DocFence 0.12.0
Package digital-signature evidence
DocFence 0.12 inventories stored OPC package digital-signature material as private, aggregate evidence:
- origin, XML-signature, and certificate part counts;
- SignedInfo, manifest, relationship, inline-X.509, and signature-property counts;
- DFP037 to require a handoff with no stored package-signature material;
- DFP038 to freeze an approved package-signature baseline.
Signature values, signer/certificate material, algorithms, signing times, comments, provider data, reference URIs, relationship IDs, paths, and fingerprints are never emitted. Recognized relationships and basic XMLDSIG shape fail closed. This is not cryptographic verification: DocFence does not validate signatures or digests, certificate chains, revocation, timestamps, signer identity, coverage, policy, or Office trust.
Validation
- 33 tests, Ruff, and compileall
- Python 3.11/3.13 CI
- real public signed-package smoke and unlabelled Open XML SDK docx/dotx zero smoke
- source and wheel independently rebuilt byte-identically
- installed-wheel profile smoke
- SHA256SUMS release asset