← Home

@sigstore/tuf

Client for the Sigstore TUF repository

1
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

bdehamer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:yup AI (typosquat): @sigstore/tuf is a scoped package under the official Sigstore org namespace; the levenshtein match against 'yup' is a false positive with no plausible impersonation intent. ai
dependencies unvetted-dep:tuf-js AI (dependencies): tuf-js is the canonical TUF client library for Node.js, a direct dependency expected for this Sigstore TUF client package. ai
dependencies unvetted-dep:@sigstore/protobuf-specs AI (dependencies): @sigstore/protobuf-specs is an official Sigstore ecosystem package; expected dependency for this package. ai

Versions (showing 1 of 1)

Version Deps Published
4.0.2 2 / 3