This release is a pre-release and may not be stable for production use.
swarmauri_signing_pep458
swarmauri_signing_pep458 packages a detached signature provider that implements
PEP 458 style signing for The Update Framework
(TUF) metadata. It brings canonical JSON, multi-algorithm support, and quorum-aware
verification to the Swarmauri runtime so supply-chain aware components can produce
and validate repository metadata with a uniform API.
Key Features
- PEP 458 compatible format ? Signatures emit the
tuf/pep458envelope withmethod,keyid, and base64-encoded payloads so the metadata aligns with the specification's detached signature requirements. - Deterministic canonicalization ? Canonicalizes envelopes using TUF's lexicographically-sorted JSON encoding to guarantee byte-for-byte reproducibility.
- Multiple signature algorithms ? Supports Ed25519 for online roles and RSA-PSS-SHA256 for offline root-style metadata, allowing you to mix schemes per role.
- Quorum aware verification ? Enforces
min_signers, explicit key-id allow lists, and algorithm restrictions during verification to help model offline threshold signing policies. - Flexible key inputs ? Accepts cryptography key objects, PEM encoded key
material, or Swarmauri
KeyRefdictionaries for both signing and verification.
Installation
Using uv
uv add swarmauri_signing_pep458
Using pip
pip install swarmauri_signing_pep458
Quick Start
import asyncio
from cryptography.hazmat.primitives.asymmetric import ed25519
from swarmauri_signing_pep458 import Pep458Signer
async def main() -> None:
signer = Pep458Signer()
private = ed25519.Ed25519PrivateKey.generate()
keyref = {"kind": "cryptography_obj", "obj": private, "alg": "Ed25519"}
payload = b"release metadata"
signatures = await signer.sign_bytes(keyref, payload)
is_valid = await signer.verify_bytes(
payload,
signatures,
opts={"pubkeys": [private.public_key()]},
)
print(f"Signature valid? {is_valid}")
asyncio.run(main())
Signature Format
Each signature returned by the signer follows this shape:
{
"format": "tuf/pep458",
"method": "ed25519",
"alg": "Ed25519",
"keyid": "base64(SHA256(method || SPKI))",
"sig": "base64(signature-bytes)"
}
Use the method label when matching public keys and verifying thresholds for a
particular TUF role.
Verification Policy Hints
The verify_bytes and verify_envelope APIs accept a require mapping with the
following helpful keys:
min_signers: Require at least n distinct key ids to validate.algs: Restrict verification to a subset of algorithms, e.g.("Ed25519",). The values are normalized case-insensitively.kids: Whitelist key identifiers allowed to satisfy the policy.pubkeys: Explicit public key materials to use when verifying (PEM strings, cryptography objects, or{"kind": "pem", "pub": ...}dictionaries).
Relationship to the Cipher Suite
Pair this package with swarmauri_cipher_suite_pep458 to describe repository role
policies, canonicalization settings, and default algorithm choices across the
Swarmauri ecosystem.
Development
- Format the code with
ruff format .and lint withruff check . --fix. - Run the asynchronous unit tests with
pytestonce cryptography dependencies are available. - Contributions should include updates to documentation fragments and policy tables when new capabilities are added.
License
This project is licensed under the Apache License 2.0.
Metadata
Release files for swarmauri_signing_pep458 0.11.0.dev1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_signing_pep458-0.11.0.dev1.tar.gz | 10.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_signing_pep458-0.11.0.dev1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 21.2 kB
Release files / swarmauri_signing_pep458-0.11.0.dev1.tar.gz
| Download URL | swarmauri_signing_pep458-0.11.0.dev1.tar.gz |
|---|---|
| Size | 10.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3be581d90cafe442b7487dbfcb4dfdca58bb2516a0df742bbfc829bb1f319a92
|
|
BLAKE2b-256 checksum How to use checksums |
5edaea841ef8b6095f1735d2bcf9cc3e83914057b45ad5dc10305ab6b717d14f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_signing_pep458-0.11.0.dev1-py3-none-any.whl
| Download URL | swarmauri_signing_pep458-0.11.0.dev1-py3-none-any.whl |
|---|---|
| Size | 11.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0a175daa2deb5da69754a7c32f53d6f71f9663ac83c3da333092153fce21c19a
|
|
BLAKE2b-256 checksum How to use checksums |
1b76fbef0efe093ee2655c1e48b901e91394f4cfde779e95d89adc5c3dfc69db
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|