Cross-cutting Tip #5

Two packs of one folder are never the same bytes

Pack the same unpacked folder twice and you get two files of the same size and different bytes. Hash the artifact in a pipeline and every run looks like a change.

Pack the same unpacked folder twice and you get two different files. Not different versions - the same version, the same components, the same bytes inside, and a different file on disk.

same1.zip  6632 bytes  sha256 35998096895556804644d0d9
same2.zip  6632 bytes  sha256 dfa77e387980a4d25ef968e3

Same size, different hash. Unzip both and the contents are identical, down to the hashes of every member: the four parts in the container are the same four parts. The difference is the container - the zip’s own metadata - and it moves every time you pack.

This matters the moment a pipeline looks at the artifact rather than at the solution. A step that hashes the zip to detect “did anything change” reports a change on every build. A PR that includes the built package shows a binary diff nobody can review. An artifact cache keyed on the file’s hash misses every time. None of it is a change to your solution, and all of it looks like one.

Compare the thing that carries meaning instead. Diff the unpacked folder - that is text, and it tells you which component moved. If you have to compare two packages, compare them member by member rather than byte by byte, because that is the comparison that answers the question you were asking.

Ship the zip, version the folder.