DocFence 0.48.0 Tightens XMLDSIG Package Binding Syntax Checks for OOXML Files
DocFence version 0.48.0 introduces stricter structural validation of XMLDSIG package bindings in OOXML documents, focusing on the shape of ds:Reference elements within signed packages. The tool checks that DigestMethod carries a non-blank algorithm, DigestValue is direct and non-empty, and any transform list uses only recognized XML canonicalization forms. It does not verify, decode, or recompute signatures, nor does it assess trust or certificate validity — its scope is limited to stored structural conformance. A 69-test suite was used to confirm acceptance of valid bindings and rejection of malformed, duplicate, or unsupported constructs. The release artifacts were built twice under the same commit timestamp and confirmed byte-for-byte identical, with CI passing on both main and tagged branches.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in