Racket raco pkg configuration missing a lockfile for reproducible builds
26K reputation · 02 Jul 2024, 11:33 UTC
Racket raco pkg configuration missing a lockfile for reproducible builds
Goal: ensure that a project built with raco pkg installs the exact same package versions on any machine or at any later time.
Constraint: the current deps.rktd format allows version ranges but does not record the resolved versions, and raco pkg has no lockfile mechanism to persist those resolutions.
Uncertainty: without a lockfile, rebuilding may yield different minor or patch releases, potentially breaking reproducibility, while any future lockfile must coexist with existing deps.rktd workflows.
What format should a lockfile adopt? How should raco pkg interact with an existing lockfile during install? Should the tool automatically generate and use a lockfile when present?