Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

python312-sigstore-4.1.0-2.1 RPM for noarch

From OpenSuSE Ports Tumbleweed for noarch

Name: python312-sigstore Distribution: openSUSE Tumbleweed
Version: 4.1.0 Vendor: openSUSE
Release: 2.1 Build date: Mon Nov 10 09:18:47 2025
Group: Unspecified Build host: reproducible
Size: 666424 Source RPM: python-sigstore-4.1.0-2.1.src.rpm
Packager: http://bugs.opensuse.org
Url: https://github.com/sigstore/sigstore-python
Summary: A tool for signing Python package distributions
sigstore is a Python tool for generating and verifying Sigstore
signatures. You can use it to sign and verify Python package
distributions, or anything else!

Provides

Requires

License

Apache-2.0

Changelog

* Mon Nov 10 2025 Dirk Müller <dmueller@suse.com>
  - remove sigstore-protobuf-specs:
    * replaced by sigstore-models
* Fri Nov 07 2025 Matej Cepl <mcepl@cepl.eu>
  - Add nofail-neg-test.patch to fix OpenSSL configuration on SUSE
    platforms (gh#sigstore/sigstore-python!1605).
* Tue Nov 04 2025 Matej Cepl <mcepl@cepl.eu>
  - Update to 4.1.0:
    - cli: Support using other Sigstore instances with --instance
      URL. New instances are trusted with new top level command
      trust-instance ROOTFILE. #1548
    - Added cryptography 46 to list of compatible cryptography
      releases (#1544)
    - Improved error message when verifying bundles with
      unsupported log entry versions (#1569)
    - cli: Always read/write UTF-8. This fixes an issue on Windows
      where the platform default encoding was used: the issue has
      existed for a while, but became more visible with signature
      bundles that contain rekor2 entries. #1553
  - Update to 4.0.0:
    This is a major release with a host of API and functionality
    changes. The major new feature is Rekor v2 support but many
    other changes are also included, see list below.
    - cli: Add --rekor-version to sign command arguments: This
      can be useful if Sigstore instance provides multiple Rekor
      versions and user wants to override the default choice #1471
    - cli: Support parallel signing. When multiple artifacts are
      signed, the Rekor requests are submitted in parallel: this is
      especially useful with Rekor v2. #1468, #1478, #1485
    - oidc (API): Allow custom audience claims via API #1402
    - rekor (API): Support Rekor v2 (aka rekor-tiles) in both
      verification and signing. #1370, #1422, #1432
    - trust (API): Make TrustedRoot, SigningConfig and
      ClientTrustConfig public API #1496
    - cli: Improve verify UX when wrong instance is used #1510
    - deps: replace sigstore_protobuf_specs dependency with
      sigstore-models #1470
    - trust: Update embedded TUF root #1515
    - trust (API): TrustConfig now provides the production()and
      staging() helpers. Similar methods were removed from
      SigningConfig, TrustedRoot, SigningContext and Issuer. Use
      TrustConfig everywhere in code base. #1363
    - trust (API): support SigningConfig v0.2, remove support for
      v0.1. The new format now fully defines the sigstore instance
      the client uses. SigningConfig class now has methods to
      return actual clients (like RekorClient) instead of just URLs
      for that sigstore instance. The --trust-config cli option now
      expects the trust config to contain a v0.2 SigningConfig.
      [#1358], #1407
    - trust: Support ed25519 keys in trusted root #1377
    - rekor: resolve circular import of LogEntry #1458
    - rekor: Fix checkpoint signature lookup when there are
      multiple signatures #1514
    - rekor: Fix entry handling so inclusion promise is optional
      [#1382]
    - rekor: Avoid trailing slash in post to /entries #1366
    - sign: fetch TSA timestamps before submitting an entry to
      Rekor #1463
    - timestamp: Specify sha256 in TSA timestamp request #1373
    - trust: Fail less hard when trusted root contains unknown keys
      [#1424]
    - verify: Fix TSA cert chain construction (fixes issue in the
      case where certificate is not embedded in the timestamp)
      [#1482]
    - verify: Use TSA hash algorithm specified in the timestamp
      (SHA-256, SHA-384 and SHA-512 are supported) #1385
    - verify: Check artifact signing time against all established
      times #1381
    - verify: Handle unset TSA timestamp validity end #1368
  - Update to 3.6.6:
    - Improved error message when verifying bundles with rekor v2
      entries (#1565)
    - Added cryptography 46 to list of compatible cryptography
      releases (#1566)
  - Update to 3.6.5:
    - Fixed verified time handling so that additional timestamps
      cannot break otherwise valid signature bundles (#1492)
    - Added cryptography 45 to list of compatible cryptography
      releases (#1498)
  - Update to 3.6.4:
    - Bumped the rfc3161-client dependency to >=1.0.3 to fix a
      security vulnerability (#1451)
  - Update to 3.6.3:
    - Verify: Avoid hard failure if trusted root contains
      unsupported keytypes (as verification may succeed without
      that key). #1425
  - Add fix-ecparam-testing.patch patch to overcome a FTBFS bug
    (gh#sigstore/sigstore-python#1603).
* Wed Apr 16 2025 Steve Kowalik <steven.kowalik@suse.com>
  - Update to 3.6.2:
    * Fixed issue where a trust root with multiple rekor keys was not considered
      valid.
    * Upgraded python-tuf dependency to 6.0.
    * Updated the embedded TUF root to version 12
* Tue Jan 21 2025 Daniel Garcia <daniel.garcia@suse.com>
  - Initial version (3.6.1)

Files

/usr/bin/sigstore
/usr/bin/sigstore-3.12
/usr/lib/python3.12/site-packages/sigstore
/usr/lib/python3.12/site-packages/sigstore-4.1.0.dist-info
/usr/lib/python3.12/site-packages/sigstore-4.1.0.dist-info/INSTALLER
/usr/lib/python3.12/site-packages/sigstore-4.1.0.dist-info/METADATA
/usr/lib/python3.12/site-packages/sigstore-4.1.0.dist-info/RECORD
/usr/lib/python3.12/site-packages/sigstore-4.1.0.dist-info/REQUESTED
/usr/lib/python3.12/site-packages/sigstore-4.1.0.dist-info/WHEEL
/usr/lib/python3.12/site-packages/sigstore-4.1.0.dist-info/entry_points.txt
/usr/lib/python3.12/site-packages/sigstore-4.1.0.dist-info/licenses
/usr/lib/python3.12/site-packages/sigstore-4.1.0.dist-info/licenses/LICENSE
/usr/lib/python3.12/site-packages/sigstore/__init__.py
/usr/lib/python3.12/site-packages/sigstore/__main__.py
/usr/lib/python3.12/site-packages/sigstore/__pycache__
/usr/lib/python3.12/site-packages/sigstore/__pycache__/__init__.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/__init__.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/__main__.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/__main__.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/_cli.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/_cli.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/_utils.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/_utils.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/errors.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/errors.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/hashes.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/hashes.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/models.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/models.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/oidc.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/oidc.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/sign.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/__pycache__/sign.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_cli.py
/usr/lib/python3.12/site-packages/sigstore/_internal
/usr/lib/python3.12/site-packages/sigstore/_internal/__init__.py
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/__init__.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/__init__.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/key_details.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/key_details.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/merkle.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/merkle.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/sct.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/sct.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/timestamp.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/timestamp.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/trust.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/trust.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/tuf.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/__pycache__/tuf.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/fulcio
/usr/lib/python3.12/site-packages/sigstore/_internal/fulcio/__init__.py
/usr/lib/python3.12/site-packages/sigstore/_internal/fulcio/__pycache__
/usr/lib/python3.12/site-packages/sigstore/_internal/fulcio/__pycache__/__init__.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/fulcio/__pycache__/__init__.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/fulcio/__pycache__/client.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/fulcio/__pycache__/client.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/fulcio/client.py
/usr/lib/python3.12/site-packages/sigstore/_internal/key_details.py
/usr/lib/python3.12/site-packages/sigstore/_internal/merkle.py
/usr/lib/python3.12/site-packages/sigstore/_internal/oidc
/usr/lib/python3.12/site-packages/sigstore/_internal/oidc/__init__.py
/usr/lib/python3.12/site-packages/sigstore/_internal/oidc/__pycache__
/usr/lib/python3.12/site-packages/sigstore/_internal/oidc/__pycache__/__init__.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/oidc/__pycache__/__init__.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/oidc/__pycache__/oauth.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/oidc/__pycache__/oauth.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/oidc/oauth.py
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/__init__.py
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/__pycache__
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/__pycache__/__init__.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/__pycache__/__init__.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/__pycache__/checkpoint.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/__pycache__/checkpoint.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/__pycache__/client.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/__pycache__/client.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/__pycache__/client_v2.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/__pycache__/client_v2.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/checkpoint.py
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/client.py
/usr/lib/python3.12/site-packages/sigstore/_internal/rekor/client_v2.py
/usr/lib/python3.12/site-packages/sigstore/_internal/sct.py
/usr/lib/python3.12/site-packages/sigstore/_internal/timestamp.py
/usr/lib/python3.12/site-packages/sigstore/_internal/trust.py
/usr/lib/python3.12/site-packages/sigstore/_internal/tuf.py
/usr/lib/python3.12/site-packages/sigstore/_store
/usr/lib/python3.12/site-packages/sigstore/_store/__init__.py
/usr/lib/python3.12/site-packages/sigstore/_store/__pycache__
/usr/lib/python3.12/site-packages/sigstore/_store/__pycache__/__init__.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/_store/__pycache__/__init__.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/_store/https%3A%2F%2Ftuf-repo-cdn.sigstage.dev
/usr/lib/python3.12/site-packages/sigstore/_store/https%3A%2F%2Ftuf-repo-cdn.sigstage.dev/root.json
/usr/lib/python3.12/site-packages/sigstore/_store/https%3A%2F%2Ftuf-repo-cdn.sigstage.dev/signing_config.v0.2.json
/usr/lib/python3.12/site-packages/sigstore/_store/https%3A%2F%2Ftuf-repo-cdn.sigstage.dev/trusted_root.json
/usr/lib/python3.12/site-packages/sigstore/_store/https%3A%2F%2Ftuf-repo-cdn.sigstore.dev
/usr/lib/python3.12/site-packages/sigstore/_store/https%3A%2F%2Ftuf-repo-cdn.sigstore.dev/root.json
/usr/lib/python3.12/site-packages/sigstore/_store/https%3A%2F%2Ftuf-repo-cdn.sigstore.dev/signing_config.v0.2.json
/usr/lib/python3.12/site-packages/sigstore/_store/https%3A%2F%2Ftuf-repo-cdn.sigstore.dev/trusted_root.json
/usr/lib/python3.12/site-packages/sigstore/_utils.py
/usr/lib/python3.12/site-packages/sigstore/dsse
/usr/lib/python3.12/site-packages/sigstore/dsse/__init__.py
/usr/lib/python3.12/site-packages/sigstore/dsse/__pycache__
/usr/lib/python3.12/site-packages/sigstore/dsse/__pycache__/__init__.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/dsse/__pycache__/__init__.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/dsse/__pycache__/_predicate.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/dsse/__pycache__/_predicate.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/dsse/_predicate.py
/usr/lib/python3.12/site-packages/sigstore/errors.py
/usr/lib/python3.12/site-packages/sigstore/hashes.py
/usr/lib/python3.12/site-packages/sigstore/models.py
/usr/lib/python3.12/site-packages/sigstore/oidc.py
/usr/lib/python3.12/site-packages/sigstore/py.typed
/usr/lib/python3.12/site-packages/sigstore/sign.py
/usr/lib/python3.12/site-packages/sigstore/verify
/usr/lib/python3.12/site-packages/sigstore/verify/__init__.py
/usr/lib/python3.12/site-packages/sigstore/verify/__pycache__
/usr/lib/python3.12/site-packages/sigstore/verify/__pycache__/__init__.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/verify/__pycache__/__init__.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/verify/__pycache__/policy.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/verify/__pycache__/policy.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/verify/__pycache__/verifier.cpython-312.opt-1.pyc
/usr/lib/python3.12/site-packages/sigstore/verify/__pycache__/verifier.cpython-312.pyc
/usr/lib/python3.12/site-packages/sigstore/verify/policy.py
/usr/lib/python3.12/site-packages/sigstore/verify/verifier.py
/usr/share/doc/packages/python312-sigstore
/usr/share/doc/packages/python312-sigstore/README.md
/usr/share/libalternatives/sigstore
/usr/share/libalternatives/sigstore/312.conf
/usr/share/licenses/python312-sigstore
/usr/share/licenses/python312-sigstore/LICENSE


Generated by rpm2html 1.8.1

Fabrice Bellet, Thu Nov 13 22:53:28 2025