Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Swarmauri Logo

PyPI - Downloads Hits PyPI - Python Version PyPI - License PyPI - swarmauri_cipher_suite_pep458 Discord

swarmauri_cipher_suite_pep458

swarmauri_cipher_suite_pep458 captures the policy surface and algorithm registry that PEP 458 describes for securing Python package repositories. The suite models canonicalization, allowed algorithms, role thresholds, and metadata lifetimes so Swarmauri services can negotiate the same expectations when they sign or verify TUF metadata.

Highlights

  • Explicit role policies ? Encodes recommended thresholds, expiration windows, and algorithm selections for the canonical root, targets, snapshot, and timestamp metadata roles.
  • Deterministic defaults ? Advertises TUF canonical JSON (tuf-json) as the canonicalization format and returns Ed25519 as the default online algorithm while still supporting RSA-PSS-SHA256 for offline roots.
  • Descriptor normalization ? Produces rich normalized descriptors containing the signer implementation hint (swarmauri_signing_pep458.Pep458Signer), canonical preferences, and caller-specified policy overrides.
  • Compliance metadata ? Surfaces machine readable notes indicating PEP 458 and TUF compatibility, enabling automated linting and negotiation between components.

Installation

Using uv

uv add swarmauri_cipher_suite_pep458

Using pip

pip install swarmauri_cipher_suite_pep458

Quick Usage

from swarmauri_cipher_suite_pep458 import Pep458CipherSuite

suite = Pep458CipherSuite()

print(suite.features())
# {'suite': 'pep458', 'version': 1, ...}

descriptor = suite.normalize(op="sign", params={"role": "targets", "threshold": 2})
print(descriptor["mapped"]["provider"]["signer"])
# 'swarmauri_signing_pep458.Pep458Signer'

Combine the descriptor with instances of Pep458Signer to build automated pipelines that enforce PEP 458's online/offline separation.

Role Guidance

Role Default Alg Threshold Recommended Expiration
root RSA-PSS-SHA256 2 P365D
targets Ed25519 1 P90D
snapshot Ed25519 1 P14D
timestamp Ed25519 1 P1D

These defaults mirror the best practices described in PEP 458, but you can override them by passing parameters to normalize or adjusting the resulting policy document.

Relationship to the Signer

This package pairs with swarmauri_signing_pep458, which implements the detached signature algorithm itself. The cipher suite surfaces metadata while the signer performs the cryptographic operations.

Development

  • Format the code with ruff format . and lint with ruff check . --fix.
  • Add or update unit tests alongside policy changes to validate normalization and feature reporting.
  • Document any new role guidance in both the README and the policy() payload so downstream systems stay synchronized.

License

This project is licensed under the Apache License 2.0.

Metadata

Release files for swarmauri_cipher_suite_pep458 0.11.0.dev2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for swarmauri_cipher_suite_pep458 0.11.0.dev2
File Size Uploaded
swarmauri_cipher_suite_pep458-0.11.0.dev2.tar.gz 8.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for swarmauri_cipher_suite_pep458 0.11.0.dev2
File Interpreter ABI Platform
swarmauri_cipher_suite_pep458-0.11.0.dev2-py3-none-any.whl Python 3 none any Details

Total release size: 17.9 kB

Release files / swarmauri_cipher_suite_pep458-0.11.0.dev2.tar.gz

Download URL swarmauri_cipher_suite_pep458-0.11.0.dev2.tar.gz
Size 8.5 kB
Tags Source
SHA-256 checksum
How to use checksums
01cb8c7c7d50c0ff3abf487407583cb56f2a963c1f617192e06be30af7508a25
BLAKE2b-256 checksum
How to use checksums
23eb27dc05f22d3e87b7b85b3056c0e91d1c3b131cc0b03b923320dc5354ff22
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / swarmauri_cipher_suite_pep458-0.11.0.dev2-py3-none-any.whl

Download URL swarmauri_cipher_suite_pep458-0.11.0.dev2-py3-none-any.whl
Size 9.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
35c36b67263df866c66646f883fb753f0b9d8e6ab72934c3447738d54482d0fa
BLAKE2b-256 checksum
How to use checksums
29a8bc6e7f317dde2fd71e2dd279b2c2cffce38a9567c285ae9cbd4d99cb54f9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page