A release focused on a security fix and API evolution. It tightens the Updater() contract and begins preparation for removal of an existing module.
Action needed (1)
securitymediumGHSA-qp9x-wp8f-qgjj fixed
The release fixes GHSA-qp9x-wp8f-qgjj.
Check if affected (1)
breakingThe
Updater()bootstrap argument, now requiredApplies if you use
Updater().In
ngclient,Updater()now requires the namedbootstrapargument. The previous default behavior can be reproduced withbootstrap=None.
Plan ahead (1)
deprecatedPreparation for removal of
securesystemslib.hash Applies if you use
securesystemslib..hash The release prepares for removal of
securesystemslib..hash