Skip to content

v0.3.0: Secure Image ID Verification

Choose a tag to compare

@garyrob garyrob released this 16 Aug 16:21
· 7 commits to main since this release

Breaking Changes

  • Security: Receipt.verify() now requires image_id parameter to prevent deriving image ID from untrusted receipt data

What's Changed

Security Improvements

  • Enforced external image ID verification in verify() method
  • Follows security best practice: never trust data from unverified sources
  • Prevents potential security vulnerabilities from trusting receipt-provided image IDs

Test Suite Enhancements

  • Added comprehensive test suite with zero-tolerance policy
  • Created run_all_tests.sh master test runner
  • All tests and demos now return proper exit codes (0 for success, 1 for failure)
  • Test runner aborts immediately on first failure
  • Added security verification tests

API Refinements

  • Simplified API with consistent naming conventions
  • Removed legacy code and unnecessary complexity
  • Better error messages and validation
  • Cleaner module structure

Files Changed

  • Modified receipt verification to require external image ID
  • Updated all demos and tests to pass image ID to verify()
  • Added new security tests
  • Created unified test runner

Installation

# For development
uv tool run maturin build --release
uv pip install --force-reinstall target/wheels/PyR0-*.whl

Full Changelog: v0.2.0...v0.3.0