Proposed updates to Java product versioning policy

Ian Young ian at iay.org.uk
Mon Jun 1 10:32:42 EDT 2015


> On 1 Jun 2015, at 14:54, Cantor, Scott <cantor.2 at osu.edu> wrote:
> 
> On 6/1/15, 6:35 AM, "dev on behalf of Ian Young" <dev-bounces at shibboleth.net on behalf of ian at iay.org.uk> wrote:
> 
>> The thing that has always irked me most about the general model is indeed the third party library stability part. I think adding the rationale for that is a big help, even if I still feel that to some extent we're playing things more cautiously than we need to in some cases (e.g., Spring patch releases).
> 
> As I said, I'm simply articulating what we've done, but that doesn't mean we have to keep doing it.

Understood. I think being clear about this is the only way to find out whether something needs to change. I'm undecided on the latter.

> But we also can't say "plugins will work across minor versions" if we change that.

I understand that if we have no trust that a dependent library really follows semantic versioning then we can't make that guarantee. If we really believed that likely, though, we wouldn't let patch versions of a dependent library into our minor versions either.

>> I'd suggest adding a reference to the third party library section from the second bullet in the Patch Version Compatibility section. It may also be worth thinking about whether we might make exceptions for some projects that have taken the semantic versioning pledge, although I can see that might be hard to explain.
> 
> I think I meant to imply that by saying that we're trying to apply the same API policy to those projects as our own to the extent we can, but I'll review it.

We are stricter, though, at present. That's not unjustifiable, and we do now have a stated rationale for it. I'm just interested in exploring whether we can actually apply the same criteria to *some* other dependencies where we might have some trust.

    -- Ian




-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5250 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/dev/attachments/20150601/de32bca4/attachment-0001.p7s>


More information about the dev mailing list