OpenSSF project

Repository Service for TUF (RSTUF)

A drop-in implementation of The Update Framework (TUF) that protects software repositories from compromise, rollback, and man-in-the-middle attacks.

How each persona uses Repository Service for TUF (RSTUF)

Software Developer / Maintainer Developer

Relies on RSTUF-backed repositories to confidently pull dependencies without fear of targeted man-in-the-middle or rollback attacks.

See everything for Developer →

Open Source Professional (OSPO) OSPO

Recommends RSTUF to ensure the organization's internally hosted artifact repositories are resilient against compromise.

See everything for OSPO →

Security Engineer / Architect Security

Implements The Update Framework (TUF) via RSTUF to secure software delivery architectures and protect cryptographic root keys.

See everything for Security →

CI/CD DevOps & Tooling Integrator DevOps

Configures build pipelines to exclusively interact with RSTUF-secured repositories to guarantee the integrity of fetched dependencies.

See everything for DevOps →

Package & Repository Manager Package Manager

Implements RSTUF to secure content downloads against tampering between the remote repository and the client.

See everything for Package Manager →

Executive / End-User Consumer Executive

Reduces enterprise liability by ensuring all software updates distributed to customers are cryptographically verified and secure.

See everything for Executive →

Problems Repository Service for TUF (RSTUF) helps with

Artefact Signing & Verification Signing

Cryptographically signs repository metadata so clients can verify content has not been tampered with in transit.

See everything for Signing →

Build & Provenance Integrity Build Integrity

Protects the distribution chain against rollback and man-in-the-middle attacks between repository and client.

See everything for Build Integrity →