NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3565 most downloaded on PyPI
A secure updater framework for Python
Last release 1 months ago
02 Sep 2026
Ships fairly regularly
a new release about every 4 months
Nearly every release is documented
notes for 33 of 33 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
40 releases · first in 2013
Fix hash method on Role and DelegatedRole
This is a major release only because of a minor ngclient API tweak: there are no large functional changes.
One column per quarter.
This is a major release only because of a minor ngclient API tweak: there
are no large functional changes.
The deprecated RequestsFetcher implementation is available but requires selecting the fetcher at Updater initialization and explicitly depending on re…
This release is not strictly speaking an API break from 5.1 but it does contain some
major internal changes that users should be aware of when upgrading.
requests, idna, charset-normalizer and certificertifi (#2762)bootstrap argument to Updater (#2767)ngclient: default user-agent was updated from "tuf/x.y.z" to "python-tuf/x.y.z"
This release, most notably, marks stable securesystemslib v1.0.0 as minimum requirement. The update causes a minor break in the new DSSE API (see belo
This release, most notably, marks stable securesystemslib v1.0.0 as minimum
requirement. The update causes a minor break in the new DSSE API (see below)
and affects users who also directly depend on securesystemslib. See the securesystemslib release
notes
and the updated python-tuf examples (#2617) for details. ngclient API remains
backwards-compatible.
This release is a small API change for Metadata API users (see below). ngclient API is compatible but optional DSSE support has been added.
This release is a small API change for Metadata API users (see below).
ngclient API is compatible but optional DSSE support has been added.
Root.get_verification_result() and Targets.get_verification_result()Root.get_root_verification_result() has been added to handle the specialThis is a security fix release to address advisory GHSA-77hh-43cm-v8j6 . The issue does not affect tuf.ngclient users, but could affect tuf.api.metada…
This is a security fix release to address advisory GHSA-77hh-43cm-v8j6. The issue does not affect tuf.ngclient users, but could affect tuf.api.metadata users.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
The notable change in this release is #2165: The tuf.api.metadata.Key class implementation was moved to Securesystemslib with minor API changes. These changes require no action in tuf.ngclient users but may require small changes in tuf.api.metadata using repository implementations that create keys.
As a result of these changes, both signing and verification are now fully extensible, see Securesystemslib signer API for details.
tuf.repository remains an unstable module in 3.0.0.
Key.verify_signature() method signature has changedKey.from_securesystemslib_key() was removed: Use
Securesystemslibs SSlibKey.from_securesystemslib_key() insteadSee CHANGELOG.md for details.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
This release, most notably, adds support for TAP 15 - succinct hash bin delegation, which results in a few backwards-incompatible changes in the Metadata API.
NOTE: While TAP 15 has been accepted it is not yet part of the TUF specification. Therefore, adopters should be prepared for potential changes to the implementation in future and for a lack of support for TAP 15 in other TUF implementations.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
This release contains major build improvements as well as fixes and backwards-compatible API improvements.
docs: Remove deprecated documentation (#1768, #1769, #1773, #1848)
This release makes ngclient and the Metadata API the supported python-tuf APIs.
It also removes the legacy implementation as documented in the 1.0.0 announcement:
all library code is now contained in tuf.api or tuf.ngclient.
See Python-TUF reaches version 1.0.0 for a blog post about this release.
Please see the *1.0.0 announcement* page for more details about the next release and the deprecation of the legacy implementation, including migration…
NOTE: This will be the final release of python-tuf that includes the legacy implementation code. Please see the 1.0.0 announcement page for more details about the next release and the deprecation of the legacy implementation, including migration instructions.
For users of legacy client (tuf.client module) this is purely a security fix release with no API or functionality changes. For ngclient (tuf.ngclient)…
For users of legacy client (tuf.client module) this is purely a security fix release with no API or functionality changes. For ngclient (tuf.ngclient) and Metadata API (tuf.api.metadata), some API changes are included.
All users are advised to upgrade.
Note that python-tuf has required python>=3.5 since release 0.18.0.
Note: The v0.18.0 release was made with the changes from #1566, resulting in a release with sources which don't match the git tag. We are rectifying t
Note: The v0.18.0 release was made with the changes from #1566, resulting in a release with sources which don't match the git tag. We are rectifying this with this v0.18.1 release.
0.18 is a big release with 3 main themes:
Additionally the Github project name changed: project is now "python-tuf" instead of "tuf". Redirects are in place for the old name but updating links is advised.
Please see https://github.com/theupdateframework/python-tuf/releases/tag/v0.18.0
0.18 is a big release with 3 main themes:
0.18 is a big release with 3 main themes:
Additionally the Github project name changed: project is now "python-tuf" instead of "tuf". Redirects are in place for the old name but updating links is advised.
NOTE: this will be the final release of tuf that supports Python 2.7. This is because Python 2.7 was marked end-of-life in January of 2020, and since
NOTE: this will be the final release of tuf that supports Python 2.7. This is because Python 2.7 was marked end-of-life in January of 2020, and since then several of tuf's direct and transient dependencies have stopped supporting Python 2.7.
Begin to document architectural and project-wide decisions as Architectural Decision Records (ADRs) in docs/adr (#1182, #1203)
tuf.api (#1193)aggregate_tests) and stop executing unit test
modules in a random order (#1187)sleep() calls (#1194)Queues, rather than files,
for process communication (#1198)tuf.client.updater (#1219)[]) as the default argument in a test
function (#1216)_verify_root_self_signed() such that
signatures by the same root key count only once towards the threshold (#1218)Simple TUF role metadata model in the tuf.api package for interacting with metadata files directly, per-file without the overheads of reading and writ
tuf.api package for interacting with
metadata files directly, per-file without the overheads of reading and
writing the entire repository at once (#1112, #1177, #1183)MissingLocalRepositoryError in updater when local repository can not
be found (#1173)fileinfo (#1078)tuf.client.updater when metadata is loaded without a
signature (#1100)tuf.repository_tool when metadata is written without a
signature (#1100)targets_path, metadata_path and confined_target_dirs fields in
tuf.client.updaters mirror configuration optional (#1153, #1166)colorama and dependency (#1180)requests.Responses are closed during tests (#1147)securesystemslib head of development (#1185)tuf.repository_lib error message (#1078)Added a mechanism to the Updater to disable the hash prefix for target files even when consistent_snapshot is enabled for a repository
consistent_snapshot is enabled for a repository (#1102)keyid_hash_algorithms (#1014, #1121)keyid_hash_algorithms (#1014, #1121)securesystemslib.settings.HASH_ALGORITHMS, instead pass
desired algorithms explicitly to securesystemslib's
keys.format_metadata_to_key (#1016)Add support for BLAKE hash functions
Fix incorrect threshold signature computation
Relax spec version format check for backwards compatibility
Add backwards incompatible TUF spec version checks (#842, #844, #854, #914)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Highlight deprecations of Updater.targets_of_role() and Updater.all_targets().
Upgrade dependencies to latest versions.
Allow TUF to work through proxies (HTTP, HTTPS, and TCP (HTTP CONNECT))
For now, this development release does not include a full changelog entry. To see the full list of changes, see this commit list.
Issue deprecation warning for all_targets() and targets_of_role().
Prevent persistent freeze attack (pr #737).
Add --no-release option to CLI.
Issue deprecation warning for all_targets() and targets_of_role().
Disable file logging, by default.
Tweak network settings (in settings.py) for production environments.
Add tuf.log.enable_file_logging() and tuf.log.disable_file_logging().
Replace %xx escapes in URLs.
Support Appveyor (for Windows) with Continuous Integration.
Run unit tests in Python 3.4 & 3.5 under Appveyor.
Edit contact text to encourage users to report issues with specification.
Generate (w/ CLI) Ed25519 keys, by default.
Upgrade dependencies to latest versions.
Add requirements.in, which is used to generate the other requirement files.
Update list of adopters.
Convert README to Markdown.
Update installation instructions to note SSLib's optional dependencies that should be installed to support RSA, ECDSA, etc. keys.
Add unit test for persistent freeze attack.
Update list of tasks in ROADMAP.md.
Replace deprecated 'cryptography' functions.
Note: This is a backwards-incompatible pre-release.
Make significant improvements to execution speed of updater.
Resolve all of the unit test failures in Windows.
Add or revise many CLI options.
Revise CLI documentation, such as QUICKSTART.md.
Ensure consistent behavior between add_targets and add_target().
Add a CLI doc that demonstrates more complex examples.
Move LICENSE files to the root directory.
Update dependencies.
Update TUTORIAL.md to fix links.
Fix bug where the latest consistent metadata is not loaded.
Modify the pyup update schedule from daily to weekly.
Add hashes to requirements.txt.
Update AUTHORS.txt and add organizations.
Replace deprecated 'cryptography' functions.
Remove dependency in dev-requirements.txt that causes error.
Ensure that the latest consistent metadata is added to Snapshot.
Tweak a few logger and exception messages.
Revise introductory text in README.
Update ADOPTERS.md and link to pages that cover each adoption.
Remove target paths in metadata that contain leading path separators.
Address Pylint/Bandit warnings for the CLI modules.
Replace calls to deprecated 'imp' module.
Fix bug where the hashing algorithms used to generate local KEYIDs does not match the ones chosen by the repo.
Fix bug in tuf.sig.get_signature_status() where a given threshold is not used.
Refactor code that stores the previous keyids of a role.
Nothing published for this version
Fix PGP key fingerprint provided for security vulnerability reports.
Note: This is a backwards-incompatible pre-release.
Support TAP 4 (multiple repository concensus on entrusted targets). https://github.com/theupdateframework/taps/blob/master/tap4.md
Add quick start guide.
Add CLI (repo.py) to create and modify repositories.
Refactor client CLI (client.py).
Add pyup.io to manage dependencies.
Update all dependencies to their latest versions.
Add Pylint and Bandit (security) linters to Travis CI. Fix issues reported by both linters.
Tidy up documenation and directory structure.
Add option to exclude custom field when returning valid targetinfo with MultiRepoUpdater.get_valid_targetinfo().
Fix PGP key fingerprint provided for security vulnerability reports.
Modify API for creating delegations.
Add wrapper functions for securesystemslib functions.
Fix bug: non-default repository names raises an exception.
Refactor modules for inconsistent use of whitespace and indentation.
Add cryptographic functions to read and write keys from memory.
Add full support for ECDSA keys. List ecdsa-sha2-nistp256 in specification.
Remove example metadata. Documentation now points to up-to-date metadata in the tests directory.
Remove all references to PyCrypto.
Add copyright and license to all modules.
Add README for the unit tests.
Remove remnants of the compressed metadata feature (now discontinued).
Fix minor issues such as broken links, typos, etc.
Update configuration files to fix issues, such as duplicate upgrade commands, badges, etc.
Revise policy on static code analysis, CI, etc.
Earn CII Best Practices Badge.
Reach 98% score for CII Silver Badge.
Remove obsolete code, such as tufcli.py, interposition, check_crypto_libraries(), etc.
…requirements, and instructions for submitting a vulnerability report.
Note: This is a backwards-incompatible pre-release.
Add CHANGELOG.md, MAINTAINERS.txt, CODE-OF-CONDUCT.md, GOVERNANCE.md, ADOPTERS.md, DCO requirements, and instructions for submitting a vulnerability report.
Move specification to github.com/theupdateframework/specification.
Dual license the project: MIT license and Apache license, version 2.
Update to latest version of securesystemslib v0.10.8, which dropped PyCrypto and multi-lib support.
Add ecdsa-sha2-nistp256 to specification.
Remove directory of example metadata. Documentation now references unit test metadata.
Implement TAP 9 (mandatory metadata signing schemes). https://github.com/theupdateframework/taps/blob/master/tap9.md
Drop support for Python 2.6 and 3.3.
Support Python 3.6.
Improve code coverage to 99%.
Convert specification from text to Markdown format.
Add MERCURY paper, which covers protection against roleback attacks.
Implement TAP 6 (include specification version in metadata).
Implement TAP 10 (remove native support for compressed metadata).
Support ability to append an externally-generated signature to metadata.
Remove capitalization from rolenames listed in metadata.
Add a more detailed client workflow to specification.
Modify client workflow: A client must now fetch root first. Intermediate versions of Root must also be downloaded and verified by the client. See specification for modified workflow.
Fix bug with key IDs, where incorrect number of key IDs are detected.
Minor bug fixes, such as catching correct type and number of exceptions, detection of slow retrieval attack, etc.
Do not list Root's hash and lenth in Snapshot (only its version number).
Allow user to configure hashing algorithm used to generate hashed bin delegations.
Fix Markdown errors in SECURITY.md.
Add fast-forward attack to specification
Remove simple-settings dependency
Move crypto-related code to external library (securesystemslib).
Allow replacement of already listed targets in metadata. Fix issue #319.
Add instructions for contributors in README.
Copy (rather than link) target file to consistent target. Fix issue #390.
Rename target() -> get_one_valid_targetinfo().
Ensure consistent Root is written if consistent snapshot = False. Fix issue #391.
repository_tool.status(): Print status of only the top-level roles.
Document and demonstrate protection against repository attacks.
Add installation instructions for Fedora-based environments.
Exclude "private" dict key from metadata.
"backtrack" attribute renamed to "terminating".
Fix data loss that might occur during sudden power failure. Pull requests #365, 367.
Add repository tool function that can mark roles as dirty.
Store all delegated roles in one flat directory.
Support Unix shell-style wildcards for paths listed in metadata.
Add draft of specification (version 1.0).
Sleep a short while during download.py while loop to release CPU.
Support multiple key ID hashing algorithms.
Prepend version number to filename of consistent metadata.
Remove updater method: refresh_targets_metadata_chain().
Add Diplomat paper. It covers integrating TUF with community repositories.
Add project logo.
Delegations now resemble a graph, rather than a tree.
Fix Python 3 str<->bytes issues
@vladimir-v-diaz vladimir-v-diaz released this on Jan 22, 2016 · 879 commits to develop since this release
Fix Python 3 str<->bytes issues
Drop support for Python 3.2
Support Python 3.5
Fix for Issue #244 (hash, rather than hash algorithm, should be prepended to consistent targets)
Support externally created PEM files. Previous release generated an unexpected keyid for the external public key because of trailing whitespace, which
Using TUF section of the README.@vladimir-v-diaz vladimir-v-diaz released this on Jul 23, 2014 · 1058 commits to develop since this release
Support externally created PEM files. Previous release generated an unexpected keyid for the external public key because of trailing whitespace, which did not match the format of internally generated keys saved to metadata.
Fix installation instructions. Non-wheel installation instruction listed an invalid command-line option to pip (-no-use-wheel, which is missing a leading hyphen.)
Add paragraph to Using TUF section of the README.
@vladimir-v-diaz vladimir-v-diaz released this on Jul 16, 2014 · 1069 commits to develop since this release
@vladimir-v-diaz vladimir-v-diaz released this on Jul 16, 2014 · 1069 commits to develop since this release
@trishankkkarthik trishankkarthik released this on Sep 21, 2013 · 1877 commits to develop since this release
@trishankkkarthik trishankkarthik released this on Sep 21, 2013 · 1877 commits to develop since this release
Your coding agent can read these notes before it upgrades. Set up the MCP server →