theupdateframework / theupdateframework/python-tuf

blog post about choosing your repository implementation

Open
#2,452 2 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
1.7k
Forks
304
Avg merge
1d 2h
Merged PRs (30d)
17

Description

I'd like to have a text I can link to that explains some of the things that affect the choices in TUF repository setup and (now that we have multiple implementations) makes practical comparisons.

We should write a blog post that talks about

  • basic requirements that apply to any TUF setup (e.g. trusted client software that you can embed root metadata in)
  • what tuf-on-ci and RSTUF are good for and and how they work differently

Planning to set up a TUF repository to securely deliver your digital artifacts? Confused by all of the choices available? This essay is for you!

@kairoaraujo a blog collaboration maybe?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the issue brief and gather the stated baseline TUF requirements plus the practical differences between tuf-on-ci and RSTUF. Done means a reviewed, publishable blog post that compares repository choices and can be linked to by people setting up TUF repositories.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.