DocFence 0.62.0
Bounded XMLDSIG declaration hardening
DocFence 0.62 makes its static OPC package-signature coverage audit require XMLDSIG’s declared direct attribute surfaces: Reference may use only Id, URI, and Type; its direct DigestMethod must use exactly Algorithm. Unknown attributes no longer lend coverage.
This remains a bounded declaration audit, not full XMLDSIG schema validation, digest or signature verification, certificate validation, or a trust decision.
Verification
- 72 tests, Ruff, and main/tag CI passed on Python 3.11 and 3.13.
- The 29-fixture public OOXML Signature Security corpus had byte-identical captured outcomes relative to 0.61.
- Two epoch-fixed builds were byte-identical.
SHA-256:
docfence-0.62.0-py3-none-any.whl:3667fa38e0596ba177805417003dfdeec6fadee408c5eca8f81f3707191cadc5docfence-0.62.0.tar.gz:a5f0645f614520a5723c37938bf694dc76bfb3ee312ed2b6de68924b0cce67c3