DocFence 0.53.0
DocFence 0.53 applies OPC's hard MD5 prohibition to every XMLDSIG DigestMethod in a recognized package signature, not only static coverage references.
It rejects MD5 on application-object and other non-coverage references. SHA-1 remains structurally accepted because OPC says it should not be used, rather than shall not.
This remains a static structural boundary: DocFence does not recompute digests, evaluate XMLDSIG, canonicalize XML, or establish trust.
Validation: 69 tests; 29 public DOCX profiles unchanged from 0.52; a native application-object SHA-1 mutation accepts while MD5 rejects; clean wheel and sdist builds.