5.9 Document Conventions

Every artifact this chapter defines — the manifest, the files manifest, the signature envelope, the repository descriptor, and both indexes — is a JSON document. The rules below apply to all of them.

5.9.1 JSON #

Documents conform to RFC 8259 and are UTF-8 encoded (RFC 3629). Field names are lowercase with underscores between words: schema_version, never schemaVersion. Field order is not significant.

Unknown fields MUST be ignored on parse, so that the format can be extended compatibly (§5.38). The signature envelope (§5.28) is the one exception, and mandates strict parsing.

5.9.2 Parser hardening #

A consumer's JSON parser processes attacker-supplied input. It MUST therefore enforce the following, on every document defined in this chapter:

  • Duplicate keys in any object MUST cause the document to be rejected. A parser that silently takes first-wins or last-wins is not conformant.
  • Integer fields MUST fit in the unsigned 64-bit range and MUST NOT use exponent notation.
  • Nesting depth MUST be capped at 64; a document exceeding that depth MUST be rejected.
  • A string value MUST NOT exceed the document size limit applicable to its containing artifact (§5.A).
  • A Unicode escape within a string MUST resolve to a valid code point per RFC 8259 §7.

5.9.3 Hashes #

Hash values are encoded in lowercase hexadecimal unless stated otherwise. Hash algorithms are identified by their IANA-registered names (sha256, blake3).

5.9.4 Signatures #

Signatures use Ed25519 as defined in RFC 8032 unless stated otherwise. Signature values are encoded in base64 (RFC 4648 §4) without padding. A base64 value carrying padding MUST be rejected.

5.9.5 Strings #

String comparison uses byte-for-byte equality unless stated otherwise.

5.9.6 URLs #

URLs follow RFC 3986. Relative URLs in a repository index are resolved against the repository descriptor's URL (§5.36).

5.9.7 Compression #

Compression uses the Zstandard format (RFC 8478). This specification does not constrain the compression level.

Edit this page