Hello,
We are evaluating graphifyy==0.9.27 for a read-only, offline advisory
architecture index and pinning its source exactly. Before treating the pin as
supported upstream evidence, could you clarify two release-policy points?
Observed on the current v8 branch and tag refs:
pyproject.toml has advanced to version 0.9.28.
SECURITY.md lists 0.3.x as supported and <0.3 as unsupported, but does
not mention 0.9.x.
refs/tags/v0.9.27 resolves directly to commit
f5a3592882ad54e5394c5cd5391786a589110bd1; Git therefore exposes no
annotated tag object or tag signature for that release.
Questions:
- Which
0.9.x releases are currently supported for security fixes, and is
graphifyy==0.9.27 still within that range? Would you consider updating
SECURITY.md to state the supported 0.9 release range?
- Is commit
f5a3592882ad54e5394c5cd5391786a589110bd1 the intended canonical
source for 0.9.27?
- Is there an immutable release digest, signed tag/attestation, or other
provenance record consumers should verify for 0.9.27?
This is a policy/provenance clarification, not a vulnerability report and not
a request to activate any integration. Thank you.
Hello,
We are evaluating
graphifyy==0.9.27for a read-only, offline advisoryarchitecture index and pinning its source exactly. Before treating the pin as
supported upstream evidence, could you clarify two release-policy points?
Observed on the current
v8branch and tag refs:pyproject.tomlhas advanced to version0.9.28.SECURITY.mdlists0.3.xas supported and<0.3as unsupported, but doesnot mention
0.9.x.refs/tags/v0.9.27resolves directly to commitf5a3592882ad54e5394c5cd5391786a589110bd1; Git therefore exposes noannotated tag object or tag signature for that release.
Questions:
0.9.xreleases are currently supported for security fixes, and isgraphifyy==0.9.27still within that range? Would you consider updatingSECURITY.mdto state the supported 0.9 release range?f5a3592882ad54e5394c5cd5391786a589110bd1the intended canonicalsource for 0.9.27?
provenance record consumers should verify for 0.9.27?
This is a policy/provenance clarification, not a vulnerability report and not
a request to activate any integration. Thank you.