Skip to content

pin sigstore-python version used in custom_test#391

Open
bobcallaway wants to merge 1 commit into
sigstore:mainfrom
bobcallaway:pin_sigstore
Open

pin sigstore-python version used in custom_test#391
bobcallaway wants to merge 1 commit into
sigstore:mainfrom
bobcallaway:pin_sigstore

Conversation

@bobcallaway

Copy link
Copy Markdown
Member

this ensures we get a consistent resolution of all transitive deps

Signed-off-by: Bob Callaway <bcallaway@google.com>
@bobcallaway bobcallaway requested a review from jku April 8, 2026 01:23
@jku

jku commented Apr 9, 2026

Copy link
Copy Markdown
Member

Yeah, I don't object to the idea... but then we also need dependabot to ensure we test the latest release and that likely means dealing with the constant flood of dependency updates.

There is an argument to be made that sigstore-python (the CLI) should act like a real application and should pin dependencies so that users don't have to... but sigstore-python is also a library that should not pin dependencies so we'd have to start doing two separate releases to implement that.

@jku jku changed the title pin sigstore version used in custom_test pin sigstore-python version used in custom_test Apr 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants