python-tuf
The Python reference implementation of The Update Framework — secures software update systems against key compromise, rollback and freeze attacks.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| The Update Framework | verifies |
The reference implementation. |
- Interfaces
librarycli- Install
-
pypi
tuf - Consumes
- tuf-metadata
- Runtime
- Needs network Deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
TUF's premise is that keys WILL be compromised, and the system should survive it. That is a different design goal from ordinary code signing.
- Website
- https://theupdateframework.com/
- Repository
- https://github.com/theupdateframework/python-tuf
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-09-17
- Stars
- 1727 · last commit 2026-09-15
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.