theupdateframework / theupdateframework/python-tuf
Request: independently verifiable source signing and reproducible-build details for v7.0.0
まだ誰も着手していません。
- 主要言語
- Python
- スター
- 1.7k
- フォーク
- 304
- 平均マージ
- 1日 2時間
- マージ済み PR(30日)
- 17
説明
Hello maintainers,
I am reviewing python-tuf v7.0.0 for use in a security-sensitive, offline-verification workflow.
I could verify the following GitHub objects:
- Annotated tag object:
fed65f73486314242cc738fc7c5c891f5d7fc369 - Peeled commit:
353bdb767db56fd4667c9bcf56b710d50fdc2ac0
GitHub shows the tag as verified through GitHub's web-flow signing key. However, I have not found an independently published maintainer signature or key binding that can authenticate these source objects without initially trusting GitHub as the identity authority.
Could you please clarify:
- Is there an official non-GitHub location that binds the v7.0.0 tag or commit to a maintainer-controlled signing-key fingerprint?
- Is a detached signature or signed release statement available for the tag, commit, or source archive?
- What is the canonical SHA-256 digest of the source archive used to build the published v7.0.0 artifacts?
- What exact build-tool and dependency versions were used for the release?
- Are the wheel and source distribution intended to be byte-for-byte reproducible from the tagged source? If not, which content-level comparison is considered authoritative?
- Are there plans to publish provenance or attestations that bind the source commit to the PyPI artifacts?
This is a supply-chain provenance question, not a vulnerability report. No private repository information or credentials are involved.
Thank you.
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
調査の方向性
まず、issue に記載されている annotated tag v7.0.0、peeled commit、source archive、wheel、source distribution を確認します。プロジェクトの release および packaging プロセスについて、maintainer の署名、鍵の対応付け、ハッシュ、ビルドツールと依存関係のバージョン、provenance の記録を確認します。完了とは、provenance と再現可能性に関して要求された6つの質問への信頼できる回答を文書化または公開することを意味します。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- git, github, python
- 領域
- build-system, documentation, release, security
- issue の種類
- ドキュメント
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 42/100