Skip to main content

TAF (The Archive Framework)

TAF is a framework that aims to provide archival authentication and ensure that Git repositories can be securely cloned/updated. TAF's implementation strongly relies on The Update Framework (TUF), which helps developers maintain the security of a software update system. It provides a flexible framework and specification that developers can integrate into any software update system. TAF integrates Git with TUF:

  • TUF targets were modified to authenticate Git commits instead of individual files. This reduces the metadata size and simplifies authentication.
  • The TUF metadata repository storage utilizes Git. That means TUF metadata files are stored in a Git repository, which is referred to as an authentication repository.

When a TAF authentication repository is cloned, all target repositories are also cloned, and TUF validation is performed against every commit since the repository's inception. When a TAF repository is updated, data is fetched from upstream and each commit is authenticated. A TAF clone/update differs from a standard Git clone/fetch in that remote commits aren't added to the local Git repositories until they've been fully authenticated locally. TAF can be used to secure any git repository, regardless of its content.

Threats

A git repository can be compromised in several ways:

  • An attacker might hack a user's account on a code hosting platform, like GitHub or GitLab.
  • An attacker might compromise the hosting platform itself.
  • An attacker might gain access to a developer's personal computer.

Such an attacker could then:

  • Upload a new GPG key to GitHub.
  • Push new commits to any repository.
  • Add another authorized user with write access.
  • Unprotect the master branch of any repository and force-push to it.

TAF's primary objective is not to prevent the attacks listed above but rather to detect when an attack has occurred and halt an update if necessary. Thus, TAF should be used instead of directly calling git pull and git clone.

Further reading

  1. UELMA whitepaper
  2. TAF implementation and integration with TUF

Installation Steps

From PyPI

pip install taf

From source:

pip install -e .

Install extra dependencies when using Yubikey:

pip install taf[yubikey]

Add bash completion:

  1. copy taf-complete.sh to user's directory
  2. add source ./taf-complete.sh to ~/.bash_profile or ~/.bashrc
  3. source ~/.bash_profile

Development Setup

We are using pre-commit to run black code formatter, flake8 and bandit code quality checks, as well as Mypy static type checker.

pip install -e .[dev]
pip install -e .[test]

pre-commit install # registers git pre-commit hook

pre-commit run --all-files # runs code formatting and quality checks for all files

NOTE: For Windows users: Open settings.json and replace paths.

Running Tests

To run tests with mocked Yubikey:

pytest

To run tests with real Yubikey:

  1. Insert test Yubikey
  2. Run taf setup_test_key WARNING: This command will import targets private key to signature slot of your Yubikey, as well as new self-signed x509 certificate!
  3. Run REAL_YK=True pytest or set REAL_YK=True pytest depending on platform.

Installing Wheels on Windows and MacOS

The newer versions of TAF do not require additional setup, and there are no platform-specific wheels needed. However, older versions required certain platform-specific DLLs, which the CI would copy to taf/libs before building a wheel. Therefore, it's important to install the appropriate platform-specific wheel if you're using an older version.

Installing Wheels on Ubuntu

  • Install dependencies
sudo add-apt-repository ppa:jonathonf/python-3.10
sudo apt-get update
sudo apt-get install python3.10
sudo apt-get install python3.10-venv
sudo apt-get install python3.10-dev
sudo apt-get install swig
sudo apt-get install libpcsclite-dev
sudo apt-get install libssl-dev
sudo apt-get install libykpers-1-dev
  • Create virtual environment
python3.10 -m venv env
pip install --upgrade pip
pip install wheel
pip install taf
  • Test CLI
taf

Related Projects

There are projects which share similar ideas to TAF.

gittuf

gittuf is a security layer for Git repositories. gittuf enables a security policy to be specified for a Git repository, such that any user who has read access to the repository may verify compliance with it. While similar in goals, gittuf differs from TAF in its architecture and intended use case.

TAF relies on a multi-repository architecture: TUF metadata resides in an authentication repository, which is used to validate the changes made to any number of target repositories. For detailed information on TAF's architecture, see the TAF architecture document. TAF is intended to verify changes to an archive consisting of any number of Git repositories.

gittuf relies on a Reference State Log (RSL) that encodes a log of repository activity, as well as security policy, loosely based on TUF metadata. This log is then used to enable the validation of every commit in the protected repository. For detailed information on gittuf's architecture, see the gittuf design document. gittuf may be used to verify changes to any single Git repository (multi-repository support is in progress).

Acknowledgements

This project was made possible in part by the Institute of Museum and Library Services (LG-246285-OLS-20)

Metadata

Release files for taf 0.39.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for taf 0.39.3
File Size Uploaded
taf-0.39.3.tar.gz 192.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for taf 0.39.3
File Interpreter ABI Platform
taf-0.39.3-py3-none-any.whl Python 3 none any Details

Total release size: 502.1 kB

Release files / taf-0.39.3.tar.gz

Download URL taf-0.39.3.tar.gz
Size 192.3 kB
Tags Source
SHA-256 checksum
How to use checksums
e712b7b00c836d2a335c811a36093854e72fc3c21d215bb9db00527627398deb
BLAKE2b-256 checksum
How to use checksums
20bbc1e5eb8a20adf18ed7c8e76f2ed1ef9307364fb6eed0b12235b6c67673c7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.8.0 pkginfo/1.13 readme-renderer/46.0 requests/2.34.2 requests-toolbelt/1.0.0 urllib3/2.7.0 tqdm/4.70.0 importlib-metadata/9.0.1 keyring/25.7.0 rfc3986/2.0.0 colorama/0.4.6 CPython/3.10.21

Release files / taf-0.39.3-py3-none-any.whl

Download URL taf-0.39.3-py3-none-any.whl
Size 309.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
abdc5134f3576341c4e6c8866d05d7dcf5493fe19a6fc28308def0feaf30ea42
BLAKE2b-256 checksum
How to use checksums
7119c26553519c4f23039609e6e55b95f25b11af7e781fc390cf181fc85faa41
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.8.0 pkginfo/1.13 readme-renderer/46.0 requests/2.34.2 requests-toolbelt/1.0.0 urllib3/2.7.0 tqdm/4.70.0 importlib-metadata/9.0.1 keyring/25.7.0 rfc3986/2.0.0 colorama/0.4.6 CPython/3.10.21

Release history Release notifications | RSS feed

0.40.0

2 release files

This release

0.39.3 This release

2 release files

0.39.2

2 release files

0.38.3

2 release files

0.38.2

2 release files

0.38.1

2 release files

0.37.6

2 release files

0.37.5

2 release files

0.37.4

2 release files

0.37.1

2 release files

0.37.0

2 release files

0.36.2

2 release files

0.36.1

2 release files

0.36.0

2 release files

0.35.4

2 release files

0.35.3

2 release files

0.35.2

2 release files

0.35.1

2 release files

0.34.1

2 release files

0.33.0

2 release files

0.32.3

2 release files

0.32.2

2 release files

0.32.0

2 release files

0.31.2

2 release files

0.16.0

7 release files

0.15.0

7 release files

0.14.0

7 release files

0.13.4

7 release files

0.13.3

7 release files

0.13.2

7 release files

0.13.1

7 release files

0.13.0

7 release files

0.12.0

7 release files

0.11.2

7 release files

0.11.1

7 release files

0.11.0

7 release files

0.10.1

7 release files

0.10.0

7 release files

0.9.0

7 release files

0.8.1

7 release files

0.8.0

7 release files

0.7.2

7 release files

0.7.1

7 release files

0.7.0

7 release files

0.6.1

4 release files

0.6.0

4 release files

0.5.2

4 release files

0.5.1

4 release files

0.5.0

4 release files

0.4.1

4 release files

0.4.0

4 release files

0.3.1

4 release files

0.3.0

4 release files

0.2.2

4 release files

0.2.1

4 release files

0.2.0

4 release files

0.1.8

4 release files

0.1.7

4 release files

0.1.6

4 release files

0.1.5

4 release files

0.1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page