Clarity needed in relation to Snapshot role and online vs offline
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 35/100
- issue の種類
- ドキュメント
- 明瞭さ
- おおむね明確
- 活発さ
- 停滞
調査の方向性
content/metadata.md と content/faq.md にある Snapshot key に関するガイダンスを、issue で引用されている Specification と比較します。まず、どのガイダンスが正式なものかを確認し、その後、参照先が一致するように、矛盾しているウェブサイトの文言を更新します。FAQ とメタデータのドキュメントが Snapshot role key の保存方法を一貫して説明していれば完了です。
索引モデルが issue の本文から書いたものです。
説明
At the moment, the website can't seem to make its mind up as to whether Snapshot role keys should be online or offline.
Really someone needs to decide once and for all and stick to it, instead of all this conflicting wording.
If we consider the Specification as the ultimate source of truth, then we are told:
All keys, except those for the timestamp and mirrors roles, should be stored securely offline
content/metadata.md seems to agree:
so that the Snapshot role's keys can be kept offline, and thus more secure
So far so good. But the FAQ content/faq.md is where you have the bouncing around. On one page we are told two different things...
Three places state online:
even sharing online keys (e.g., between the Timestamp and Snapshot roles)
In contrast, the Snapshot role is updated often, signed with an online key
The Timestamp and Snapshot roles can use online keys
And then we have a suggestion of offline for Snapshot:
separate keys should be used so that the Snapshot role’s keys can be kept offline, and thus in a more secure manner.
If we assume the Specification reflects the TUF design decision, then the rest of the website should be consistent.
- 主要言語
- HTML
- スター
- 25
- フォーク
- 46
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
theupdateframework/theupdateframework.io のほかの issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
theupdateframework/theupdateframework.io#184 · コメント 1 件 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 84/100
theupdateframework/theupdateframework.io#183 · コメント 3 件 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
theupdateframework/theupdateframework.io#182 · コメント 1 件 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
theupdateframework/theupdateframework.io の issue をすべて見る
似ている issue
-
Link Checker Reportオープンautomated issue report
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
-
難易度 1/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
-
agent-reported area/browser area/docs documentation good first issue hacktoberfest help wanted P2
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
メンテナーはふだん 2 日以内に返信