theupdateframework / theupdateframework/python-tuf
Testing specific sequences the client should be able to handle
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 1.7k
- Forks
- 304
- Avg merge
- 1d 2h
- Merged PRs (30d)
- 17
Description
Description of issue or feature request:
Consider different types of updates sequences that may exist in a repository and which the updater should be able to handle.
Analyze their relevance and the need of a dedicated test case. For example:
- Client that has been offline for N expirations of root metadata
- Air-gapped client outside of timestamp expiration window
- Some of the previously reported security issues
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the updater's handling of repository update sequences and the linked security advisories. Evaluate cases such as multiple root-metadata expirations and air-gapped clients outside the timestamp window, then identify which need dedicated tests. Done means the relevant sequences are analyzed and the necessary test coverage is defined or added.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security, testing
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100