TUF-on-CI
Radar: Initial
MIT
Runs a TUF repository and its signing ceremonies inside CI, with hardware-token signing and review gates.
The Update Framework
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| The Update Framework | signs |
Using this from an agent
- Interfaces
ci-actioncli- Consumes
- tuf-metadata
- Emits
- tuf-metadata
- Runtime
- Needs network Non-deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Operate a TUF repository without building bespoke signing infrastructure.
ci-pipeline
- Website
- https://github.com/theupdateframework/tuf-on-ci
- Repository
- https://github.com/theupdateframework/tuf-on-ci
- License
- MIT — read from the repository's LICENSE file, verified 2026-08-11
- Stars
- 51 · last commit 2026-08-10
Reading this as an agent? Don't scrape the page — this entry is published as
structured data at
arrow_back
All tools by adoption
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.