A BSD-licensed framework for securely updating software. Has a specification, including threat model. Implemented in Python, Ruby, Go, and Haskell.
Thread
Stories related to "The Update Framework (TUF)" across the full archive.
A BSD-licensed framework for securely updating software. Has a specification, including threat model. Implemented in Python, Ruby, Go, and Haskell.
This was [submitted](https://lobste.rs/s/3xryrx/update_framework_tuf) two years ago, but given [current events](https://lobste.rs/s/ceexg6/remote_code_execution_alpine_linux) I figured it's worth resubmitting.
Wherein we chat with Trishank Karthik Kuppusamy about The Update Framework, a security layer that lets package managers assure the veracity and integrity of their packages. We talk about how it grew out of the TOR Project, how it works, how Uptane is used for package management in cars (!), and what...
New Release: Tor 0.3.4.8 (also other stable updates: 0.2.9.17, 0.3.2.12, and 0.3.3.10)
(blog.torproject.org)