DocFence 0.46.0
Static package-signature coverage now accepts only the exact OPC package-specific topology: one direct ds:Object whose only attribute is Id="idPackageObject", direct ds:Manifest then ds:SignatureProperties children, and exactly one direct SignedInfo reference to that object. Nonstandard IDs, missing or extra children, duplicate package objects, and duplicate bindings leave coverage unavailable rather than contributing arbitrary manifest coverage.
This remains a bounded structural declaration audit. DocFence uses only the binding Reference URI fragment; it does not parse or validate that Reference digest or transforms, recompute manifest digests, validate signatures or certificates, establish trust, or predict Office client behavior.
Artifact SHA-256:
- docfence-0.46.0-py3-none-any.whl: ee2b710e6f712c2cbebcc0c2a4247dc476b390c286b643efac9662f57a898b44
- docfence-0.46.0.tar.gz: f96301ccb9000021d1ce138afb1a95fb8b3b71746709950c63e193e3f25c3604