theupdateframework / theupdateframework/taps
Introduce a status for approved/accepted TAPs that are not intended to make it into the core specification
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 37
- Forks
- 23
- PR merge metrics
- No merged PRs in 30d
Description
In the most recent community meeting there was a sidebar discussion on the complexity of implementing TUF and how several TAPs (specifically TAP 4 and TAP 8) increase complexity for optional features.
As part of the discussion I proposed that we add an additional TAP status, or update the accepted status, to include a notion of a TAP which is reviewed and approved but, due to its optional nature, is considered supplementary to the specification and is not destined to become a part of the core specification document.
During the discussion the following pros and cons were discussed:
Pros
- implementation simplicity and safety for those only interested in the core TUF functionality of today
Cons
- confusion in how implementations/adoptions communicate which combination of TUF + TAPs are implemented
- this potentially makes it harder to find a TUF implementation which suits all of an adopters needs
- testing combinations of features is harder
- unclear what this means for the reference implementation(s)
FWIW some of these cons (i.e., compatibility across implementations, lack of clarity around what exactly a TUF implementation implements) already exist today.
Filing this issue as a place to continue this discussion.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the community-meeting context and the discussion of TAP 4 and TAP 8. Compare the proposed additional status or accepted-status update with the listed implementation, compatibility, testing, and reference-implementation concerns; done would be a documented decision on whether and how such a status should be defined.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100