Documentation
Could the source release/commit and build provenance be documented for the Windows x64 libtommath.dll supplied with CPython's Tcl/Tk 9.0.4 dependency bundle?
Public artifact references:
The DLL in both repositories has Git blob ID 856af88d7e51af58d705d9b187a0b151880bafee and size 81,408 bytes. It has no file/product version resource. The dynamic x64 makefile copies that prebuilt DLL instead of compiling the adjacent LibTomMath sources, so the neighboring source changelog does not by itself establish the DLL's source revision.
A pointer to the exact upstream release/commit, build recipe/toolchain, and applicable license/notice would make component attribution and advisory-version matching possible without guessing. If this information already exists, could it be linked alongside the binary dependency records?
This is a provenance/documentation request, not a report of a confirmed vulnerability. I am filing here because the binary-dependency repository has issues disabled.
Documentation
Could the source release/commit and build provenance be documented for the Windows x64
libtommath.dllsupplied with CPython's Tcl/Tk 9.0.4 dependency bundle?Public artifact references:
The DLL in both repositories has Git blob ID
856af88d7e51af58d705d9b187a0b151880bafeeand size 81,408 bytes. It has no file/product version resource. The dynamic x64 makefile copies that prebuilt DLL instead of compiling the adjacent LibTomMath sources, so the neighboring source changelog does not by itself establish the DLL's source revision.A pointer to the exact upstream release/commit, build recipe/toolchain, and applicable license/notice would make component attribution and advisory-version matching possible without guessing. If this information already exists, could it be linked alongside the binary dependency records?
This is a provenance/documentation request, not a report of a confirmed vulnerability. I am filing here because the binary-dependency repository has issues disabled.