Skip to content

Replace signatory dependency with signature to remove der - #57

Open
relistan wants to merge 1 commit into
wasmCloud:mainfrom
relistan:fix/remove-unused-signatory
Open

relistan wants to merge 1 commit into
wasmCloud:mainfrom
relistan:fix/remove-unused-signatory

Conversation

@relistan

Copy link
Copy Markdown

Feature or Problem

Currently, nkeys imports the signatory crate just to use signature::Error. This unnecessarily drags in pkcs8 and der as dependencies. Security scanners often flag der 0.7.10 because of a quadratic decoding issue, and we can't easily upgrade it because of the signatory dependency chain.

This PR fixes the issue by replacing signatory with a direct dependency on signature 2.x (with the std feature enabled). We still get the exact same signature::Error type, so the public API, key parsing, and signing behavior remain exactly the same.

Related Issues

Related to #56. This PR is specifically focused on dropping the unused signatory dependency.

Release Information

Next patch release.

Consumer Impact

Projects using this crate will no longer pull in signatory, pkcs8, or der. No code changes are required for users. Downstream projects carrying a vendored patch for the der issue can drop it once this is released.

Testing

Unit Test(s)

All existing unit tests pass, including those for signing, key encoding, and invalid signatures. No tests needed to be changed.

Acceptance or Integration

The CLI target builds successfully and documentation examples pass.

Manual Verification

  • cargo test --all-features: 32 unit tests and 1 doctest passed.
  • cargo fmt --all -- --check: passed.
  • cargo clippy --all-features --tests -- -D warnings: passed.
  • cargo tree --all-features --locked: confirmed that signatory, pkcs8, and der are no longer in the dependency tree.

Signed-off-by: Karl Matthias <karl.matthias@mechanical-orchard.com>
@relistan
relistan marked this pull request as ready for review September 16, 2026 16:47
@relistan
relistan requested a review from a team as a code owner September 16, 2026 16:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants