tuf
A secure updater framework for Python
Decision gist · record as of 2026-08-14
Yes. TUF is a mature, actively maintained reference implementation of a CNCF-backed security standard used in production by major organizations. It has low install friction, no known vulnerabilities, permissive licensing, and supports current Python versions. Install it if you need to secure software updates or validate update metadata according to the TUF specification.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later; you must have securesystemslib and urllib3 installed as runtime dependencies.
- Low install friction with only two runtime dependencies (securesystemslib and urllib3).
- Active maintenance with a recent release 88 days ago and continuous commits; supports current Python versions (3.10 through 3.14).
License · maintenance · safety
Apache-2.0 OR MIT (permissive) — Dual-licensed under Apache-2.0 OR MIT (permissive), so you may choose either license when using or redistributing the package.
last release 2026-05-18 (88 days) · last repo commit 2026-08-12 · 1,720 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 961,921 downloads/mo, #4,631 on PyPI
Alternatives
Verify before relying
pip install tuf
from tuf.ngclient import Updater
from tuf.api.metadata import Root
# Initialize updater with metadata and targets directories
updater = Updater(
metadata_dir='./metadata',
targets_dir='./targets',
target_base_url='https://example.com/targets',
metadata_base_url='https://example.com/metadata'
)- Whether the ngclient API is suitable for production use or still considered experimental
- Performance characteristics when validating large metadata hierarchies or many targets
- Whether the repository module is stable enough for production adoption
What it is and what it does
TUF is a reference implementation of The Update Framework specification, a security framework designed to protect software update systems from supply chain attacks, key compromise, and repository tampering. It provides two main APIs: a low-level metadata API for safe access to TUF metadata and serialization, and an ngclient implementation for fetching and validating updates. The package handles the cryptographic validation of update metadata according to the TUF specification, ensuring that even if a repository is compromised or signing keys are stolen, attackers cannot silently distribute malicious updates.
The framework is production-ready and used by major organizations and open-source projects (including Uptane for automotive over-the-air updates). It's hosted by the Linux Foundation as part of the Cloud Native Computing Foundation. The reference implementation is intended as both a working tool and a readable guide for those implementing TUF in other languages or environments.
Use it for
- Implement secure update delivery for Python applications or services that need protection against repository compromise
- Validate software update metadata according to TUF specification in a supply chain security pipeline
- Build a custom update system that delegates trust to multiple signing keys with threshold signatures
- Integrate TUF metadata validation into a package manager or software distribution system
- Audit and verify the integrity of update metadata in an existing update infrastructure
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
TUF is a mature, actively maintained reference implementation of a CNCF-backed security standard used in production by major organizations. It has low install friction, no known vulnerabilities, permissive licensing, and supports current Python versions. Install it if you need to secure software updates or validate update metadata according to the TUF specification.
Install
tuf on PyPI
Before you install
Low install friction with only two runtime dependencies (securesystemslib and urllib3). Active maintenance with a recent release 88 days ago and continuous commits; supports current Python versions (3.10 through 3.14).
Requires Python 3.10 or later; you must have securesystemslib and urllib3 installed as runtime dependencies.
License in practice
Dual-licensed under Apache-2.0 OR MIT (permissive), so you may choose either license when using or redistributing the package.
Quickstart
pip install tuf
from tuf.ngclient import Updater
from tuf.api.metadata import Root
# Initialize updater with metadata and targets directories
updater = Updater(
metadata_dir='./metadata',
targets_dir='./targets',
target_base_url='https://example.com/targets',
metadata_base_url='https://example.com/metadata'
)
Verify before relying
- Whether the ngclient API is suitable for production use or still considered experimental
- Performance characteristics when validating large metadata hierarchies or many targets
- Whether the repository module is stable enough for production adoption
Package facts
| License | Apache-2.0 OR MIT permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagessecuresystemsliburllib3 |
| Maintenance | Actively maintained 88 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 961,921 / month, #4,631 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersNatural Language :: EnglishOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: POSIXOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonTopic :: SecurityTopic :: Software Development |
Evidence: tuf-7.0.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “secure software updates”
- tufTUF is a Python reference implementation of The Update Framework…
- borgbackupBorgBackup is a command-line deduplicating backup tool that stores…
- dnspythondnspython is a DNS toolkit that handles queries, zone transfers,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also securesystemslib · asgi-csrf · sendsafely · PyOTP · itsdangerous · pipfile · tf-keras · srp · std-uritemplate · secure-smtplib