sigstore/sigstore-python

pin securesystemslib in 2.1.x series

Closed this issue · 1 comments

jku commented

Since the next release is a pretty big API change, it might be safest if we pin securesystemslib in 2.1.x branch already. This was already fixed in main by constraining python-tuf to 4.x (as python-tuf is now more strict about securesystemslib).

See comment in #958 for more detail.

I'll do a PR, we can still discuss if this is needed or not

Agreed and merged in #961, so closing.