Skip to content

Conversation

@jku
Copy link
Collaborator

@jku jku commented Sep 24, 2025

Not a lot here but it's been a few months since previous release, doesn't hurt to do a release.

  • There is an open PR for dependency updates but that's for pinned deps: these are not used in the released package
  • Looking at git log, I used way too much "squash and merge" this summer: will avoid that in future unless there's a good reason as it seems to make git archaeology more difficult

Signed-off-by: Jussi Kukkonen <jkukkonen@google.com>
@jku jku requested a review from lukpueh September 24, 2025 08:26
## securesystemslib v1.3.1

### Fixed
* AWSSigner: Don't send payload to AWS for signing, send hash only (#1026)
Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I considered this as a simple bug fix from semver perspective: we should never have sent payloads to AWS.

]
classifiers = [
"Development Status :: 4 - Beta",
"Development Status :: 5 - Production/Stable",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moving to Prod / Stable makes sense given our user base seems quite stable. Any concerns from anyone? I just wanted to flag this for further comment...

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh right, I didn't mention that: I figured this was just forgotten since 1.0 in May 2024 was supposed to mark stability...

@jku jku merged commit 6f77419 into secure-systems-lab:main Sep 26, 2025
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants