Skip to content

build(deps): bump weight-custody-manifest from 0.28.4 to 0.28.5 in /demos - #261

Merged
imran-siddique merged 1 commit into
mainfrom
dependabot/pip/demos/weight-custody-manifest-0.28.5
Oct 5, 2026
Merged

imran-siddique merged 1 commit into
mainfrom
dependabot/pip/demos/weight-custody-manifest-0.28.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Bumps weight-custody-manifest from 0.28.4 to 0.28.5.

Release notes

Sourced from weight-custody-manifest's releases.

weight-custody-manifest 0.28.5

pip install weight-custody-manifest==0.28.5

Check before upgrading

  • wcm verify-quote --kind snp without --root now accepts only a pinned AMD ARK (Milan or Genoa). A bundle that carries its own AMD root is no longer trusted for that. Pass the root with --root if you use another one. --kind tdx no longer takes the Intel root pin from the bundle.
  • One key can no longer satisfy two required roles in verify_manifest. role and signer sit outside the signed pre-image, so a builder signature relabelled as custodian or sovereign used to pass as a joint signature. Each required role now needs its own trusted key. The one exception is byom-symmetric with the same identity for builder and custodian, which SPEC 3.1 allows.
  • JsonQuoteParser takes report_data_offset from its own configuration (new keyword, default 0). A container may still carry the field but it must match. Before, the evidence chose which signed 32 bytes the nonce check read.
  • A manifest now requires cryptographic evidence verification unless it says otherwise (#162). New optional field release_policy.require_evidence_verification: absent or true means the KBS must verify the CPU quote and, when presented, the GPU report. A KBS with no verifier for the evidence the manifest requires refuses with WCM-L2-0019 where it used to pass with "structural trust only". The field is optional, so an existing signed manifest keeps its pre-image, but a manifest that is silent on it now requires verification.
  • tools/nvat_adapter.py no longer asserts confidential-compute mode. It emitted cc_mode: True unconditionally; it now emits unknown, which the gate denies (WCM-L2-0018). With a GPU verifier configured, a verified GPU report satisfies require_cc_mode and no waiver is needed.

To keep a deployment on mock or unverified evidence releasing, set both waivers in the manifest and re-sign it: release_policy.require_evidence_verification: false and, if a GPU is required, required_gpu_measurement.require_cc_mode: false. wcm gate now reports the checks mock evidence cannot satisfy as SKIP rather than FAIL.

Verification fixes (#163)

  • verify_tdx_quote checks that the QE report is Intel's TD Quoting Enclave (Intel PCS QE identity: MRSIGNER, ISVPRODID 2, masked attributes and MISCSELECT) and that the QE REPORT_DATA tail is zero. Before, any enclave the PCK certified could vouch for an attestation key.
  • Certificate chains require every issuer to be a CA (basicConstraints, pathLenConstraint, keyCertSign), so a leaf under a trusted root can no longer issue.
  • EnclaveSession.from_release refuses a manifest other than the one the key was released against, since cadence and time floor are read from it.
  • ChallengeStore is thread-safe (two concurrent presentations of one nonce both passed) and drops expired challenges instead of keeping every nonce ever issued.
  • Malformed input returns a denial instead of raising from AzureSnpVtpmVerifier, parse_tdx_quote, JsonQuoteParser and NvidiaGpuVerifier.
  • HashValue rejects a trailing newline, Merkle inclusion rejects a leaf index outside the tree, and combine_shares rejects share x outside 1..255.
  • verify_and_release refuses input that does not canonicalize (a lone surrogate) before consuming the nonce. verify_for_renewal raises ValueError for that input.
  • seal_to_public_key raises SealError for a low-order X25519 key, and the KBS turns that into a denial (key_sealed).
  • artifact_digest takes each file's size and bytes from one open handle, raises if they disagree, and opens with O_NOFOLLOW where available.
  • verify_log_consistency takes an optional log_public_key and then requires both heads to verify; a malformed root returns False.
  • The Azure TDX provider takes no nonce-bound vTPM quote, so its evidence has no freshness binding. The docstrings that said otherwise are corrected, and LIMITATIONS.md says so.

Conformance

  • First real-silicon vendor vector (#160): a genuine Azure SEV-SNP report verified against an independently staged AMD ARK-Milan root, with all six mandatory refusal mutations. Intel TDX and GPU vendor vectors remain uncovered.
  • Ten gate vectors gained explicit waivers, and two were added: deny-evidence-verification-required-without-verifier and deny-gpu-cc-mode-asserted-but-unverified.
  • H100 captures with the mode on and off, the attestation certificate chain and the capture tool are under python/tests/fixtures/nvidia/cc-mode and tools/capture_gpu_cc_mode.py.

Deprecated

GpuReport.cc_mode. It is still accepted and an explicit False still denies, but True and None are ignored. It will be removed in a later release.

Build

CI and the fuzz build install third-party dependencies from hash-locked files under requirements/ (#164). Workflow write permissions are scoped to the jobs that use them (#165). The package's runtime dependencies are unchanged.

Full notes: CHANGELOG.md

Changelog

Sourced from weight-custody-manifest's changelog.

0.28.5 - 2026-09-26

Add the first real-silicon vendor conformance vector: a genuine Azure SEV-SNP report verified against an independently staged AMD ARK-Milan root. The scored case declares the paravisor's vTPM-attestation-key binding and derives all six mandatory refusal mutations, so passing L2 now exercises real AMD report bytes rather than only the synthetic quote container. Intel TDX and GPU vendor vectors remain explicitly uncovered. The legacy SDK fixture no longer carries its own trust anchor; callers stage the same named root independently.

Changed (behaviour). tools/nvat_adapter.py no longer asserts confidential-compute mode. It emitted cc_mode: True unconditionally, so the gate added in GHSA-j665-99rh-w85h read a constant from the adapter rather than evidence from the device and could not deny along that path. It now emits unknown, which the gate denies (WCM-L2-0018).

A release through this adapter therefore fails closed. A deployment that accepts the risk can waive the check with required_gpu_measurement.require_cc_mode: false, which is the existing, explicit waiver and belongs to whoever signs the manifest. The adapter does not set it and nothing enables it automatically.

Captures from an H100 with the mode on and off, the attestation certificate chain, and the capture tool are under python/tests/fixtures/nvidia/cc-mode and tools/capture_gpu_cc_mode.py. They establish that this adapter cannot read the mode from what it receives. They do not establish what every device, driver or host configuration reports.

Fixed (verification). A sweep of the verifiers and the release path:

  • verify_manifest no longer lets one key satisfy two required roles. role and signer sit outside the signed pre-image, so a builder's signature relabelled as custodian (or sovereign) passed as a joint signature. Each required role now needs its own trusted key; byom-symmetric with one identity for builder and custodian keeps the single-key case SPEC 3.1 allows.
  • verify_tdx_quote checks that the QE report is Intel's TD Quoting Enclave (Intel PCS QE identity: MRSIGNER, ISVPRODID 2, masked attributes and MISCSELECT) and that the QE REPORT_DATA tail is zero. Before, any enclave the PCK certified could vouch for an attestation key.
  • Certificate chains require every issuer to be a CA (basicConstraints, pathLenConstraint, keyCertSign), so a leaf under a trusted root can no longer issue.
  • wcm verify-quote --kind snp no longer trusts the AMD root carried in the bundle unless it is a pinned ARK (Milan, Genoa) or passed with --root, and --kind tdx no longer takes the Intel root pin from the bundle.
  • EnclaveSession.from_release refuses a manifest other than the one the key was released against, since cadence and time floor are read from it.
  • ChallengeStore is thread-safe (two concurrent presentations of one nonce both passed) and drops expired challenges instead of keeping every nonce ever issued.

... (truncated)

Commits
  • 94d5519 chore(release): 0.28.5 (#166)
  • d7a66ae ci: scope workflow write permissions to the job that uses them (#165)
  • f0199c0 ci: hash-pin pip installs in workflows and the fuzz build (#164)
  • 8a716d2 feat(kbs): let the manifest require evidence verification (#162)
  • c8a2f72 fix(security): TDX QE identity, role-bound joint signatures, CA-only issuers,...
  • bd36cf7 fix(nvat): emit unknown confidential-compute mode instead of asserting it
  • 2341ab0 feat(conformance): add real AMD SEV-SNP vector (#160)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 2, 2026
Bumps [weight-custody-manifest](https://github.com/agentrust-io/weight-custody-manifest) from 0.28.4 to 0.28.5.
- [Release notes](https://github.com/agentrust-io/weight-custody-manifest/releases)
- [Changelog](https://github.com/agentrust-io/weight-custody-manifest/blob/main/CHANGELOG.md)
- [Commits](agentrust-io/weight-custody-manifest@v0.28.4...v0.28.5)

---
updated-dependencies:
- dependency-name: weight-custody-manifest
  dependency-version: 0.28.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/demos/weight-custody-manifest-0.28.5 branch from aeb919c to 42f4171 Compare October 4, 2026 18:19

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot bump. Every check is green apart from the maintainer hold.

@imran-siddique
imran-siddique merged commit 556d702 into main Oct 5, 2026
54 of 55 checks passed
@imran-siddique
imran-siddique deleted the dependabot/pip/demos/weight-custody-manifest-0.28.5 branch October 5, 2026 21:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant