech/tags/compression.md>), [git](<https://devfeed.tech/tags/git.md>), [github](<https://devfeed.tech/tags/github.md>), [open-source](<https://devfeed.tech/tags/open-source.md>)

## AI overview

GitHub explains how a January 2023 change to compression settings for source code downloads altered archive hashes and disrupted systems that depended on stable hashes. It describes commitments to keep tarball and zipball downloads byte-for-byte stable for at least a year, give six months' notice before future format changes, and add testing to detect changes before deployment. For reproducibility, it recommends downloading archives by commit ID; for security-sensitive use, it recommends release assets.

## Source excerpt

A look at what happened on January 30, what measures we're putting in place to prevent surprises, and how we'll handle future changes.