npm package
Home@sigstore/tuf
The @sigstore/tuf package is a JavaScript library designed for securely retrieving targets from the Sigstore TUF repository. It is ideal for applications that require secure access to trusted metadata and target files. This package initializes a local TUF cache and manages interactions with the Sigstore repository.
- lurq health score
- 80/100
- Confidence
- proven
- Weekly downloads
- 11,419,928
- Latest version
- 5.0.0
- Last release
- Aug 4, 2026
- License
- Apache-2.0
Should you depend on @sigstore/tuf?
lurq's verdict: low
- No known advisories
Check this from your coding agent
This page is a daily snapshot. lurq's verify tool checks @sigstore/tuf at the exact version your agent is about to install, and compat checks it against the rest of your stack. One command connects Claude Code, Cursor, VS Code and other agents:
npx lurqrun
Free to start. Quickstart
Other styling packages lurq scores
- @mui/private-theming94/100 · proven
- @mui/system93/100 · proven
- remeda93/100 · proven
- gaxios91/100 · proven
- @internationalized/number91/100 · proven
Scored from public signals (npm registry, GitHub, deps.dev and advisory databases). Data as of Sep 3, 2026; this page refreshes every 24 hours. Source repository.