DocFence 0.40.0
DocFence 0.40.0
DocFence 0.40.0 adds a privacy-safe, static declared OPC package-signature
coverage audit for signed Word packages.
- Adds aggregate-only coverage counts for bound package manifests, bounded Word
parts and relationships, and unresolved or unsupported references. - Adds
DFP092for an opt-in complete static declaration-coverage gate and
DFP093for declaration-coverage baseline changes. - Resolves exact local manifest part URIs with case-sensitive content-type
matching and standard OPC relationship-transformSourceId/SourceType
selectors. Raw package paths, object IDs, reference URIs, relationship
selectors, and digest material remain private. - Keeps the boundary deliberately non-cryptographic: DocFence does not
recompute digests or canonicalization, verify XMLDSIG/certificates, establish
trust, or predict Office client behavior.
Verification completed:
- GitHub Actions passed on Python 3.11, Python 3.13, and the distribution
build for both the release commit and tag. - Local release checks passed: Ruff, 67 tests, package metadata validation, a
clean installed-wheel smoke, and a public USENIX OOXML Signature Security
corpus smoke. The signed content-injection baseline passes the strict static
gate; selected published CIA, USF, DDA, and ETA attacker variants are
rejected for declaration gaps. This is bounded structural evidence, not a
signature-validity or client-behavior claim.
Fresh-tag artifact SHA-256:
docfence-0.40.0-py3-none-any.whl
41a0750370d713a43ff25e17ae8543d8607bab63ead4ce7d8b1884d0f2aed5fedocfence-0.40.0.tar.gz
c0d3b21c2757e176a14ff1af40b39e0ff4d21bcb55c75bfe602de990bc19fd6c