The stable SDK 8 line on release/8.x embeds AdCP 3.2.1. Update it to the signed AdCP 3.2.3 maintenance release after that protocol release publishes.
The audited-release pin checker currently accepts only the upstream main certificate identity, so it rejects stable 3.2 bundles signed by release.yml@refs/heads/3.2.x. Permit that exact identity only for stable 3.2 pins, retain exact audited URLs/digests and Sigstore transparency verification, and add tests rejecting unrelated branches and mismatched release lines.
After publication, audit the protocol tag and signed tuple, add the reviewed 3.2.3 release pin, regenerate the schema/model/compliance assets, validate wheel/sdist inclusion and compatibility, and use the existing stable Release Please/PyPI flow. Keep Python 9 on its separate beta line.
Work is already in progress; no-triage avoids a duplicate implementation.
The stable SDK 8 line on
release/8.xembeds AdCP 3.2.1. Update it to the signed AdCP 3.2.3 maintenance release after that protocol release publishes.The audited-release pin checker currently accepts only the upstream
maincertificate identity, so it rejects stable 3.2 bundles signed byrelease.yml@refs/heads/3.2.x. Permit that exact identity only for stable 3.2 pins, retain exact audited URLs/digests and Sigstore transparency verification, and add tests rejecting unrelated branches and mismatched release lines.After publication, audit the protocol tag and signed tuple, add the reviewed 3.2.3 release pin, regenerate the schema/model/compliance assets, validate wheel/sdist inclusion and compatibility, and use the existing stable Release Please/PyPI flow. Keep Python 9 on its separate beta line.
Work is already in progress;
no-triageavoids a duplicate implementation.