This release is a pre-release and may not be stable for production use.
swarmauri_cipher_suite_pep458
swarmauri_cipher_suite_pep458 captures the policy surface and algorithm registry
that PEP 458 describes for securing Python
package repositories. The suite models canonicalization, allowed algorithms, role
thresholds, and metadata lifetimes so Swarmauri services can negotiate the same
expectations when they sign or verify TUF metadata.
Highlights
- Explicit role policies ? Encodes recommended thresholds, expiration windows,
and algorithm selections for the canonical
root,targets,snapshot, andtimestampmetadata roles. - Deterministic defaults ? Advertises TUF canonical JSON (
tuf-json) as the canonicalization format and returns Ed25519 as the default online algorithm while still supporting RSA-PSS-SHA256 for offline roots. - Descriptor normalization ? Produces rich normalized descriptors containing the
signer implementation hint (
swarmauri_signing_pep458.Pep458Signer), canonical preferences, and caller-specified policy overrides. - Compliance metadata ? Surfaces machine readable notes indicating PEP 458 and TUF compatibility, enabling automated linting and negotiation between components.
Installation
Using uv
uv add swarmauri_cipher_suite_pep458
Using pip
pip install swarmauri_cipher_suite_pep458
Quick Usage
from swarmauri_cipher_suite_pep458 import Pep458CipherSuite
suite = Pep458CipherSuite()
print(suite.features())
# {'suite': 'pep458', 'version': 1, ...}
descriptor = suite.normalize(op="sign", params={"role": "targets", "threshold": 2})
print(descriptor["mapped"]["provider"]["signer"])
# 'swarmauri_signing_pep458.Pep458Signer'
Combine the descriptor with instances of Pep458Signer to build automated
pipelines that enforce PEP 458's online/offline separation.
Role Guidance
| Role | Default Alg | Threshold | Recommended Expiration |
|---|---|---|---|
root |
RSA-PSS-SHA256 |
2 | P365D |
targets |
Ed25519 |
1 | P90D |
snapshot |
Ed25519 |
1 | P14D |
timestamp |
Ed25519 |
1 | P1D |
These defaults mirror the best practices described in PEP 458, but you can
override them by passing parameters to normalize or adjusting the resulting
policy document.
Relationship to the Signer
This package pairs with swarmauri_signing_pep458, which implements the detached
signature algorithm itself. The cipher suite surfaces metadata while the signer
performs the cryptographic operations.
Development
- Format the code with
ruff format .and lint withruff check . --fix. - Add or update unit tests alongside policy changes to validate normalization and feature reporting.
- Document any new role guidance in both the README and the
policy()payload so downstream systems stay synchronized.
License
This project is licensed under the Apache License 2.0.
Metadata
Release files for swarmauri_cipher_suite_pep458 0.11.0.dev2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_cipher_suite_pep458-0.11.0.dev2.tar.gz | 8.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_cipher_suite_pep458-0.11.0.dev2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 17.9 kB
Release files / swarmauri_cipher_suite_pep458-0.11.0.dev2.tar.gz
| Download URL | swarmauri_cipher_suite_pep458-0.11.0.dev2.tar.gz |
|---|---|
| Size | 8.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
01cb8c7c7d50c0ff3abf487407583cb56f2a963c1f617192e06be30af7508a25
|
|
BLAKE2b-256 checksum How to use checksums |
23eb27dc05f22d3e87b7b85b3056c0e91d1c3b131cc0b03b923320dc5354ff22
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_cipher_suite_pep458-0.11.0.dev2-py3-none-any.whl
| Download URL | swarmauri_cipher_suite_pep458-0.11.0.dev2-py3-none-any.whl |
|---|---|
| Size | 9.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
35c36b67263df866c66646f883fb753f0b9d8e6ab72934c3447738d54482d0fa
|
|
BLAKE2b-256 checksum How to use checksums |
29a8bc6e7f317dde2fd71e2dd279b2c2cffce38a9567c285ae9cbd4d99cb54f9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|