So, upstream does indeed provide a URL redirector so we can use a predictable URL scheme without hashes. The new URL scheme is: https://files.pythonhosted.org/packages/source/p/positional/positional-1.1.0.tar.gz Upstream also plans to support the redirector for the long term [0], so I believe switching to it in all the spec files our best move. Maybe it would be beneficial to also work the change into the RPM rebase-helper [1] which does automatic scratch builds when a new version of software is detected upstream? Does anyone have experience with this project? [0] https://bitbucket.org/pypa/pypi/issues/438/backwards-compatible-un-hashed-package#comment-27734791 [1] https://github.com/phracek/rebase-helper -- packaging mailing list packaging@xxxxxxxxxxxxxxxxxxxxxxx http://lists.fedoraproject.org/admin/lists/packaging@xxxxxxxxxxxxxxxxxxxxxxx