Visitar URL original
TUF specification has a new version - v1.0.32 · Issue #2394 · theupdateframework/python-tuf · GitHub
Skip to content

TUF specification has a new version - v1.0.32 #2394

Description

@github-actions

Hey, it seems there's a newer version of the TUF specification - v1.0.32

The version which theupdateframework/python-tuf states it supports is - v1.0.31

The following is a comparison of what changed between the two versions - Compare v1.0.31 to v1.0.32

Please review the newer version and address the changes.

Activity

  1. ishan-1010 commented on Oct 7, 2026

    @ishan-1010

    went through the spec diff v1.0.31...v1.0.36 (37 commits, only tuf-spec.md has real changes). what changed and where python-tuf stands:

    • the ecdsa keytype is now "ecdsa" and the scheme stays "ecdsa-sha2-nistp256". nothing in the repo uses the old keytype, and securesystemslib's CryptoSigner.generate_ecdsa() already gives keytype "ecdsa".
    • threshold counting: one verified signature per keyid, even if a keyid shows up twice in "signatures". Role rejects duplicate keyids (_payload.py:293), Metadata.signatures is a dict keyed by keyid, and verification walks role.keyids, so a duplicate can't count twice.
    • the canonical json link, licence and governance files are editorial.

    so no code changes needed. what's left is SPECIFICATION_VERSION in tuf/api/_payload.py:43 and the spec_version in the 4 generated fixtures under tests/generated_data/ed25519_metadata. want me to send that as a PR, or is there a reason to stay on 1.0.31?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions