agent-manifest 0.13.0
·
19 commits
to main
since this release
agent-manifest 0.13.0 is on PyPI: pip install agent-manifest==0.13.0.
Compatibility: canonicalize() now follows RFC 8785 exactly (#404, closes #322). It no longer NFC-normalizes strings, no longer escapes U+2028, U+2029 or U+007F to U+009F, and refuses integers above 2**53 - 1. A signature that 0.12.0 made over a document containing any of those will not verify. Every other document canonicalizes to the same bytes as before.
Security fixes
- #404: two distinct strings could share one signature, and two keys that normalized alike produced invalid JSON that silently dropped a signed field.
- #450:
verify_revocation_signature()comparessigner_key_idin constant time. - #449: ML-DSA-65 public key length is enforced in the hybrid and standalone verifiers.
- #452:
MerkleTree.verify_inclusion()checkstree_size,leaf_indexand audit path length, and implements RFC 9162 section 2.1.3.2 in full. - #454:
verify_deltabinds the presented operations to the consistency proof. It now requires arepresentationkeyword. - #458: the catalog tree binds each tool's hash algorithm.
- #418:
verify_manifest()recomputes the declared tool catalog root. - #445:
verify_tdx_quote()checks the PCK chain with the sharedverify_cert_chain. - #442:
manifest keygenno longer has a key-file TOCTOU race. - #377, #417: invalid authenticated revocation records are rejected; an empty
trusted_key_issuersmeans trust nobody. - #407:
POST /verifybounds body size and field count. - #373: an Azure platform label is no longer accepted as proof of manifest binding.
- #459: delegation hop and
verify_hitl_approval()signatures go throughverify_bytes(), which enforces the 64-byte Ed25519 length. The backend already refused other lengths, so this closes a gap in the SDK's own checks, not a live bypass.
Other fixes
#375, #378, #392, #393, #403, #411, #415, #435, #436, #444, #448, and duration/timestamp validation failing closed.
Added
- #453:
VerificationResult.hitl_admissibilityreports undecidable present applicability on its own. - Spec section 6.2.1 maps the enforcement mode vocabularies used by the manifest, cMCP and TRACE (#344).
The full list is in CHANGELOG.md.