-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathapis.yml
More file actions
236 lines (236 loc) · 8.31 KB
/
Copy pathapis.yml
File metadata and controls
236 lines (236 loc) · 8.31 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
aid: tuf
name: The Update Framework (TUF)
description: >-
TUF (The Update Framework) is a CNCF graduated framework for securing
software update systems. It provides a specification for how software
repositories should be structured and how clients should verify updates
to protect against key compromise, rollback attacks, and mix-and-match
attacks. TUF is used by many package managers and update systems including
PyPI, Sigstore, and various Linux distributions. The framework defines
a four-role metadata structure (root, targets, snapshot, timestamp) with
threshold signing and delegation capabilities for scalable trust management.
url: https://theupdateframework.io
deliveryModel:
model: unknown
license_evidence:
not_product:
- theupdateframework/go-tuf
- theupdateframework/python-tuf
- theupdateframework/rust-tuf
- theupdateframework/specification
- theupdateframework/tuf-conformance
open_source: unknown
commercial: false
callable_host: false
label: Delivery model not determined — needs a product licence on record
confidence: low
source:
- repository-not-product
generated: '2026-09-25'
method: derived
accessModel:
pricing: freemium
onboarding: unknown
trial: false
try_now: false
public: false
label: Freemium
confidence: medium
source:
- plans
generated: '2026-07-22'
method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/tuf.png
tags:
- CNCF
- Cloud-Native
- Graduated
- Security
- Software Supply Chain
- Software Updates
- Verification
tags_raw:
- CNCF
- Cloud Native
- Graduated
- Security
- Software Supply Chain
- Software Updates
- Verification
created: '2026-03-16'
modified: '2026-05-03'
specificationVersion: '0.23'
type: Index
apis:
- aid: tuf:tuf-spec
name: TUF Repository Specification
description: >-
The TUF specification defines the structure of update repositories
including the root, targets, snapshot, and timestamp metadata files.
Each metadata file has a defined schema with signatures, expiration
dates, and delegation rules. Clients follow a defined verification
workflow to securely resolve and download updates while protecting
against various attack vectors including key compromise, rollback attacks,
freeze attacks, and mix-and-match attacks. The specification is version 1.0.31.
humanURL: https://theupdateframework.github.io/specification/latest/
properties:
- type: Documentation
url: https://theupdateframework.github.io/specification/latest/
- type: GitHubRepository
url: https://github.com/theupdateframework/specification
- type: JSONSchema
url: json-schema/tuf-root-metadata-schema.json
- type: JSONSchema
url: json-schema/tuf-targets-metadata-schema.json
- type: JSONSchema
url: json-schema/tuf-snapshot-metadata-schema.json
- type: JSONSchema
url: json-schema/tuf-timestamp-metadata-schema.json
tags:
- Metadata
- Repository Metadata
- Specification
- Verification
- aid: tuf:python-tuf
name: TUF Python Reference Implementation
description: >-
The official Python reference implementation of The Update Framework (TUF)
specification. Provides a metadata API for reading and writing TUF metadata
files, an ngclient API implementing the TUF client update workflow, and a
repository library for building TUF-compliant software repositories.
Available on PyPI as the 'tuf' package.
humanURL: https://theupdateframework.readthedocs.io/en/stable/
properties:
- type: Documentation
url: https://theupdateframework.readthedocs.io/en/stable/
- type: GitHubRepository
url: https://github.com/theupdateframework/python-tuf
- type: PackageRegistry
url: https://pypi.org/project/tuf/
tags:
- Client Library
- Python
- Security
- Software Updates
- Supply Chain
- aid: tuf:go-tuf
name: TUF Go Implementation
description: >-
A Go implementation of The Update Framework (TUF), heavily influenced by
python-tuf's design. Provides metadata, TrustedMetadata, and Updater
packages implementing the TUF client workflow and specification-compliant
metadata handling, as well as multi-repository support via TAP 4.
humanURL: https://github.com/theupdateframework/go-tuf
properties:
- type: Documentation
url: https://github.com/theupdateframework/go-tuf
- type: GitHubRepository
url: https://github.com/theupdateframework/go-tuf
tags:
- Client Library
- Go
- Security
- Software Updates
- Supply Chain
- aid: tuf:rust-tuf
name: TUF Rust Implementation
description: >-
A Rust implementation of The Update Framework (TUF) specification providing
a strongly-typed API for working with TUF metadata, verifying signatures,
and implementing the TUF client update workflow.
humanURL: https://github.com/theupdateframework/rust-tuf
properties:
- type: GitHubRepository
url: https://github.com/theupdateframework/rust-tuf
tags:
- Client Library
- Rust
- Security
- Software Updates
- aid: tuf:tuf-js
name: TUF JavaScript Implementation
description: >-
A JavaScript/TypeScript implementation of The Update Framework (TUF) for
use in Node.js environments and browser-based update systems. Enables
TUF-compliant software update verification in the JavaScript ecosystem.
humanURL: https://github.com/theupdateframework/tuf-js
properties:
- type: GitHubRepository
url: https://github.com/theupdateframework/tuf-js
tags:
- Client Library
- JavaScript
- Security
- Software Updates
- TypeScript
- aid: tuf:tuf-on-ci
name: TUF on CI
description: >-
A TUF repository management and signing tool designed for use in CI/CD
pipelines. Enables teams to maintain a TUF repository using GitHub Actions
and other CI systems for automated, policy-driven key management and metadata
signing workflows.
humanURL: https://github.com/theupdateframework/tuf-on-ci
properties:
- type: GitHubRepository
url: https://github.com/theupdateframework/tuf-on-ci
tags:
- CI/CD
- Key Management
- Repository Management
- Security
- aid: tuf:tuf-conformance
name: TUF Conformance Test Suite
description: >-
The official TUF client conformance test suite for verifying that TUF client
implementations correctly implement the TUF specification, including proper
handling of all attack vectors and edge cases.
humanURL: https://github.com/theupdateframework/tuf-conformance
properties:
- type: GitHubRepository
url: https://github.com/theupdateframework/tuf-conformance
tags:
- Compliance
- Conformance Testing
- Security
- Testing
common:
- type: IssueTracker
url: https://github.com/theupdateframework/specification/issues
- type: Releases
url: https://github.com/theupdateframework/specification/releases
- type: DomainSecurity
url: security/tuf-domain-security.yml
- type: Website
url: https://theupdateframework.io/
- type: Documentation
url: https://theupdateframework.io/docs/
- type: GettingStarted
url: https://theupdateframework.io/docs/getting-started/
- type: GitHubOrganization
url: https://github.com/theupdateframework
- type: GitHubRepository
url: https://github.com/theupdateframework/python-tuf
- type: Specification
url: https://theupdateframework.github.io/specification/latest/
- type: Blog
url: https://theupdateframework.io/resources/news/
- type: CNCF
url: https://www.cncf.io/projects/the-update-framework-tuf/
- type: Community
url: https://github.com/theupdateframework/community
- type: JSONLD
url: json-ld/tuf-context.jsonld
- type: JSONSchema
url: json-schema/tuf-root-metadata-schema.json
- type: JSONSchema
url: json-schema/tuf-targets-metadata-schema.json
- type: JSONSchema
url: json-schema/tuf-snapshot-metadata-schema.json
- type: JSONSchema
url: json-schema/tuf-timestamp-metadata-schema.json
- type: Vocabulary
url: vocabulary/tuf-vocabulary.yml
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com