dennisvang / tufup

Automated updates for stand-alone Python applications.
MIT License
100 stars 2 forks source link

Upgrade to tuf 4.0 (or cap securesystemslib version) #133

Closed jku closed 7 months ago

jku commented 7 months ago

Hi,

I suggest updating your tuf dependency to 4.x:

So ideally python-tuf users make releases that require (or at least allow) tuf 4.x before securesystemslib makes their next release (https://github.com/secure-systems-lab/securesystemslib/pull/767). If you don't want to bump tuf version you could alternatively cap securesystemslib to < 0.32 yourself: this would be the minimal change that should prevent future breakage.

dennisvang commented 7 months ago

@jku Thanks for the warning. I'll have a look at it a.s.a.p.

dennisvang commented 7 months ago

@jku Our latest v0.8.0 release now includes the upgraded tuf 4.0 dependency.

Sorry this took so long, I haven't had much time lately.