jupyter / jupyter/nbformat

Should kernel info be included in notebook signature computation?

Open
#296 4 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
Python
Stars
313
Forks
176
PR merge metrics
No merged PRs in 30d

Description

@divyansshhh opened an [issue in JupyterLab](https://github.com/jupyterlab/jupyterlab/issues/12955) that is more appropriate for `jupyter/nbformat`, so this issue is meant to replace the original in JupyterLab.

> ### Problem
> At present, when computing the signature of a notebook, the `compute_signature` function ([ref](https://github.com/jupyter/nbformat/blob/main/nbformat/sign.py#L421)) takes into consideration the kernel info. I believe this shouldn't be done because it has no effect on the safety of the output.
>
> ### Proposed Solution
>
> If there is no reason to include kernel info while computing the notebook signature then it should be stripped out.
>
> ### Additional context
> In our use-case we have a custom contents manager that can be used to access notebooks from a remote host in a read-only mode. Now, if the original notebook was authored with say `kernel1` then opening that in a host which doesn't have a kernel named `kernel1` makes the notebook untrusted.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.