theupdateframework / theupdateframework/python-tuf

Testing specific sequences the client should be able to handle

Open
#1,747 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

testing
Dominant language
Python
Stars
1.7k
Forks
304
Avg merge
1d 2h
Merged PRs (30d)
17

Description

Description of issue or feature request:

Consider different types of updates sequences that may exist in a repository and which the updater should be able to handle.
Analyze their relevance and the need of a dedicated test case. For example:

  • Client that has been offline for N expirations of root metadata
  • Air-gapped client outside of timestamp expiration window
  • Some of the previously reported security issues

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the updater's handling of repository update sequences and the linked security advisories. Evaluate cases such as multiple root-metadata expirations and air-gapped clients outside the timestamp window, then identify which need dedicated tests. Done means the relevant sequences are analyzed and the necessary test coverage is defined or added.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security, testing
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.