Consider including `securesystemslib[crypto]` as a dependency in TUF
Maintainer thường phản hồi trong vòng 2 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 45/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- python
- Lĩnh vực
- build-system
Hướng nghiên cứu
Bắt đầu bằng cách so sánh các khai báo dependency trong pyproject.toml và requirements/main.txt, sau đó chạy tuf_import_error_issue.py.txt trong môi trường được mô tả. Công việc được coi là hoàn tất khi metadata của package yêu cầu securesystemslib[crypto] và việc cài đặt python-tuf cung cấp phiên bản cryptography cần thiết để xác minh chữ ký.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Issue Description
The purpose of this issue is to kindly ask whether listing securesystemslib[crypto] as a dependency would improve the out-of-the-box experience with python-tuf.
I noticed that pip3 install tuf did not upgrade the pre-existing, old cryptography==3.4.8 present in a standard python installation. (The exact situation is an AWS Ubuntu 22.04 machine where python3 comes pre-installed with cryptography==3.4.8.) A more recent version like cryptography>=37.0.0 is required to perform a tuf.ngclient.Updater.download_target operation.
cryptography>=37.0.0 is listed as a dependency of the custom install securesystemslib[crypto] of securesystemslib, but not for the base install. Unfortunately, tuf==3.1.0 only mentions securesystemslib[crypto] in requirements/main.txt, but not as a dependency in pyproject.toml.
Reproduce issue
The issue becomes evident during signature verification processes, where the older cryptography library cannot correctly handle the signatures. Here are relevant snippets from the logs:
# create dirs
mkdir -p ~/.tuf_import_error_issue/metadata ~/.tuf_import_error_issue/tmp
# get root.json
curl -o ~/.tuf_import_error_issue/metadata/root.json https://raw.githubusercontent.com/sigstore/root-signing/main/ceremony/2022-10-18/repository/5.root.json
Please find attached the python file which generates the error and its logs below. You should be able to run the python script from anywhere as it has the paths indicated above hard-coded for this example.
tuf_import_error_issue.py.txt
Logs
DEBUG - tuf/ngclient/_internal/trusted_metadata_set.py:98 - Updating initial trusted root
INFO - securesystemslib/signer/_key.py:429 - Key xyz...123 failed to verify sig: 'pyca/cryptography' library required
INFO - tuf/api/metadata.py:744 - Key xyz...123 failed to verify root
...
tuf.api.exceptions.UnsignedMetadataError: root was signed by 0/3 keys
Summary
python-tuflistssecuresystemslib>=0.26.0as a dependency but does not specify that it should include the[crypto]extras.- When an outdated version of the
cryptographylibrary is already installed, installingpython-tufdoes not prompt an upgrade to meetsecuresystemslib[crypto]'s requirements, leading to potential signature verification issues. - Kindly consider including
securesystemslib[crypto]as a direct dependency forpython-tuf. This change would ensure that the necessarycryptographyversion is installed or upgraded duringpython-tuf's installation, mitigating issues related to outdated dependencies and improving the out-of-the-box security and reliability ofpython-tuf, especially in environments where dependency management is crucial.
I appreciate that managing dependencies is a delicate balance and I am curious to hear your thoughts. Please let me know if there is any further information I could help with.
- Ngôn ngữ chính
- Python
- Star
- 1.7k
- Fork
- 304
- Merge trung bình
- 1 ngày 2 giờ
- Pull request đã merge (30 ngày)
- 17
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của theupdateframework/python-tuf
-
switch to main branch?Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
theupdateframework/python-tuf#3001 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 42/100
theupdateframework/python-tuf#2979 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Use Immutable ReleasesĐang mởenhancement github_actions
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
theupdateframework/python-tuf#2920 · 1 bình luận · 2 reaction ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Investigate/test fetcher retriesĐang mở
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 35/100
theupdateframework/python-tuf#2842 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
theupdateframework/python-tuf#2836 · 7 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của theupdateframework/python-tuf
Issue tương tự
-
good first issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
vllm-project/vllm-metal#822 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
vector-store
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 90/100
mem0ai/mem0#7461 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug]: chunk_span_bounds and _validated_chunk_spans reject Pydantic models ChunkSpan and AudioFileĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
BasedHardware/omi#19047 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày