diff --git a/ADOPTERS.md b/ADOPTERS.md new file mode 100644 index 0000000..f6cc599 --- /dev/null +++ b/ADOPTERS.md @@ -0,0 +1,22 @@ +# Adopters + +This page lists organizations and projects that use `fabric-chaincode-python` in production or as the basis for their work. If your organization uses this project, we would love to add you to this list. + +Adding your organization is easy: open a pull request that adds a row to the table below, including a publicly verifiable reference (a URL to a blog post, case study, documentation, or other verifiable public material). + +> A description of what constitutes an adopter and the requirements for being listed can be found in the +> [LFDT Defining Adopters](https://lf-decentralized-trust.github.io/governance/governing-documents/repository-structure/defining-adopters.html) document. + +## Adopters + +| Organization | Project / Use case | Reference | +|--------------|--------------------|-----------| +| _(Add your organization here)_ | _(Brief description of usage)_ | _(Public verifiable URL)_ | + +## How to Add Your Organization + +1. Fork the repository. +2. Add a row to the table above with your organization, a brief description of how you use the project, and a publicly verifiable reference URL. +3. Submit a pull request. + +The list is maintained by the project maintainers but can be updated by anyone — including adopters and third parties — as long as the reference is publicly verifiable. diff --git a/CHANGELOG.md b/CHANGELOG.md new file mode 100644 index 0000000..c194a04 --- /dev/null +++ b/CHANGELOG.md @@ -0,0 +1,7 @@ +# Changelog + +All notable changes to this project are documented in the +[GitHub Releases](https://github.com/hyperledger/fabric-chaincode-python/releases) +for `hyperledger/fabric-chaincode-python`. + +Each release entry lists the changes, deprecations, and breaking changes introduced. diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..2f1f0e3 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,8 @@ +Code of Conduct Guidelines +========================== + +Please review the Hyperledger [Code of +Conduct](https://wiki.hyperledger.org/community/hyperledger-project-code-of-conduct) +before participating. It is important that we keep things civil. + +Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 International License. diff --git a/NOTICE b/NOTICE new file mode 100644 index 0000000..37d66a9 --- /dev/null +++ b/NOTICE @@ -0,0 +1,18 @@ +Fabric Chaincode for Python +Copyright 2023-2026 The Hyperledger Fabric Contributors + +This product includes software developed at +Hyperledger (https://www.hyperledger.org/) and the +Linux Foundation Decentralized Trust (https://www.lfdecentralizedtrust.org/). + +This product is licensed under the Apache License, Version 2.0 (the "License"); +you may not use this product except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, WITHOUT +WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the +License for the specific language governing permissions and limitations under +the License. diff --git a/README.md b/README.md index 8f0db9b..09dcd06 100644 --- a/README.md +++ b/README.md @@ -1,36 +1,76 @@ -# fabric-chaincode-python +# Hyperledger Fabric Chaincode Python + +![GitHub License](https://img.shields.io/github/license/hyperledger/fabric-chaincode-python) +[![OpenSSF Best Practices](https://bestpractices.coreinfrastructure.org/projects/14928/badge)](https://bestpractices.coreinfrastructure.org/projects/14928) +[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/hyperledger/fabric-chaincode-python/badge)](https://scorecard.dev/viewer/?uri=github.com/hyperledger/fabric-chaincode-python) -[![Lifecycle](https://img.shields.io/badge/lifecycle-experimental- orange.svg)](https://github.com/hyperledger/fabric-chaincode-python/blob/main/lifecycle.md) [![Python Version](https://img.shields.io/pypi/pyversions/fabric-chaincode-python.svg)](https://pypi.org/project/fabric-chaincode-python/) -[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0) [![GitHub Actions](https://github.com/hyperledger/fabric-chaincode-python/workflows/CI/badge.svg)](https://github.com/hyperledger/fabric-chaincode-python/actions?query=workflow%3ACI) [![GitHub Release](https://img.shields.io/github/v/release/hyperledger/fabric-chaincode-python.svg)](https://github.com/hyperledger/fabric-chaincode-python/releases) -# Hyperledger Fabric Chaincode shim and Contract API for Python - -This repository provides the Python implementation of Hyperledger Fabric chaincode shim and contract API. Chaincodes (smart contracts) can be written in Python to run inside Hyperledger Fabric peers. +This is a Python based implementation of Hyperledger Fabric chaincode shim and contract +API, which enables development of smart contracts using the Python language. Chaincodes +(smart contracts) written in Python run inside Hyperledger Fabric peers. ## Documentation -- API documentation: https://hyperledger.github.io/fabric-chaincode-python/ -- Full Documentation on Hyperledger Fabric: https://hyperledger-fabric.readthedocs.io/ -- Samples repository: https://github.com/hyperledger/fabric-samples -- Quick-start tutorial: TUTORIAL.md +- [API documentation](https://hyperledger.github.io/fabric-chaincode-python/) +- [Full Hyperledger Fabric documentation](https://hyperledger-fabric.readthedocs.io/) +- [Samples repository](https://github.com/hyperledger/fabric-samples) + +## Project structure + +``` +src/ +├── fabric_contract_api/ Python Contract API +└── fabric_shim/ Python chaincode shim (Fabric 2.x) +``` + +- **fabric_contract_api** - Contains the Python contract API used to write smart contracts with the high-level contract programming model. +- **fabric_shim** - Contains the Python classes that implement the chaincode shim API and the way to communicate with Fabric peers. -## Compatibility +## Building and testing -For details on what Python versions and Hyperledger Fabric versions can be used, see the [COMPATIBILITY.md](COMPATIBILITY.md). +Make sure you have the following prereqs installed: -## npm Shrinkwrap +- [Python](https://www.python.org/) 3.11 or later +- [pip](https://pip.pypa.io/en/stable/) -Strongly recommended to create a `requirements.txt` file after testing and before putting your contract into production. +Create a virtual environment and install the development dependencies: + +``` +python3 -m venv .venv +source .venv/bin/activate +pip install -e . -r requirements-dev.txt +``` + +Run the unit tests: + +``` +pytest tests/ +``` ## Contributing -If you are interested in contributing updates to this project, please start with the [contributing guide](CONTRIBUTING.md). +We welcome contributions to the Hyperledger Fabric project in many forms. If you are +interested in contributing updates to this project, please start with the +[contributing guide](CONTRIBUTING.md). + +There is also a [release guide](RELEASING.md) describing the process for publishing new +versions. + +## Community -There is also a [release guide](RELEASING.md) describing the process for publishing new versions. +- [Hyperledger Community](https://www.hyperledger.org/community) +- [Hyperledger mailing lists and archives](http://lists.hyperledger.org/) +- [Hyperledger Chat](http://chat.hyperledger.org/channel/fabric) +- [Hyperledger Fabric Wiki](https://wiki.hyperledger.org/display/Fabric) +- [Hyperledger Code of Conduct](CODE_OF_CONDUCT.md) -## Build Status +## License -CI runs with Python 3.11 on `main` and `release-*` branches, and on pull requests. \ No newline at end of file +Hyperledger Project source code files are made available under the Apache License, +Version 2.0 (Apache-2.0), located in the [LICENSE](LICENSE) file. Hyperledger Project +documentation files are made available under the Creative Commons Attribution 4.0 +International License (CC-BY-4.0), available at +http://creativecommons.org/licenses/by/4.0/. diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..11ea40d --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,38 @@ +# Security Policy + +We take the security of `fabric-chaincode-python` seriously. This document describes how to report a vulnerability and how we handle it. + +## Reporting a Vulnerability + +Please **do not** open a public issue for security vulnerabilities. Instead, report them privately so they can be addressed before disclosure. + +To report a vulnerability, contact the project maintainers directly. See [MAINTAINERS.md](MAINTAINERS.md) for contact information. + +Vulnerabilities in the broader Hyperledger Fabric ecosystem should be reported in accordance with the +[Hyperledger Fabric security policy](https://github.com/hyperledger/fabric/blob/main/SECURITY.md). + +## Responsible Disclosure + +We follow a coordinated disclosure process: + +1. You report the vulnerability privately to the maintainers. +2. The maintainers acknowledge receipt and begin an assessment. +3. A fix is prepared, tested, and released. +4. The vulnerability is disclosed publicly only after the fix is available. + +We ask that you keep the details confidential until a fix has been released. + +## Scope + +- The Python chaincode shim and contract API implemented in this repository (`src/`). +- Supporting build and test tooling under `scripts/` and `tests/`. + +Third-party dependencies are outside this repository's direct control; please report issues with them to their respective projects. + +## Supported Versions + +Security fixes are provided for the latest stable release and, where feasible, recent releases still under active maintenance. See [RELEASING.md](RELEASING.md) for the release and support policy. + +## Thanks + +We appreciate responsible security researchers who help us improve the security of this project. diff --git a/src/fabric_shim/__init__.py b/src/fabric_shim/__init__.py index bbaec90..2829617 100644 --- a/src/fabric_shim/__init__.py +++ b/src/fabric_shim/__init__.py @@ -1 +1,2 @@ +# SPDX-License-Identifier: Apache-2.0 __all__ = ["chaincode", "handler", "interfaces", "iterators", "server", "stub"] diff --git a/src/fabric_shim/handler.py b/src/fabric_shim/handler.py index 97e0f63..3e2db56 100644 --- a/src/fabric_shim/handler.py +++ b/src/fabric_shim/handler.py @@ -1,3 +1,4 @@ +# SPDX-License-Identifier: Apache-2.0 import datetime from typing import AsyncIterable import asyncio diff --git a/src/fabric_shim/interfaces.py b/src/fabric_shim/interfaces.py index b523b27..05c90f4 100644 --- a/src/fabric_shim/interfaces.py +++ b/src/fabric_shim/interfaces.py @@ -1,3 +1,4 @@ +# SPDX-License-Identifier: Apache-2.0 from abc import ABC, abstractmethod from fabric_protos.peer import proposal_response_pb2 as pb diff --git a/src/fabric_shim/logger.py b/src/fabric_shim/logger.py index e69de29..9881313 100644 --- a/src/fabric_shim/logger.py +++ b/src/fabric_shim/logger.py @@ -0,0 +1 @@ +# SPDX-License-Identifier: Apache-2.0 diff --git a/src/fabric_shim/logging.py b/src/fabric_shim/logging.py index 496ad98..bdcd690 100644 --- a/src/fabric_shim/logging.py +++ b/src/fabric_shim/logging.py @@ -1,3 +1,4 @@ +# SPDX-License-Identifier: Apache-2.0 import asyncio import logging import logging.handlers diff --git a/src/fabric_shim/msg_queue_handler.py b/src/fabric_shim/msg_queue_handler.py index 5f011f6..64b1c09 100644 --- a/src/fabric_shim/msg_queue_handler.py +++ b/src/fabric_shim/msg_queue_handler.py @@ -1,3 +1,4 @@ +# SPDX-License-Identifier: Apache-2.0 import asyncio from src.fabric_shim.logging import LOGGER diff --git a/src/fabric_shim/response.py b/src/fabric_shim/response.py index 3b9d55c..80fb900 100644 --- a/src/fabric_shim/response.py +++ b/src/fabric_shim/response.py @@ -1,3 +1,4 @@ +# SPDX-License-Identifier: Apache-2.0 from fabric_protos.peer import chaincode_shim_pb2 as ccshim_pb2 from fabric_protos.peer import proposal_response_pb2 as pb diff --git a/src/fabric_shim/server.py b/src/fabric_shim/server.py index 53fa4cf..12086eb 100644 --- a/src/fabric_shim/server.py +++ b/src/fabric_shim/server.py @@ -1,3 +1,4 @@ +# SPDX-License-Identifier: Apache-2.0 import asyncio import logging import os diff --git a/src/fabric_shim/stub.py b/src/fabric_shim/stub.py index beab609..c7446c3 100644 --- a/src/fabric_shim/stub.py +++ b/src/fabric_shim/stub.py @@ -1,3 +1,4 @@ +# SPDX-License-Identifier: Apache-2.0 from src.fabric_shim.interfaces import ChaincodeStubInterface from src.fabric_shim.utils import ( COMPOSITEKEY_NS, diff --git a/src/fabric_shim/utils.py b/src/fabric_shim/utils.py index 808de96..b33749d 100644 --- a/src/fabric_shim/utils.py +++ b/src/fabric_shim/utils.py @@ -1,3 +1,4 @@ +# SPDX-License-Identifier: Apache-2.0 # Auxiliary tools