Skip to content

Address known C2PA conformance program applicant manifest nonconformities #7

@ScottSPerryCPA

Description

@ScottSPerryCPA

As we look at the the Conformulator to add interrogation and assessment capabilities, the following are known issues from a history of applicant samples that the Conformulator product should flag:

  1. Deprecated use of URN (current has c2pa in the body of the identifier)
  2. Deprecated use of c2pa.ingredient.v2 (c2pa.ingredient.v3 pegs to v2.2 of spec)
  3. Deprecated us of stds.schema-org.CreativeWork (now using CAWG)
  4. Deprecated us of c2pa.actions (now using c2pa.actions.v2
  5. Lack of a c2pa inception action (either open or created)
  6. Lack of a DigitalSourcetype for a created action
  7. Deprecated use of an assertions array not grouped by created and gathered assertions (current version groups them)
  8. Placement of standard c2pa assertions in gathered assertions array
  9. Placement of non-generator product claims (CAWG, custom attribution assertions) in created assertions array.
  10. Lack of inclusion of the C2PA Trust List to validate certificate trust (don't know where that occurs but I flag this when applicants show c2pa conformant google files as untrusted.
  11. Lack of evaluating timestamping certificate to indicate that signing cert was valid at time of signing.
  12. (when in use against 2.4 manifests) Empty or missing specversion key. (Conformulator cannot reference the Applicant';s asserted conformance spec level - that still requires manual inspection)
  13. An ingested ingredient that has any of these issues.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions