Examples: ship bootstrap root.jsons for well-known repositories
維護者通常 10 天內回覆
還沒有人認領這個 Issue。
評估
研究方向
從用戶端範例的 repository-cache 初始化開始,檢視 #2193 中描述的現有 TOFU 流程。為指定的儲存庫新增隱藏的 bootstrap root.json 檔案,並讓空快取使用相符的 bootstrap root;確認該範例不使用 TOFU 也能運作,同時將 #1168 視為後續工作。
由索引模型根據 Issue 內容生成。
描述
In #2193 the client example gains Trust-On-First-Use (TOFU) functionality and support for arbitrary repositories. This is very useful for testing but has two issues:
- we should also be an example of not using TOFU (and shipping the bootstrap root metadata) whenever possible
- some known repositories have old root metadata that the client is incompatible with: This breaks the TOFU approach. We could workaround this issue by shipping a newer root metadata as bootstrap
So:
- client example could ship with root.json files for known repositories like https://github.com/jku/tuf-demo, sigstore, bottlerocket, the manual repo in python-tuf sources, etc
- these should be "hidden" a bit so that they don't confuse someone who is just looking for example code
- client should automatically use these bootstrap roots: the initial implementation could be just
if cache for {REPO} does not have root.json and bootstrap root.json for {REPO} exists, then copy bootstrap root.json to cache - the obvious next step is #1168 , which is a ngclient feature that would make the example even simpler and safer
- 主要語言
- Python
- 星號
- 1.7k
- 分支
- 304
- 平均合併
- 9 小時 25 分鐘
- 30 天內合併 PR
- 14
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
theupdateframework/python-tuf 的其他 Issue
-
難度 4/5 3-5 天 新手友好度 48/100
theupdateframework/python-tuf#3001 ·
維護者通常 10 天內回覆
-
難度 4/5 3-5 天 新手友好度 42/100
theupdateframework/python-tuf#2979 · 1 則留言 ·
維護者通常 10 天內回覆
-
enhancement github_actions
難度 3/5 1-2 天 新手友好度 45/100
theupdateframework/python-tuf#2920 · 1 則留言 · 2 個 reaction ·
維護者通常 10 天內回覆
-
難度 3/5 1-2 天 新手友好度 35/100
theupdateframework/python-tuf#2842 · 3 則留言 ·
維護者通常 10 天內回覆
-
難度 5/5 一週以上 新手友好度 25/100
theupdateframework/python-tuf#2836 · 7 則留言 ·
維護者通常 10 天內回覆
查看 theupdateframework/python-tuf 的全部 Issue
相似的 Issue
-
docs pydanty:is-working
難度 2/5 1-3 小時 新手友好度 75/100
pydantic/pydantic-ai#8863 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 68/100
run-llama/llama_index#23278 ·
維護者通常 2 天內回覆
-
documentation from-review-extraction github-actions priority: low severity:nit
難度 1/5 1 小時以內 新手友好度 92/100
LearningCircuit/local-deep-research#6946 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 82/100
oracle/langchain-oracle#323 ·
維護者通常 1 天內回覆
-
難度 1/5 1 小時以內 新手友好度 88/100
tenstorrent/tt-metal#58057 · 1 則留言 ·
維護者通常 1 天內回覆