A version number is a string a human edits. When two release tags declare the same version and the code differs, one address now points to two artefacts. Nothing notices, because the version is all anyone recorded.
I wanted to know how often this happens, so I built a small tool to check it and ran it on the 100 most-downloaded PyPI projects with a public repository. The method was fixed before the first run, and no project was tuned.
| result | repositories |
|---|---|
| every version names one code state | 59 |
| at least one version names two | 29 |
| not enough tags compared | 4 |
| no version found, or inconclusive | 8 |
Every collision is listed and can be checked by hand. In requests:
$ closure-drift --compare v2.16.0 v2.16.1
DIFFERS UNDER ONE LABEL: both declare 2.16.0, and the code differs in 2 path(s).
Why it happens
Mostly not carelessness. A tag created before the version was bumped, branch markers such as 7.x, and monorepos where several tag families share one version file. I asked the maintainers of three projects about their cases; all three confirmed what the tool measured.
Checking your own repository
pipx install git+https://github.com/luizfnsilva/closure_drift@v1.0.0
closure-drift # inside any git repository
It is one file, standard library only, read-only, no network. Exit 0 means clean, 1 means drift, 2 means it could not tell, and the report says why. To stop it before it happens, --would-tag checks a commit before you tag it, and runs as a GitHub Action or a pre-commit hook.
The full study, the method and every collision: https://github.com/luizfnsilva/closure_drift
Top comments (0)