Request: independently verifiable source signing and reproducible-build details for v7.0.0
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 42/100
- issue の種類
- ドキュメント
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- git, github, python
調査の方向性
まず、issue に記載されている annotated tag v7.0.0、peeled commit、source archive、wheel、source distribution を確認します。プロジェクトの release および packaging プロセスについて、maintainer の署名、鍵の対応付け、ハッシュ、ビルドツールと依存関係のバージョン、provenance の記録を確認します。完了とは、provenance と再現可能性に関して要求された6つの質問への信頼できる回答を文書化または公開することを意味します。
索引モデルが issue の本文から書いたものです。
説明
Hello maintainers,
I am reviewing python-tuf v7.0.0 for use in a security-sensitive, offline-verification workflow.
I could verify the following GitHub objects:
- Annotated tag object:
fed65f73486314242cc738fc7c5c891f5d7fc369 - Peeled commit:
353bdb767db56fd4667c9bcf56b710d50fdc2ac0
GitHub shows the tag as verified through GitHub's web-flow signing key. However, I have not found an independently published maintainer signature or key binding that can authenticate these source objects without initially trusting GitHub as the identity authority.
Could you please clarify:
- Is there an official non-GitHub location that binds the v7.0.0 tag or commit to a maintainer-controlled signing-key fingerprint?
- Is a detached signature or signed release statement available for the tag, commit, or source archive?
- What is the canonical SHA-256 digest of the source archive used to build the published v7.0.0 artifacts?
- What exact build-tool and dependency versions were used for the release?
- Are the wheel and source distribution intended to be byte-for-byte reproducible from the tagged source? If not, which content-level comparison is considered authoritative?
- Are there plans to publish provenance or attestations that bind the source commit to the PyPI artifacts?
This is a supply-chain provenance question, not a vulnerability report. No private repository information or credentials are involved.
Thank you.
- 主要言語
- Python
- スター
- 1.7k
- フォーク
- 304
- 平均マージ
- 1日 2時間
- マージ済み PR(30日)
- 17
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
theupdateframework/python-tuf のほかの issue
-
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
theupdateframework/python-tuf#3001 ·
-
enhancement github_actions
難易度 3/5 1〜2日 初心者へのやさしさ 45/100
theupdateframework/python-tuf#2920 · コメント 1 件 · リアクション 2 件 ·
-
難易度 3/5 1〜2日 初心者へのやさしさ 35/100
theupdateframework/python-tuf#2842 · コメント 3 件 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
theupdateframework/python-tuf#2836 · コメント 7 件 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 30/100
theupdateframework/python-tuf#2676 · コメント 2 件 · リアクション 1 件 ·
theupdateframework/python-tuf の issue をすべて見る
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 75/100
-
hcocena オープンpolicies-accepted pre-review precheck-passed
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
Bioconductor/BiocContributions#214 · コメント 5 件 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
TencentCloud/Octop#1169 · コメント 1 件 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
521xueweihan/HelloGitHub#3778 ·
-
The version checker's trailing attribute region has no control for a less-than inside a quoted value オープンarea: dashboard area: tests bug perceived difficulty: 2 python
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
Nitjsefnie-Harness-Commons/daedalus#1105 · コメント 1 件 ·