Signer.derive key() ignores key derivation setting and produces wrong signatures
Signer.derive key() ignores key derivation setting and produces wrong signatures: a task in repo2rlenv-swe-smith (Harbor dataset). As a consequence, Serializer instances configured with different key derivation methods produce identical signed output, so tokens signed under one derivation method…
The task
As a consequence, `Serializer` instances configured with different key derivation methods produce identical signed output, so tokens signed under one derivation method are accepted by a signer using a completely different method.
Part of FineEnvs/repo2rlenv-swe-smith.