Skip to content

Clarify supported 0.9.x versions and release provenance #2238

Description

@crisuoksa-ship-it

Hello,

We are evaluating graphifyy==0.9.27 for a read-only, offline advisory
architecture index and pinning its source exactly. Before treating the pin as
supported upstream evidence, could you clarify two release-policy points?

Observed on the current v8 branch and tag refs:

  • pyproject.toml has advanced to version 0.9.28.
  • SECURITY.md lists 0.3.x as supported and <0.3 as unsupported, but does
    not mention 0.9.x.
  • refs/tags/v0.9.27 resolves directly to commit
    f5a3592882ad54e5394c5cd5391786a589110bd1; Git therefore exposes no
    annotated tag object or tag signature for that release.

Questions:

  1. Which 0.9.x releases are currently supported for security fixes, and is
    graphifyy==0.9.27 still within that range? Would you consider updating
    SECURITY.md to state the supported 0.9 release range?
  2. Is commit f5a3592882ad54e5394c5cd5391786a589110bd1 the intended canonical
    source for 0.9.27?
  3. Is there an immutable release digest, signed tag/attestation, or other
    provenance record consumers should verify for 0.9.27?

This is a policy/provenance clarification, not a vulnerability report and not
a request to activate any integration. Thank you.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions