Request: independently verifiable source signing and reproducible-build details for v7.0.0
維護者通常 2 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 新手友好度
- 42/100
- Issue 類型
- 文件
- 描述清晰度
- 基本清楚
- 活躍度
- 冷清
- 技術堆疊
- git, github, python
研究方向
首先檢查 issue 中指定的 annotated tag v7.0.0、peeled commit、source archive、wheel 和 source distribution。檢查專案的 release 和 packaging 流程,確認 maintainer 簽章、金鑰繫結、雜湊值、建置工具和相依性的版本,以及 provenance 紀錄。完成的標準是:記錄或發布針對所要求的六個 provenance 和可重現性問題的權威答案。
由索引模型根據 Issue 內容生成。
描述
Hello maintainers,
I am reviewing python-tuf v7.0.0 for use in a security-sensitive, offline-verification workflow.
I could verify the following GitHub objects:
- Annotated tag object:
fed65f73486314242cc738fc7c5c891f5d7fc369 - Peeled commit:
353bdb767db56fd4667c9bcf56b710d50fdc2ac0
GitHub shows the tag as verified through GitHub's web-flow signing key. However, I have not found an independently published maintainer signature or key binding that can authenticate these source objects without initially trusting GitHub as the identity authority.
Could you please clarify:
- Is there an official non-GitHub location that binds the v7.0.0 tag or commit to a maintainer-controlled signing-key fingerprint?
- Is a detached signature or signed release statement available for the tag, commit, or source archive?
- What is the canonical SHA-256 digest of the source archive used to build the published v7.0.0 artifacts?
- What exact build-tool and dependency versions were used for the release?
- Are the wheel and source distribution intended to be byte-for-byte reproducible from the tagged source? If not, which content-level comparison is considered authoritative?
- Are there plans to publish provenance or attestations that bind the source commit to the PyPI artifacts?
This is a supply-chain provenance question, not a vulnerability report. No private repository information or credentials are involved.
Thank you.
- 主要語言
- Python
- 星號
- 1.7k
- 分支
- 304
- 平均合併
- 1 天 2 小時
- 30 天內合併 PR
- 17
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
theupdateframework/python-tuf 的其他 Issue
-
難度 4/5 3-5 天 新手友好度 48/100
theupdateframework/python-tuf#3001 ·
維護者通常 2 天內回覆
-
enhancement github_actions
難度 3/5 1-2 天 新手友好度 45/100
theupdateframework/python-tuf#2920 · 1 則留言 · 2 個 reaction ·
維護者通常 2 天內回覆
-
難度 3/5 1-2 天 新手友好度 35/100
theupdateframework/python-tuf#2842 · 3 則留言 ·
維護者通常 2 天內回覆
-
難度 5/5 一週以上 新手友好度 25/100
theupdateframework/python-tuf#2836 · 7 則留言 ·
維護者通常 2 天內回覆
-
難度 5/5 一週以上 新手友好度 30/100
theupdateframework/python-tuf#2676 · 2 則留言 · 1 個 reaction ·
維護者通常 2 天內回覆
查看 theupdateframework/python-tuf 的全部 Issue
相似的 Issue
-
documentation
難度 2/5 1-3 小時 新手友好度 70/100
kristofdegrave/homeassistant-smart-charging#1413 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 88/100
nasa/earthdata-varinfo#113 ·
-
curriculum documentation quality
難度 2/5 1-3 小時 新手友好度 88/100
githubnext/gh-aw-workshop#3849 ·
維護者通常 2 天內回覆
-
難度 2/5 1-3 小時 新手友好度 90/100
-
難度 2/5 1-3 小時 新手友好度 84/100
維護者通常 1 天內回覆