Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Examples: ship bootstrap root.jsons for well-known repositories

Offen
#2,206 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 10 Tagen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
45/100
Issue-Typ
Feature
Klarheit
Größtenteils klar
Aktivitätsstatus
Veraltet
Tech-Stack
python
Bereich
security

Rechercherichtung

Beginne bei der Initialisierung des Repository-Caches im Client-Beispiel und überprüfe den bestehenden TOFU-Ablauf, der in #2193 beschrieben ist. Füge versteckte bootstrap root.json-Dateien für die genannten Repositories hinzu und sorge dafür, dass ein leerer Cache das passende bootstrap root verwendet; verifiziere, dass das Beispiel ohne TOFU funktioniert, und behandle #1168 als Folgearbeit.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

In #2193 the client example gains Trust-On-First-Use (TOFU) functionality and support for arbitrary repositories. This is very useful for testing but has two issues:

  • we should also be an example of not using TOFU (and shipping the bootstrap root metadata) whenever possible
  • some known repositories have old root metadata that the client is incompatible with: This breaks the TOFU approach. We could workaround this issue by shipping a newer root metadata as bootstrap

So:

  • client example could ship with root.json files for known repositories like https://github.com/jku/tuf-demo, sigstore, bottlerocket, the manual repo in python-tuf sources, etc
  • these should be "hidden" a bit so that they don't confuse someone who is just looking for example code
  • client should automatically use these bootstrap roots: the initial implementation could be just if cache for {REPO} does not have root.json and bootstrap root.json for {REPO} exists, then copy bootstrap root.json to cache
  • the obvious next step is #1168 , which is a ngclient feature that would make the example even simpler and safer
Vorherrschende Sprache
Python
Sterne
1.7k
Forks
304
Ø Merge
9 Std. 25 Min.
Gemergte PRs (30 T.)
14

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus theupdateframework/python-tuf

Alle Issues in theupdateframework/python-tuf

Ähnliche Issues

Weitere Issues zu Python

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.