Repository navigation
Decide on Python version #1125
Description
Activity
- addeddiscussionDiscussions related to the design, implementation and operation of the projectDiscussions related to the design, implementation and operation of the project
on Sep 10, 2020 I absolutely agree with killing 2.x with fire but I think this "we will continue to support [current implementation] for a while" part probably needs to be quite explicit -- in practice the first step should be very prominent python2 support deprecation with at least an estimated timeline.
The reason I'm saying this is https://pypistats.org/packages/tuf: pypistats may not be that reliable but it's one of the few usage indicators available... and it looks pretty bad for tuf, much worse than most distributions: 50% of the downloads are for python 2.
Reacted by Lukas Pühringer and Joshua Lock- addeddocumentationDocumentation of the project as well as procedural documentationDocumentation of the project as well as procedural documentation
on Sep 10, 2020 - addeddecision recordOutcome of this discussion should be tracked in a decision recordOutcome of this discussion should be tracked in a decision recordand removeddecision recordOutcome of this discussion should be tracked in a decision recordOutcome of this discussion should be tracked in a decision record
on Sep 10, 2020 Datadog still needs temporary support for Python 2 at least, IIRC cc @ofek @FlorianVeaux
Yes, but we are fine with pinning as long as security fixes are backported.
Reacted by Trishank Karthik Kuppusamy and Florian VeauxDatadog still needs temporary support for Python 2 at least, IIRC cc @ofek @FlorianVeaux
Can you help quantify "temporary support"? We don't really have the engineering resources on the project to support multiple versions of the codebase. Back-porting security fixes won't be very straightforward if we rearchitect the internals as has been proposed.
I'd rather avoid Python2.7 entirely, but it may be possible to get the Python 3.x features we want on a 2.7 supporting codebase by using additional dependencies. i.e. typing is available for Python 2.7.
Of course, the danger there is that we don't know how long our dependencies will continue to support an EOL version of Python.Reacted by Lukas Pühringer, Trishank Karthik Kuppusamy and Martin VrachevTemporary means a while 😅
We're one user, please do what you wish and do not block on us. We will be fine.
Reacted by Florian Veaux, Lukas Pühringer and Trishank Karthik KuppusamyIncidentally Python 3.5 is End-Of-Life since yesterday
Reacted by Joshua Lock and Trishank Karthik Kuppusamy- added 3 commits that reference this issue
on Oct 21, 2020 Note also that pip (the program) are dropping support for Python 2.7 in January 2021: https://pip.pypa.io/en/latest/development/release-process/#python-2-support
Reacted by Trishank Karthik KuppusamyReacted by Trishank Karthik Kuppusamy- added a commit that references this issue
on Oct 26, 2020 Another worthwhile item of note is that pyca/cryptography are intending to drop support for Python 2.7 sometime around December 2020 /January 2021 (see pyca/cryptography#5359)
- added a commit that references this issue
on Oct 28, 2020 When and how we are going to drop support for python versions < 3.6?
We can easily submit a pr today to do that, but how we are going to announce it to our users, and how much time we will give them to update to a newer version?I am not sure if there are other users than DataDog that use python < 3.6, but still if there are?
Good question. Per the ADR, we plan to write new code targeting Python 3.6+ only.
Thus, implicitly, the refactored codebase which will eventually be released as version 1.0 will be Python 3.6+ only.Given that Python 2.7 and 3.5 are both EOL, I hope the number of users is low. However, we are discussing how best, and how long, to support prior versions of the code (supporting older Python versions) in #1127
- added a commit that references this issue
on Nov 3, 2020
Description of issue or feature request:
Decide which Python versions we want to support in TUF 1.0.0.
Arguments for > 3.5:
Current behavior:
setup.pyandtests)Expected behavior:
TBD