<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Luiz Fernando Nunes da Silva</title>
    <description>The latest articles on DEV Community by Luiz Fernando Nunes da Silva (@luiz_fernandonunesdasi).</description>
    <link>https://dev.to/luiz_fernandonunesdasi</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4171701%2F90a652e0-3989-4c94-bc3b-19585d13f724.jpg</url>
      <title>DEV Community: Luiz Fernando Nunes da Silva</title>
      <link>https://dev.to/luiz_fernandonunesdasi</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/luiz_fernandonunesdasi"/>
    <language>en</language>
    <item>
      <title>A git tag is not a release: requests v2.16.1 declares 2.16.0</title>
      <dc:creator>Luiz Fernando Nunes da Silva</dc:creator>
      <pubDate>Sat, 10 Oct 2026 00:05:57 +0000</pubDate>
      <link>https://dev.to/luiz_fernandonunesdasi/a-git-tag-is-not-a-release-requests-v2161-declares-2160-1gip</link>
      <guid>https://dev.to/luiz_fernandonunesdasi/a-git-tag-is-not-a-release-requests-v2161-declares-2160-1gip</guid>
      <description>&lt;p&gt;In psf/requests, the tag &lt;code&gt;v2.16.1&lt;/code&gt; points at code whose &lt;code&gt;__version__.py&lt;/code&gt; says &lt;code&gt;2.16.0&lt;/code&gt;. The tag &lt;code&gt;v2.16.0&lt;/code&gt; says the same, and the code differs between them.&lt;/p&gt;

&lt;p&gt;Check it in 30 seconds, nothing to install:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-sO&lt;/span&gt; https://raw.githubusercontent.com/luizfnsilva/closure_drift/v1.1.0/closure_drift.py
git clone &lt;span class="nt"&gt;-q&lt;/span&gt; https://github.com/psf/requests &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;cd &lt;/span&gt;requests
python3 ../closure_drift.py &lt;span class="nt"&gt;--compare&lt;/span&gt; v2.16.0 v2.16.1
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;DIFFERS UNDER ONE LABEL: both declare 2.16.0, and the code differs
in 2 path(s). If both were published, that label names two things.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Or without the tool, with plain git:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git show v2.16.1:requests/__version__.py | &lt;span class="nb"&gt;grep &lt;/span&gt;__version__
&lt;span class="c"&gt;# __version__ = '2.16.0'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The two paths are a fix to how urllib3's version is parsed and a restored module. The tag was cut before the version was bumped. That is common, not a verdict on requests: among the 100 most-downloaded PyPI projects with a public repository, 29 have at least one version label that names two code states.&lt;/p&gt;

&lt;h2&gt;
  
  
  What a tag does not tell you
&lt;/h2&gt;

&lt;p&gt;A tag is not a release. The tool reads git, so it cannot see which commit a package on PyPI was built from. Two people outside the project showed me where that matters. In ruff, &lt;code&gt;v0.0.268&lt;/code&gt; was tagged and never published. In openai-python, the 0.26.5 on PyPI was built from the commit after the tag.&lt;/p&gt;

&lt;p&gt;closure_drift 1.1.0 lets you say which versions were released. Give it a file with one version per line, from your release notes or your registry:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;closure-drift &lt;span class="nt"&gt;--published&lt;/span&gt; released.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Only tags on the list are compared. A tag left off is left out of the analysis. The tool never calls it unpublished, because it still reads only git.&lt;/p&gt;

&lt;p&gt;Then run it in your own repository:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;python3 closure_drift.py
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;One file, no dependencies, read-only. Source and method: &lt;a href="https://github.com/luizfnsilva/closure_drift" rel="noopener noreferrer"&gt;https://github.com/luizfnsilva/closure_drift&lt;/a&gt; (DOI &lt;a href="https://doi.org/10.5281/zenodo.23271569" rel="noopener noreferrer"&gt;10.5281/zenodo.23271569&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Written with AI assistance; every command and number above was run and checked.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>git</category>
      <category>python</category>
      <category>opensource</category>
      <category>devops</category>
    </item>
    <item>
      <title>29 of the 100 most-downloaded PyPI projects have a version that names two different code states</title>
      <dc:creator>Luiz Fernando Nunes da Silva</dc:creator>
      <pubDate>Thu, 08 Oct 2026 15:50:02 +0000</pubDate>
      <link>https://dev.to/luiz_fernandonunesdasi/29-of-the-100-most-downloaded-pypi-projects-have-a-version-that-names-two-different-code-states-fof</link>
      <guid>https://dev.to/luiz_fernandonunesdasi/29-of-the-100-most-downloaded-pypi-projects-have-a-version-that-names-two-different-code-states-fof</guid>
      <description>&lt;p&gt;A version number is a string a human edits. When two release tags declare the same version and the code differs, one address now points to two artefacts. Nothing notices, because the version is all anyone recorded.&lt;/p&gt;

&lt;p&gt;I wanted to know how often this happens, so I built a small tool to check it and ran it on the 100 most-downloaded PyPI projects with a public repository. The method was fixed before the first run, and no project was tuned.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;result&lt;/th&gt;
&lt;th&gt;repositories&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;every version names one code state&lt;/td&gt;
&lt;td&gt;59&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;at least one version names two&lt;/td&gt;
&lt;td&gt;29&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;not enough tags compared&lt;/td&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;no version found, or inconclusive&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Every collision is listed and can be checked by hand. In requests:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;$ closure-drift --compare v2.16.0 v2.16.1
DIFFERS UNDER ONE LABEL: both declare 2.16.0, and the code differs in 2 path(s).
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Why it happens
&lt;/h2&gt;

&lt;p&gt;Mostly not carelessness. A tag created before the version was bumped, branch markers such as &lt;code&gt;7.x&lt;/code&gt;, and monorepos where several tag families share one version file. I asked the maintainers of three projects about their cases; all three confirmed what the tool measured.&lt;/p&gt;

&lt;h2&gt;
  
  
  Checking your own repository
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;pipx &lt;span class="nb"&gt;install &lt;/span&gt;git+https://github.com/luizfnsilva/closure_drift@v1.0.0
closure-drift            &lt;span class="c"&gt;# inside any git repository&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It is one file, standard library only, read-only, no network. Exit 0 means clean, 1 means drift, 2 means it could not tell, and the report says why. To stop it before it happens, &lt;code&gt;--would-tag&lt;/code&gt; checks a commit before you tag it, and runs as a GitHub Action or a pre-commit hook.&lt;/p&gt;

&lt;p&gt;The full study, the method and every collision: &lt;a href="https://github.com/luizfnsilva/closure_drift" rel="noopener noreferrer"&gt;https://github.com/luizfnsilva/closure_drift&lt;/a&gt;&lt;/p&gt;

</description>
      <category>python</category>
      <category>git</category>
      <category>devops</category>
      <category>opensource</category>
    </item>
  </channel>
</rss>
