theupdateframework / theupdateframework/python-tuf

Add an FAQ and/or high-level overview of how to integrate TUF

Offen
#486 3 Kommentare 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

documentation
Vorherrschende Sprache
Python
Sterne
1.7k
Forks
304
Ø Merge
1 T. 2 Std.
Gemergte PRs (30 T.)
17

Beschreibung

We are often asked the same questions regarding delegations, how to organize TUF metadata, key management, etc. There should be an FAQ page for these sorts of questions.

The Survivable Key Compromise paper provides an overview of TUF's design, and the specification and other documents available here capture most of what it contains. However, the integration side of things is not adequately explained outside of the Diplomat and Mercury papers. The PEP 458 document is also a good resource for how to integrate TUF with an existing software updater and community repository.

We should provide a condensed, high-level document that contains the information in the papers and documents that have been written since the Survivable Key Compromise paper.

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Prüfe die Papers Survivable Key Compromise, Diplomat und Mercury sowie das Dokument PEP 458 und vorhandene TUF-Spezifikationsmaterialien. Fasse ihre Integrationshinweise in einer kompakten FAQ oder einem Überblick auf hoher Ebene zusammen, der Delegationen, die Organisation von Metadaten und die Schlüsselverwaltung abdeckt; abgeschlossen ist die Aufgabe, wenn die wiederkehrenden Integrationsfragen in einem zugänglichen Dokument erklärt werden.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Bereich
documentation, security
Issue-Typ
Dokumentation
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.