haskell / haskell/hackage-security

Update README to document status of TUF integrations, Phase 1, Phase 2 etc.

Open
#245 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Haskell
Stars
63
Forks
56
PR merge metrics
No merged PRs in 30d

Description

The README expresses nearly everything in the future tense:

> Phase 1 of the project will implement the basic TUF framework, but leave out author signing; support for author signed packages (and other targets) will added in phase 2.

I know almost nothing about Haskell or Hackage or Cabal, but it seems from the [Cabal documentation ](https://cabal.readthedocs.io/en/3.4/installing-packages.html) that this support is already deployed.

Did that use this code? Or some other repository?

Are both phases implemented? Widely used?

Note: I'm coming from the Python world, where TUF integration is an active process, and mainly interested in what we can learn from the Haskell community and experience. I hope I'm not off-base here....

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the README's Phase 1 and Phase 2 descriptions and compare them with the Cabal documentation linked in the issue. Trace whether the deployed Hackage support uses this repository, determine the implementation status and adoption of both phases, then update the README to reflect verified facts.

Written by the indexing model from the issue text.

Assessment

Tech stack
haskell
Domain
documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.