Better document versioning expectations for Secure analyzers
Proposal
As discussed in the epic our versioning process is quite simplistic for our analyzers. We should improve this to better support our goals of pinning to minor versions within our templates while resolving edgecases.
Questions
- Do we bump analyzer versions for data changes or only API changes?
- What warrants a breaking change?
- How should we git tag release versions (revisions?)
Links
- Epic discussion: &4060 (comment 505359594)
- Current versioning guidelines https://gitlab.com/gitlab-org/security-products/analyzers/common#versioning-and-release-process
- SemVer guidelines https://semver.org/
Edited by Lucas Charles