#1100406 ITP: golang-github-cyberphone-json-canonicalization -- JSON Canonicalization Scheme (JCS)

#1100406#5
Date:
2025-03-13 13:23:33 UTC
From:
To:
* Package name    : golang-github-cyberphone-json-canonicalization
  Version         : 6testfile-1
  Upstream Author : Anders Rundgren
* URL             : https://github.com/cyberphone/json-canonicalization
* License         : Apache-2.0 and BSD-3-Clause
  Programming Lang: Go
  Description     : JSON Canonicalization Scheme (JCS)

 JSON Canonicalization
 .
 Cryptographic operations like hashing and signing depend on that the
 target data does not change during serialization, transport, or parsing.
 By applying the rules defined by JCS (JSON Canonicalization Scheme),
 data provided in the JSON [RFC8259
 (https://tools.ietf.org/html/rfc8259)] format can be exchanged "as is",
 while still being subject to secure cryptographic operations. JCS
 achieves this by building on the serialization formats for JSON
 primitives as defined by ECMAScript [ES (https://ecma-
 international.org/ecma-262/)], constraining JSON data to the I-JSON
 [RFC7493 (https://tools.ietf.org/html//rfc7493)] subset, and through a
 platform independent property sorting scheme.
 .
 Public RFC: https://tools.ietf.org/html/rfc8785
 (https://tools.ietf.org/html/rfc8785)
 .
 The JSON Canonicalization Scheme concept in a nutshell:
 .
  * Serialization of primitive JSON data types using methods compatible
    with ECMAScript's JSON.stringify()
  * Lexicographic sorting of JSON Object properties in a *recursive*
    process
  * JSON Array data is also subject to canonicalization, *but element
    order remains untouched*

#1100406#10
Date:
2025-03-13 14:22:57 UTC
From:
To:
#1100406#15
Date:
2025-03-13 14:44:56 UTC
From:
To:
Le 13/03/2025 à 15:22, Simon Josefsson a écrit :
Different one, or am I mistaken? I think apptainer depends on
golang-github-cyberphone-json-canonicalization (at least, it's mentioned
in the go.mod file).

I also noticed your inital packaging work before I spent too much time
on mine, so I ditched mine and switched to yours. Updated and uploaded
now. Thanks :-)

Roland.

#1100406#20
Date:
2025-03-13 14:51:33 UTC
From:
To:
I believe the code is the same, it has a symlink to provide the weird old namespace:

https://salsa.debian.org/go-team/packages/golang-webpki-org-jsoncanonicalizer/-/blob/debian/latest/debian/golang-webpki-org-jsoncanonicalizer-dev.links?ref_type=heads

There may better ways to do this, patches welcome :), but it works for several packages using this.

I don’t think we should have two packages with the same code.

/Simon

#1100406#25
Date:
2025-03-13 14:59:33 UTC
From:
To:
Le 13/03/2025 à 15:51, Simon Josefsson a écrit :
Maybe a Provides: would be useful then?

Agreed. I'll recall my upload.

Roland.