Consider including `securesystemslib[crypto]` as a dependency in TUF
维护者通常 10 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 45/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- python
- 领域
- build-system
调研方向
首先比较 pyproject.toml 和 requirements/main.txt 中的依赖声明,然后在所描述的环境中运行 tuf_import_error_issue.py.txt。当包元数据请求 securesystemslib[crypto],且安装 python-tuf 提供签名验证所需的 cryptography 版本时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
Issue Description
The purpose of this issue is to kindly ask whether listing securesystemslib[crypto] as a dependency would improve the out-of-the-box experience with python-tuf.
I noticed that pip3 install tuf did not upgrade the pre-existing, old cryptography==3.4.8 present in a standard python installation. (The exact situation is an AWS Ubuntu 22.04 machine where python3 comes pre-installed with cryptography==3.4.8.) A more recent version like cryptography>=37.0.0 is required to perform a tuf.ngclient.Updater.download_target operation.
cryptography>=37.0.0 is listed as a dependency of the custom install securesystemslib[crypto] of securesystemslib, but not for the base install. Unfortunately, tuf==3.1.0 only mentions securesystemslib[crypto] in requirements/main.txt, but not as a dependency in pyproject.toml.
Reproduce issue
The issue becomes evident during signature verification processes, where the older cryptography library cannot correctly handle the signatures. Here are relevant snippets from the logs:
# create dirs
mkdir -p ~/.tuf_import_error_issue/metadata ~/.tuf_import_error_issue/tmp
# get root.json
curl -o ~/.tuf_import_error_issue/metadata/root.json https://raw.githubusercontent.com/sigstore/root-signing/main/ceremony/2022-10-18/repository/5.root.json
Please find attached the python file which generates the error and its logs below. You should be able to run the python script from anywhere as it has the paths indicated above hard-coded for this example.
tuf_import_error_issue.py.txt
Logs
DEBUG - tuf/ngclient/_internal/trusted_metadata_set.py:98 - Updating initial trusted root
INFO - securesystemslib/signer/_key.py:429 - Key xyz...123 failed to verify sig: 'pyca/cryptography' library required
INFO - tuf/api/metadata.py:744 - Key xyz...123 failed to verify root
...
tuf.api.exceptions.UnsignedMetadataError: root was signed by 0/3 keys
Summary
python-tuflistssecuresystemslib>=0.26.0as a dependency but does not specify that it should include the[crypto]extras.- When an outdated version of the
cryptographylibrary is already installed, installingpython-tufdoes not prompt an upgrade to meetsecuresystemslib[crypto]'s requirements, leading to potential signature verification issues. - Kindly consider including
securesystemslib[crypto]as a direct dependency forpython-tuf. This change would ensure that the necessarycryptographyversion is installed or upgraded duringpython-tuf's installation, mitigating issues related to outdated dependencies and improving the out-of-the-box security and reliability ofpython-tuf, especially in environments where dependency management is crucial.
I appreciate that managing dependencies is a delicate balance and I am curious to hear your thoughts. Please let me know if there is any further information I could help with.
- 主要语言
- Python
- 星标
- 1.7k
- 派生
- 304
- 平均合并
- 9 小时 25 分钟
- 30 天内合并 PR
- 14
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
theupdateframework/python-tuf 的其他 Issue
-
难度 4/5 3-5 天 新手友好度 48/100
theupdateframework/python-tuf#3001 ·
维护者通常 10 天内回复
-
难度 4/5 3-5 天 新手友好度 42/100
theupdateframework/python-tuf#2979 · 1 条评论 ·
维护者通常 10 天内回复
-
enhancement github_actions
难度 3/5 1-2 天 新手友好度 45/100
theupdateframework/python-tuf#2920 · 1 条评论 · 2 个 reaction ·
维护者通常 10 天内回复
-
难度 3/5 1-2 天 新手友好度 35/100
theupdateframework/python-tuf#2842 · 3 条评论 ·
维护者通常 10 天内回复
-
难度 5/5 一周以上 新手友好度 25/100
theupdateframework/python-tuf#2836 · 7 条评论 ·
维护者通常 10 天内回复
查看 theupdateframework/python-tuf 的全部 Issue
相似的 Issue
-
docs pydanty:is-working
难度 2/5 1-3 小时 新手友好度 75/100
pydantic/pydantic-ai#8863 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
run-llama/llama_index#23278 ·
维护者通常 2 天内回复
-
documentation from-review-extraction github-actions priority: low severity:nit
难度 1/5 1 小时以内 新手友好度 92/100
LearningCircuit/local-deep-research#6946 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
oracle/langchain-oracle#323 ·
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 88/100
tenstorrent/tt-metal#58057 · 1 条评论 ·
维护者通常 1 天内回复