tough
v0.21.0 GrowingThe Update Framework (TUF) repository client
Quick Verdict
- !Pre-1.0: API may have breaking changes
- โTrusted by 104 crates
- โTeam maintained (3 owners)
- !Heavy dependency tree (32 direct deps)
- โPermissive license (MIT OR Apache-2.0)
Security
Deep Insights
57.1K downloads in the last 30 days (1.9K/day), up 31% from the previous period.
104 crates depend on tough. Reasonable ecosystem adoption, though not yet a core dependency.
The primary maintainer publishes 81 crates. This suggests deep Rust expertise and long-term commitment to the ecosystem.
Despite being 6+ years old, tough hasn't reached 1.0 yet. Expect potential API changes between versions.
32 direct dependencies. Consider the impact on compile times and supply chain complexity.
Notable dependents include tough-ssm, tough-kms, tuftool, sigstore, sigstore-trust-root. When high-quality crates choose tough, it's a strong quality signal.
Health Breakdown
Recency, release consistency, active ratio
Yanked ratio, deps, size, maturity, features
Reverse deps, ownership, ecosystem
Downloads, momentum, growth trend
Docs, repo, license, metadata
Download Trend
Top Dependents
Most downloaded crates that depend on tough