Problem/Motivation

The Automatic Updates Initiative and the Project Browser Initiative both are creating modules that will add user interfaces for running Composer commands to add and update projects.

The initiative team has started implementing The Update Framework (TUF) to enhance security against supply side attacks. As part of #3349368: [policy, no patch] How much of The Update Framework integration is needed for alpha-level review/commit of Package Manager?, it was decided that a production setup of TUF is not a requirement for the alpha release.

In this issue, we need to determine if we can proceed with the beta release even if the production TUF implementation is not complete.

Proposed resolution

A beta level TUF is a requirement for package manager beta.

Remaining tasks

User interface changes

API changes

Data model changes

Release notes snippet

Comments

lauriii created an issue. See original summary.

quietone’s picture

Status: Postponed » Active

There is no indication what this is postponed on, so setting to active.

quietone’s picture

Issue summary: View changes
Status: Active » Postponed
Parent issue: » #3319030: Drupal Core Roadmap for Package Manager and Update Manager

This was originally postponed with no indication of what it was postponed on. I chatted with catch briefly about this issue. From that I learned that the testing in #3477553: [PP-1] Manually test TUF-enabled Composer projects should be complete before delving into this. So, I am postponing on that issue.

quietone’s picture

Title: [policy, no patch] Decide if a production level TUF is a requirement for beta-levelcommit of Package Manager » [policy, no patch] Decide if a production level TUF is a requirement for beta-level commit of Package Manager
Issue summary: View changes
Status: Postponed » Needs review

In a meeting in autoupdates-package-manager today, catch's opinion was that a beta level TUF is a requirement for package manager beta.
He also said that "we need to be able to test tuf with a beta level package manager together, and that really needs that issue done' referrring to https://github.com/php-tuf/php-tuf/issues/396.

I have updated the proposed resolution with that and setting to NR for other opinions.

Version: 11.x-dev » main

Drupal core is now using the main branch as the primary development branch. New developments and disruptive changes should now be targeted to the main branch.

Read more in the announcement.

smustgrave’s picture

This one has been around for months with no movement is there a person that could weigh in on this?

quietone’s picture

I am following this up in the autoupdate-package-manager meetings in slack and with the other release managers.

quietone’s picture

Status: Needs review » Reviewed & tested by the community

On second thought, there has been plenty of time for other opinions. Therefore, setting to RTBC.

catch’s picture

Title: [policy, no patch] Decide if a production level TUF is a requirement for beta-level commit of Package Manager » [policy, no patch] Define that package_manager
Status: Reviewed & tested by the community » Fixed

#3477553: [PP-1] Manually test TUF-enabled Composer projects has had good progress recently, one of the main blockers was closed, although that led to discovering another bug 'underneath' Currently being tracked in #3579174: [meta] Diagnose issues related to TUF-enabled projects and #3580996: Send metapackage composer metadata to Rugged for signing. Without those issues fixed, it's impossible to ask a wider group of people to test php-tuf, and I think that should be one focus of a package_manager beta since we absolutely cannot have composer crashing on people when we eventually enable TUF on all package_manager installs.

Let's mark this fixed.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

catch’s picture

Title: [policy, no patch] Define that package_manager » [policy, no patch] Decide if a production level TUF is a requirement for beta-level commit of Package Manager

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.