feat(ngclient): require explicit bootstrap argument
details
- Finding IDs
- F-TUF-PYTUF-002
- Status
- merged
- Reported date
- Rationale
- prevents accidental insecure bootstrap behavior by requiring explicit bootstrap intent.
- PR opened by
- @1seal
- PR state observed
- closed; GitHub merged: true; 2026-09-24
- PR observation basis
- Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
- Contribution boundary
- @1seal opened this PR; this alone does not establish sole code authorship.
F-TUF-PYTUF-002: Verification failures. Bootstrap handling requires an explicit trusted starting point. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-TUF-PYTUF-002
Security area (1seal assessment): Provenance. Explicit bootstrap makes the initial trusted metadata origin a caller decision; this is trust-root provenance hardening. Reviewed 24 Sep 2026.