Skip to content

DocFence 0.40.0

Choose a tag to compare

@SybilGambleyyu SybilGambleyyu released this 04 Aug 06:41

DocFence 0.40.0

DocFence 0.40.0 adds a privacy-safe, static declared OPC package-signature
coverage audit for signed Word packages.

  • Adds aggregate-only coverage counts for bound package manifests, bounded Word
    parts and relationships, and unresolved or unsupported references.
  • Adds DFP092 for an opt-in complete static declaration-coverage gate and
    DFP093 for declaration-coverage baseline changes.
  • Resolves exact local manifest part URIs with case-sensitive content-type
    matching and standard OPC relationship-transform SourceId/SourceType
    selectors. Raw package paths, object IDs, reference URIs, relationship
    selectors, and digest material remain private.
  • Keeps the boundary deliberately non-cryptographic: DocFence does not
    recompute digests or canonicalization, verify XMLDSIG/certificates, establish
    trust, or predict Office client behavior.

Verification completed:

  • GitHub Actions passed on Python 3.11, Python 3.13, and the distribution
    build for both the release commit and tag.
  • Local release checks passed: Ruff, 67 tests, package metadata validation, a
    clean installed-wheel smoke, and a public USENIX OOXML Signature Security
    corpus smoke. The signed content-injection baseline passes the strict static
    gate; selected published CIA, USF, DDA, and ETA attacker variants are
    rejected for declaration gaps. This is bounded structural evidence, not a
    signature-validity or client-behavior claim.

Fresh-tag artifact SHA-256:

  • docfence-0.40.0-py3-none-any.whl
    41a0750370d713a43ff25e17ae8543d8607bab63ead4ce7d8b1884d0f2aed5fe
  • docfence-0.40.0.tar.gz
    c0d3b21c2757e176a14ff1af40b39e0ff4d21bcb55c75bfe602de990bc19fd6c