Semver Violation: Breaking CLI Changes in Patch Release 3.0.3 #4575
lorenzo-milicia
started this conversation in
General
Replies: 1 comment 1 reply
-
|
Sorry for the confusion. This was done not as a semver violation but as a bug fix, as that flag value was being ignored under a new v3 code path. The error message provides other flags you can use. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello maintainers,
I'd like to raise a concern regarding semver practices in the recent releases. Upgrading from v3.0.2 to v3.0.3 breaks the previously valid command:
cosign sign --tlog-upload=false --key <key> <image>This now throws:
Such breaking changes should not occur in a patch release. More generally, "stable" v3.x.x tags should reflect production readiness, but the series still has notable inconsistencies and incomplete implementations.
Please reconsider how CLI deprecations and semver guarantees are managed for the project's stability and reliability in production pipelines.
Beta Was this translation helpful? Give feedback.
All reactions