Giter Site home page Giter Site logo

Comments (12)

adityasaky avatar adityasaky commented on August 19, 2024

Tagging: @MarkLodato @SantiagoTorres @lukpueh @trishankatdatadog @mnm678 @joshuagl @JustinCappos

from dsse.

adityasaky avatar adityasaky commented on August 19, 2024

FYI: I just tagged v0.1.0 -- https://github.com/secure-systems-lab/signing-spec/releases/tag/v0.1.0

from dsse.

trishankatdatadog avatar trishankatdatadog commented on August 19, 2024

Do we have working prototypes somewhere, especially one to support Google's use case, and another to support our Canonical JSON? That would be the only thing that would really convince me, not endless specifications.

from dsse.

MarkLodato avatar MarkLodato commented on August 19, 2024

I suggest creating a GitHub milestone for this. (If you add me as an editor in the project, I'd be happy to set that up for you.)

I filed #28 for the reference implementation.

from dsse.

adityasaky avatar adityasaky commented on August 19, 2024

I've created the milestone and added #28 to it.

from dsse.

dlorenc avatar dlorenc commented on August 19, 2024

Do we have working prototypes somewhere, especially one to support Google's use case, and another to support our Canonical JSON? That would be the only thing that would really convince me, not endless specifications.

I don't know if this is a "reference" implementation, but we have "an" implementation here: https://github.com/in-toto/in-toto-golang/blob/master/pkg/ssl/sign.go

from dsse.

MarkLodato avatar MarkLodato commented on August 19, 2024

I propose that the following are the only blockers:

  • #16 Choose a more specific name than "signing-spec"
  • #27 Use a simpler PAE
  • #28 Create a reference implementation and test vectors

Once we have done these three, we tag it as 1.0. Any objections?

from dsse.

TomHennen avatar TomHennen commented on August 19, 2024

How much do were care about #27? There's already an implementation that uses the already defined PAE.

I'm fine either way, I just want to make sure this is actually a good use of time.

from dsse.

MarkLodato avatar MarkLodato commented on August 19, 2024

IMO it's valuable since it significantly simplifies the implementation and is an easy change to make.

from dsse.

TomHennen avatar TomHennen commented on August 19, 2024

SGTM

from dsse.

laurentsimon avatar laurentsimon commented on August 19, 2024

I chatted offline with @MarkLodato on the possibility to use a simpler encoding for the envelope part too: that would prevent recipients from using a full-blown json parser on untrusted input. But it's yet more work to make this change and may not best use of time at this stage.

from dsse.

MarkLodato avatar MarkLodato commented on August 19, 2024

It's 1.0 now!

from dsse.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.