Clarity needed in relation to Snapshot role and online vs offline
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 文档
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
调研方向
将 content/metadata.md 和 content/faq.md 中关于 Snapshot 密钥的指导与 issue 中引用的 Specification 进行比较。首先确定哪份指导具有权威性,然后更新网站上存在冲突的措辞,使这些引用保持一致。当 FAQ 和元数据文档对 Snapshot 角色密钥存储的描述一致时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
At the moment, the website can't seem to make its mind up as to whether Snapshot role keys should be online or offline.
Really someone needs to decide once and for all and stick to it, instead of all this conflicting wording.
If we consider the Specification as the ultimate source of truth, then we are told:
All keys, except those for the timestamp and mirrors roles, should be stored securely offline
content/metadata.md seems to agree:
so that the Snapshot role's keys can be kept offline, and thus more secure
So far so good. But the FAQ content/faq.md is where you have the bouncing around. On one page we are told two different things...
Three places state online:
even sharing online keys (e.g., between the Timestamp and Snapshot roles)
In contrast, the Snapshot role is updated often, signed with an online key
The Timestamp and Snapshot roles can use online keys
And then we have a suggestion of offline for Snapshot:
separate keys should be used so that the Snapshot role’s keys can be kept offline, and thus in a more secure manner.
If we assume the Specification reflects the TUF design decision, then the rest of the website should be consistent.
- 主要语言
- HTML
- 星标
- 25
- 派生
- 46
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
theupdateframework/theupdateframework.io 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 88/100
theupdateframework/theupdateframework.io#184 · 1 条评论 ·
-
难度 1/5 1 小时以内 新手友好度 84/100
theupdateframework/theupdateframework.io#183 · 3 条评论 ·
-
难度 1/5 1 小时以内 新手友好度 88/100
theupdateframework/theupdateframework.io#182 · 1 条评论 ·
-
难度 1/5 1 小时以内 新手友好度 72/100
-
难度 2/5 1-3 小时 新手友好度 78/100
查看 theupdateframework/theupdateframework.io 的全部 Issue
相似的 Issue
-
难度 1/5 1 小时以内 新手友好度 85/100
microsoft/onnxruntime#33018 ·
维护者通常 2 天内回复
-
missing content writing algorithms
难度 1/5 1 小时以内 新手友好度 88/100
QuantConnect/Documentation#2739 ·
维护者通常 1 天内回复
-
:watch: Not Triaged dotnet-target-version
难度 1/5 1 小时以内 新手友好度 85/100
维护者通常 1 天内回复
-
copilot documentation
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 2 天内回复
-
难度 1/5 1 小时以内 新手友好度 78/100
lichess-org/api#678 ·