Results 268 comments of Joshua Lock
trafficstars

> Related to the future of the build track -- while I still support a view that it can be worded to ensuring a complete provenance, there is still a...

Zack already linked to the description of how [we handle testing in python-tuf](https://theupdateframework.github.io/python-tuf/2022/06/15/testing-ngclient.html). I also want to point out the [repository-editor-for-tuf](https://github.com/vmware-labs/repository-editor-for-tuf), which we've found to be a useful tool for...

Is opening a Pull Request considered simple enough for submitting adoptions? We could use a [data file](https://jekyllrb.com/docs/datafiles/) and allow people to submit details as a PR to the data file.

I think we should aim to have a patch release soon. We could include: - #892 - #882 - #905 What other changes should we consider?

> If VSA is part of this release, it would be useful to resolve other VSA issues - at least those we consider blocking and / or a that resolving...

Good tip. Done, thanks.

Almost two years later !? 🙊 I've managed to add some more text in an attempt to address @trishankatdatadog's concerns. I rebased on the latest changes and updated version and...

I'd love to get this PR off my backlog, any chance of some reviews @trishankatdatadog, @mnm678 and @lukpueh ?

Collecting some possible terms | style | collection | key | value | key-value pair | | -- | -- | -- | -- | -- | (current) JSON-ish |...

Great question. I think Mark's statement still holds, that tools probably should declare the version of the verification logic they are implementing. But I don't think we need to address...