Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document stability policy #254

Closed
dlorenc opened this issue Apr 14, 2021 · 3 comments
Closed

Document stability policy #254

dlorenc opened this issue Apr 14, 2021 · 3 comments

Comments

@dlorenc
Copy link
Member

dlorenc commented Apr 14, 2021

Until we get to 1.0:

  • cosign signatures should be interoperable between +/- one release. SIgnatures created with version X should be verifiable by versions X+1 and X-1, and vice versa.
  • Experimental is completely up in the air

After 1.0:

  • Signatures should always remain interoperable. We can add new formats if we want to, but old ones have to continue working and new versions of the tool need to support creating AND verifying old formats.
@dlorenc dlorenc mentioned this issue Apr 20, 2021
5 tasks
@dekkagaijin
Copy link
Member

cosign signatures should be interoperable between +/- one release. SIgnatures created with version X should be verifiable by versions X+1 and X-1, and vice versa.

Since we know where cosign is being used right now, we're opting for a clean break for 0.4.0: sigs before and sigs after. This should be the last change made in such a way.

@dlorenc
Copy link
Member Author

dlorenc commented May 4, 2021

+1, we'd document/publish this policy as part of the 0.5.0 release

@dlorenc
Copy link
Member Author

dlorenc commented Feb 21, 2022

This is done!

@dlorenc dlorenc closed this as completed Feb 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants