If either a package or dependency fails validation, the whole repository is added to the list of invalid sources.
If that happens everything a repository has to offer is unavailable, not just the one dep/pkg which is not valid. This may have unwanted heavy consequences.
If either a package or dependency fails validation, the whole repository is added to the list of invalid sources.
If that happens everything a repository has to offer is unavailable, not just the one dep/pkg which is not valid. This may have unwanted heavy consequences.
Dependency
https://github.com/wbond/package_control/blob/8b947d227bfee2b514283e650c3f88c954ae1026/package_control/providers/repository_provider.py#L344-L351
Package
https://github.com/wbond/package_control/blob/8b947d227bfee2b514283e650c3f88c954ae1026/package_control/providers/repository_provider.py#L632-L639