Request: independently verifiable source signing and reproducible-build details for v7.0.0
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 42/100
- Issue 类型
- 文档
- 描述清晰度
- 基本清楚
- 活跃度
- 冷清
- 技术栈
- git, github, python
调研方向
首先检查 issue 中指定的 annotated tag v7.0.0、peeled commit、source archive、wheel 和 source distribution。检查项目的 release 和 packaging 流程,确认 maintainer 签名、密钥绑定、哈希值、构建工具和依赖项的版本,以及 provenance 记录。完成的标准是:记录或发布针对所请求的六个 provenance 和可复现性问题的权威答案。
由索引模型根据 Issue 内容生成。
描述
Hello maintainers,
I am reviewing python-tuf v7.0.0 for use in a security-sensitive, offline-verification workflow.
I could verify the following GitHub objects:
- Annotated tag object:
fed65f73486314242cc738fc7c5c891f5d7fc369 - Peeled commit:
353bdb767db56fd4667c9bcf56b710d50fdc2ac0
GitHub shows the tag as verified through GitHub's web-flow signing key. However, I have not found an independently published maintainer signature or key binding that can authenticate these source objects without initially trusting GitHub as the identity authority.
Could you please clarify:
- Is there an official non-GitHub location that binds the v7.0.0 tag or commit to a maintainer-controlled signing-key fingerprint?
- Is a detached signature or signed release statement available for the tag, commit, or source archive?
- What is the canonical SHA-256 digest of the source archive used to build the published v7.0.0 artifacts?
- What exact build-tool and dependency versions were used for the release?
- Are the wheel and source distribution intended to be byte-for-byte reproducible from the tagged source? If not, which content-level comparison is considered authoritative?
- Are there plans to publish provenance or attestations that bind the source commit to the PyPI artifacts?
This is a supply-chain provenance question, not a vulnerability report. No private repository information or credentials are involved.
Thank you.
- 主要语言
- Python
- 星标
- 1.7k
- 派生
- 304
- 平均合并
- 1 天 2 小时
- 30 天内合并 PR
- 17
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
theupdateframework/python-tuf 的其他 Issue
-
难度 4/5 3-5 天 新手友好度 48/100
theupdateframework/python-tuf#3001 ·
-
enhancement github_actions
难度 3/5 1-2 天 新手友好度 45/100
theupdateframework/python-tuf#2920 · 1 条评论 · 2 个 reaction ·
-
难度 3/5 1-2 天 新手友好度 35/100
theupdateframework/python-tuf#2842 · 3 条评论 ·
-
难度 5/5 一周以上 新手友好度 25/100
theupdateframework/python-tuf#2836 · 7 条评论 ·
-
难度 5/5 一周以上 新手友好度 30/100
theupdateframework/python-tuf#2676 · 2 条评论 · 1 个 reaction ·
查看 theupdateframework/python-tuf 的全部 Issue
相似的 Issue
-
难度 1/5 1 小时以内 新手友好度 75/100
-
hcocena 未关闭policies-accepted pre-review precheck-passed
难度 1/5 1 小时以内 新手友好度 88/100
Bioconductor/BiocContributions#214 · 5 条评论 ·
-
难度 1/5 1 小时以内 新手友好度 92/100
TencentCloud/Octop#1169 · 1 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 70/100
521xueweihan/HelloGitHub#3778 ·
-
The version checker's trailing attribute region has no control for a less-than inside a quoted value 未关闭area: dashboard area: tests bug perceived difficulty: 2 python
难度 2/5 1-3 小时 新手友好度 84/100
Nitjsefnie-Harness-Commons/daedalus#1105 · 1 条评论 ·