theupdateframework / theupdateframework/taps
Discussion of TAP-17: Remove signature wrapper from TUF spec
Open
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 37
- Forks
- 23
- PR merge metrics
- No merged PRs in 30d
Description
This is a place to discuss removal of the signature wrapper from the TUF spec, introduced in #138.
Link to implementation: To Do
Outstanding issues and questions relating to the TAP:
- Should the spec recommend/suggest/mention a format which implements the proposed properties? i.e., DSSE
- what should the pedagogical examples look like after the spec is updated per this TAP? do we continue to use JSON for file format examples?
- should we include guidance on payload type, particularly given this is a motivation for the TAP?
- what recommendations should the spec make about capturing implementation details in a POUF, especially payload type (how to identify the implementation)?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review TAP-17 and the implementation introduced in #138, then resolve the open questions about DSSE, JSON pedagogical examples, payload type guidance, and POUF implementation details. Done means the proposed changes are decided and the TUF specification is updated accordingly.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100