A pinned archive checksum fails when a dependency's tag now comes from another repository
Symptom#
Every wheel job stops at the dependency fetch step with a SHA-256 mismatch for one dependency, right after its source URL moved to another host, with the same tag name (v0.0.8).
Cause#
A tag name is not a commit. The same tag in the new repository (github.com/llnl-asr/cpp-logger) pointed at a different commit (31753df) than in the old internal GitLab, so the archive and its hash differ.
Fix#
Build the archive locally from the new source, check that its hash equals the "actual" hash CI printed, and put that hash in the manifest (dependency/source/manifest.txt in dftracer, commit fa09659); then run the verifier (scripts/wheel/fetch_deps.sh --verify). Confirm the new tag holds the same code as the old one, or pin a commit instead of a tag.
Evidence#
dftracer PR 388 CI: the local archive hash equalled CI's actual hash 234f78f6…483b, and fetch_deps.sh --verify passed for all 5 dependencies. Whether the GitHub v0.0.8 holds the same code as the GitLab tag was not checked.