The Update Framework (TUF)
TUF (The Update Framework) is a CNCF graduated framework for securing software update systems. It provides a specification for how software repositories should be structured and how clients should verify updates to protect against key compromise, rollback attacks, and mix-and-match attacks. TUF is used by many package managers and update systems including PyPI, Sigstore, and various Linux distributions. The framework defines a four-role metadata structure (root, targets, snapshot, timestamp) with threshold signing and delegation capabilities for scalable trust management.
The Update Framework (TUF) publishes 7 APIs on the APIs.io network. Tagged areas include CNCF, Cloud Native, Graduated, Security, and Software Supply Chain.
The The Update Framework (TUF) catalog on APIs.io includes 1 JSON-LD context and 1 Spectral governance ruleset.
The Update Framework (TUF)’s developer surface includes documentation, getting-started guide, engineering blog, and 13 more developer resources.
Kin Score
APIs 7
Individual APIs this provider publishes, each with its own machine-readable definition.
TUF Repository Specification
The TUF specification defines the structure of update repositories including the root, targets, snapshot, and timestamp metadata files. Each metadata file has a defined schema w...
TUF Python Reference Implementation
The official Python reference implementation of The Update Framework (TUF) specification. Provides a metadata API for reading and writing TUF metadata files, an ngclient API imp...
TUF Go Implementation
A Go implementation of The Update Framework (TUF), heavily influenced by python-tuf's design. Provides metadata, TrustedMetadata, and Updater packages implementing the TUF clien...
TUF Rust Implementation
A Rust implementation of The Update Framework (TUF) specification providing a strongly-typed API for working with TUF metadata, verifying signatures, and implementing the TUF cl...
TUF JavaScript Implementation
A JavaScript/TypeScript implementation of The Update Framework (TUF) for use in Node.js environments and browser-based update systems. Enables TUF-compliant software update veri...
TUF on CI
A TUF repository management and signing tool designed for use in CI/CD pipelines. Enables teams to maintain a TUF repository using GitHub Actions and other CI systems for automa...
TUF Conformance Test Suite
The official TUF client conformance test suite for verifying that TUF client implementations correctly implement the TUF specification, including proper handling of all attack v...
Scroll for all 7
Pricing Plans 1
Published pricing tiers and plan structures.
Tuf Plans Pricing
PLANSRate Limits 1
Documented rate limits and quota policies.
Tuf Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Tuf Finops
FINOPSSemantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Tuf Context
JSON-LDSpectral Rules 1
Spectral governance rulesets for linting and validating these APIs.
The Update Framework (TUF) API Rules
SPECTRALJSON Schema 4
Standalone JSON Schema definitions for this provider's data models.
TUF Root Metadata
JSON SCHEMATUF Snapshot Metadata
JSON SCHEMATUF Targets Metadata
JSON SCHEMATUF Timestamp Metadata
JSON SCHEMAJSON Structure 2
JSON Structure definitions describing this provider's data shapes.
Tuf Root Metadata Structure
JSON STRUCTURETuf Targets Metadata Structure
JSON STRUCTUREExamples 3
Example request and response payloads for these APIs.
Tuf Root Metadata Example
EXAMPLETuf Targets Metadata Example
EXAMPLESecurity Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 6
Reference material describing how the API behaves
Design & Contract 2
Pagination, idempotency, versioning, errors, and events
Build 2
SDKs, sample code, and the tooling you integrate with
Access & Security 1
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Company 2
The organization behind the API
Other 1
Properties that don't map to a standard resource type