From 2fa11b31cc421dac606aed2b7a4e96ceec3ba781 Mon Sep 17 00:00:00 2001 From: marinamoore Date: Fri, 4 Oct 2019 11:29:00 -0400 Subject: [PATCH] clarified that filenames can be relative or absolute --- pep-0458.txt | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pep-0458.txt b/pep-0458.txt index a5067b51a52..63c6511885f 100644 --- a/pep-0458.txt +++ b/pep-0458.txt @@ -305,7 +305,9 @@ latest *snapshot* and can signify when a new snapshot of the repository is available. The *snapshot* role indicates the latest version of all the TUF metadata files (other than *timestamp*). The *targets* role lists the available target files (in our case, it will be all files on PyPI under the -/simple and /packages directories). Each top-level role will serve its +/simple and /packages directories). These target files do not need to be +URIs or relative files on the same repository as long as they can be accessed +by anyone performing an update. Each top-level role will serve its responsibilities without exception. Figure 1 provides a table of the roles used in TUF.