Skip to content

DocFence 0.56.0

Choose a tag to compare

@SybilGambleyyu SybilGambleyyu released this 06 Aug 10:15

DocFence 0.56.0 enforces OPC §10.5.8.1 across every XMLDSIG Transform in a recognized package signature: its Algorithm must be one of OPC's two XML Canonicalization URIs or the OPC Relationship Transform URI. Missing or other algorithms now fail the recognized signature shape closed.

This is a stored-syntax boundary, applied before the bounded declaration-coverage audit. DocFence does not resolve or execute transforms, recompute a digest, verify XMLDSIG, or make a trust decision.

Validation:

  • 69 tests passed locally and in tagged CI on Python 3.11 and 3.13.
  • 0.55 accepts a fully declared synthetic signature with an unsupported transform on an extra SignedInfo reference; 0.56 rejects it. Unsupported transforms in package-object binding and package-part declarations are also rejected, while an allowed extra canonicalization transform remains accepted.
  • The public OOXML Signature Security corpus has 29 DOCX files, 22 XML signature parts, and 21 parseable signature parts. It uses 38 OPC Relationship Transforms and 63 XML Canonicalization Transforms, with zero non-OPC algorithms; public profiles are unchanged from 0.55.
  • Two independent tagged builds were byte-identical.

SHA-256:

  • docfence-0.56.0-py3-none-any.whl: 7d9fad797cccab7223b6202db5c938ba7cb5ddb46c9833234965158bd0bea718
  • docfence-0.56.0.tar.gz: eb7ebc50321b1444817e0733a16d66e045d3c9dfd71c4551ef35c6843eb210e0