Skip to content

agent-manifest 0.13.0

Choose a tag to compare

@github-actions github-actions released this 25 Sep 21:14
· 19 commits to main since this release
dbf4a27

agent-manifest 0.13.0 is on PyPI: pip install agent-manifest==0.13.0.

Compatibility: canonicalize() now follows RFC 8785 exactly (#404, closes #322). It no longer NFC-normalizes strings, no longer escapes U+2028, U+2029 or U+007F to U+009F, and refuses integers above 2**53 - 1. A signature that 0.12.0 made over a document containing any of those will not verify. Every other document canonicalizes to the same bytes as before.

Security fixes

  • #404: two distinct strings could share one signature, and two keys that normalized alike produced invalid JSON that silently dropped a signed field.
  • #450: verify_revocation_signature() compares signer_key_id in constant time.
  • #449: ML-DSA-65 public key length is enforced in the hybrid and standalone verifiers.
  • #452: MerkleTree.verify_inclusion() checks tree_size, leaf_index and audit path length, and implements RFC 9162 section 2.1.3.2 in full.
  • #454: verify_delta binds the presented operations to the consistency proof. It now requires a representation keyword.
  • #458: the catalog tree binds each tool's hash algorithm.
  • #418: verify_manifest() recomputes the declared tool catalog root.
  • #445: verify_tdx_quote() checks the PCK chain with the shared verify_cert_chain.
  • #442: manifest keygen no longer has a key-file TOCTOU race.
  • #377, #417: invalid authenticated revocation records are rejected; an empty trusted_key_issuers means trust nobody.
  • #407: POST /verify bounds body size and field count.
  • #373: an Azure platform label is no longer accepted as proof of manifest binding.
  • #459: delegation hop and verify_hitl_approval() signatures go through verify_bytes(), which enforces the 64-byte Ed25519 length. The backend already refused other lengths, so this closes a gap in the SDK's own checks, not a live bypass.

Other fixes
#375, #378, #392, #393, #403, #411, #415, #435, #436, #444, #448, and duration/timestamp validation failing closed.

Added

  • #453: VerificationResult.hitl_admissibility reports undecidable present applicability on its own.
  • Spec section 6.2.1 maps the enforcement mode vocabularies used by the manifest, cMCP and TRACE (#344).

The full list is in CHANGELOG.md.