DocFence 0.48.0
Static OPC package-signature coverage now also requires a conforming XMLDSIG Reference where SignedInfo binds idPackageObject.
- Requires ordered optional
Transforms,DigestMethod, thenDigestValuechildren. - Allows no transforms or a direct nonempty list of OPC XML Canonicalization algorithms; relationship, unknown, empty, and duplicate lists are rejected.
- Malformed binding declarations leave coverage unavailable. This remains structural parsing, not digest computation, transform execution, XMLDSIG validation, certificate validation, trust, or Office-client validation.
Verification: 69 tests, DCAB adapter against the released wheel, public signed-corpus compatibility smoke, deterministic wheel/source builds, and passing main/tag CI.
SHA-256
docfence-0.48.0-py3-none-any.whl:9e32487c67583e8b92aedcc9038afb66590f0e3b89c993b918a6e791e952319ddocfence-0.48.0.tar.gz:a220190c360a0d831b88cac896047dfbd79517fcf4f23eacfe051b515e4e66fc