About
Overview History Timeline Project Publications Code of conduct
Getting started
Security Roles and metadata Frequently asked questions Specification (latest) Specification index Implementations Videos
Community
Adoptions Reporting issues Security audits Enhancement proposals Contribute Chat (CNCF Slack)
Blogs News Contact

Publications

The following papers provide detailed information on securing software updater systems, TUF's design, attacks on package managers, and package management security:

  • Mercury: Bandwidth-Effective Prevention of Rollback Attacks Against Community Repositories

  • Diplomat: Using Delegations to Protect Community Repositories

  • Survivable Key Compromise in Software Update Systems

  • A Look In the Mirror: Attacks on Package Managers

  • Package Management Security

© 2024 The Update Framework authors | Documentation Distributed under CC-BY-4.0

© 2024 The Linux Foundation. All rights reserved. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page.


The TUF project is managed by the Linux Foundation under the Cloud Native Computing Foundation. The consensus builder for TUF is Prof. Justin Cappos of the Secure Systems Lab at New York University. Project maintainers[1][2] are comprised of collaborators from academia and the industry. Contributors and maintainers are governed by the CNCF Community Code of Conduct.

This material is based upon work supported by the National Science Foundation under Grant Nos. CNS-1345049 and CNS-0959138. Any opinions, findings, and conclusions or recommendations expressed in this material are those of the author(s) and do not necessarily reflect the views of the National Science Foundation.