Examples: ship bootstrap root.jsons for well-known repositories
Maintainer antworten meist innerhalb von 10 Tagen
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 45/100
Rechercherichtung
Beginne bei der Initialisierung des Repository-Caches im Client-Beispiel und überprüfe den bestehenden TOFU-Ablauf, der in #2193 beschrieben ist. Füge versteckte bootstrap root.json-Dateien für die genannten Repositories hinzu und sorge dafür, dass ein leerer Cache das passende bootstrap root verwendet; verifiziere, dass das Beispiel ohne TOFU funktioniert, und behandle #1168 als Folgearbeit.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
In #2193 the client example gains Trust-On-First-Use (TOFU) functionality and support for arbitrary repositories. This is very useful for testing but has two issues:
- we should also be an example of not using TOFU (and shipping the bootstrap root metadata) whenever possible
- some known repositories have old root metadata that the client is incompatible with: This breaks the TOFU approach. We could workaround this issue by shipping a newer root metadata as bootstrap
So:
- client example could ship with root.json files for known repositories like https://github.com/jku/tuf-demo, sigstore, bottlerocket, the manual repo in python-tuf sources, etc
- these should be "hidden" a bit so that they don't confuse someone who is just looking for example code
- client should automatically use these bootstrap roots: the initial implementation could be just
if cache for {REPO} does not have root.json and bootstrap root.json for {REPO} exists, then copy bootstrap root.json to cache - the obvious next step is #1168 , which is a ngclient feature that would make the example even simpler and safer
- Vorherrschende Sprache
- Python
- Sterne
- 1.7k
- Forks
- 304
- Ø Merge
- 9 Std. 25 Min.
- Gemergte PRs (30 T.)
- 14
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Hat eine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus theupdateframework/python-tuf
-
switch to main branch?Offen
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 48/100
theupdateframework/python-tuf#3001 ·
Maintainer antworten meist innerhalb von 10 Tagen
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 42/100
theupdateframework/python-tuf#2979 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 10 Tagen
-
Use Immutable ReleasesOffenenhancement github_actions
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 45/100
theupdateframework/python-tuf#2920 · 1 Kommentar · 2 Reaktionen ·
Maintainer antworten meist innerhalb von 10 Tagen
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 35/100
theupdateframework/python-tuf#2842 · 3 Kommentare ·
Maintainer antworten meist innerhalb von 10 Tagen
-
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 25/100
theupdateframework/python-tuf#2836 · 7 Kommentare ·
Maintainer antworten meist innerhalb von 10 Tagen
Alle Issues in theupdateframework/python-tuf
Ähnliche Issues
-
docs pydanty:is-working
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
pydantic/pydantic-ai#8863 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
run-llama/llama_index#23278 ·
Maintainer antworten meist innerhalb von 2 Tagen
-
documentation from-review-extraction github-actions priority: low severity:nit
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 92/100
LearningCircuit/local-deep-research#6946 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
oracle/langchain-oracle#323 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 88/100
tenstorrent/tt-metal#58057 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag