Request: independently verifiable source signing and reproducible-build details for v7.0.0
Maintainer antworten meist innerhalb von 10 Tagen
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 42/100
- Issue-Typ
- Dokumentation
- Klarheit
- Größtenteils klar
- Aktivitätsstatus
- Ruhig
- Tech-Stack
- git, github, python
- Bereich
- build-system, documentation, release, security
Rechercherichtung
Beginne mit der Überprüfung des annotierten Tags v7.0.0, des peeled commit, des source archive, der wheel und der in der Issue genannten source distribution. Überprüfe den Release- und Packaging-Prozess des Projekts auf Maintainer-Signaturen, Schlüsselbindungen, Hashes, Versionen der Build-Tools und Abhängigkeiten sowie Provenance-Datensätze. Als erledigt gilt die Aufgabe, wenn maßgebliche Antworten auf die sechs angeforderten Fragen zu Provenance und Reproduzierbarkeit dokumentiert oder veröffentlicht sind.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Hello maintainers,
I am reviewing python-tuf v7.0.0 for use in a security-sensitive, offline-verification workflow.
I could verify the following GitHub objects:
- Annotated tag object:
fed65f73486314242cc738fc7c5c891f5d7fc369 - Peeled commit:
353bdb767db56fd4667c9bcf56b710d50fdc2ac0
GitHub shows the tag as verified through GitHub's web-flow signing key. However, I have not found an independently published maintainer signature or key binding that can authenticate these source objects without initially trusting GitHub as the identity authority.
Could you please clarify:
- Is there an official non-GitHub location that binds the v7.0.0 tag or commit to a maintainer-controlled signing-key fingerprint?
- Is a detached signature or signed release statement available for the tag, commit, or source archive?
- What is the canonical SHA-256 digest of the source archive used to build the published v7.0.0 artifacts?
- What exact build-tool and dependency versions were used for the release?
- Are the wheel and source distribution intended to be byte-for-byte reproducible from the tagged source? If not, which content-level comparison is considered authoritative?
- Are there plans to publish provenance or attestations that bind the source commit to the PyPI artifacts?
This is a supply-chain provenance question, not a vulnerability report. No private repository information or credentials are involved.
Thank you.
- Vorherrschende Sprache
- Python
- Sterne
- 1.7k
- Forks
- 304
- Ø Merge
- 9 Std. 25 Min.
- Gemergte PRs (30 T.)
- 14
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Hat eine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus theupdateframework/python-tuf
-
switch to main branch?Offen
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 48/100
theupdateframework/python-tuf#3001 ·
Maintainer antworten meist innerhalb von 10 Tagen
-
Use Immutable ReleasesOffenenhancement github_actions
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 45/100
theupdateframework/python-tuf#2920 · 1 Kommentar · 2 Reaktionen ·
Maintainer antworten meist innerhalb von 10 Tagen
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 35/100
theupdateframework/python-tuf#2842 · 3 Kommentare ·
Maintainer antworten meist innerhalb von 10 Tagen
-
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 25/100
theupdateframework/python-tuf#2836 · 7 Kommentare ·
Maintainer antworten meist innerhalb von 10 Tagen
-
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 30/100
theupdateframework/python-tuf#2676 · 2 Kommentare · 1 Reaktion ·
Maintainer antworten meist innerhalb von 10 Tagen
Alle Issues in theupdateframework/python-tuf
Ähnliche Issues
-
pydanty:is-working
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
pydantic/pydantic-ai#8843 ·
Maintainer antworten meist innerhalb von 1 Tag
-
breaking change enhancement server
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
Maintainer antworten meist innerhalb von 1 Tag
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
sktime/sktime#11310 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
Maintainer antworten meist innerhalb von 1 Tag
-
needs-triage
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
Maintainer antworten meist innerhalb von 1 Tag