theupdateframework / tuf-on-ci

A TUF repository and signing tool
Other
20 stars 11 forks source link

fix tuf dependency version #300

Closed jku closed 3 months ago

jku commented 4 months ago

There's an issue currently:

That PR has not moved because the new features still needed tweaking which happened in tuf 4.0... which is not usable because other reasons related to sigstore compat.

Options:

I think the version bump makes sense

cc @kommendorkapten

jku commented 3 months ago

securesystemslib 1.0 and tuf 5.0 have released. sigstore is likely happening soon (need to wait for that one because of the common dependency on tuf & securesystemslib)

joshuagl commented 3 months ago

Bump to 3.1 makes sense. Any reason that depending on a minor version should be avoided?

jku commented 3 months ago

Yeah bump to 3.1 makes sense.