The Update Framework and You - Sigstore Blog
If you’re anything like me and spend time reading blog posts and GitHub discussions around how to securely package and release software, you’ve probably heard of The Update Framework. Unfortunately, if you’re actually anything like me it probably seemed overwhelming and confusing at first. This blog post explains the mental model I’ve built up for TUF, and some of the concepts that finally made it understandable and digest-able for me. Naming is hard, but TUF really isn’t a framework in the traditional sense. In my head, a framework is something like a library but also the opposite. Libraries provide useful functions you can call in your program however you see fit, frameworks give you, well, a framework to write your application inside of. You call libraries, frameworks call you. While there are some TUF libraries that make working with TUF metadata and formats easier, TUF is neither a library nor a framework. So, what is it then? TUF is a set of defined attacks and threat models spec
Why does it need to be so TUF? If you’re anything like me and spend time reading blog posts and GitHub discussions around how to securely package and release software, you’ve probably heard of The Update Framework . Unfortunately, if you’re actually anything like me it probably seemed overwhelming and confusing at first. This blog post explains the mental model I’ve built up for TUF, and some of the concepts that finally made it understandable and digest-able for me. What is TUF? Naming is hard, but TUF really isn’t a framework in the traditional sense. In my head, a framework is something lik
Explore this link on the map →related reading
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Security incident disclosure — July 2026huggingface.co
- Themes from Real World Crypto 2022 - The Trail of Bits Blogblog.trailofbits.com
- A Founder's Farewell • Blogurbit.org
- Security Principles | Computer Securitytextbook.cs161.org
- Software Supply Chain Security (Part 1)softwareanalyst.substack.com
- Tailscale: How it workstailscale.com
- Turnkey Whitepaperwhitepaper.turnkey.com
- Turnkey Whitepaperwhitepaper.turnkey.com
- State of DevSecOps | Datadogdatadoghq.com
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2softwareanalyst.substack.com