{"id":13561666,"url":"https://github.com/gittuf/gittuf","last_synced_at":"2025-04-03T17:31:22.127Z","repository":{"id":73256005,"uuid":"558971199","full_name":"gittuf/gittuf","owner":"gittuf","description":"A security layer for Git repositories","archived":false,"fork":false,"pushed_at":"2024-10-30T00:46:53.000Z","size":4876,"stargazers_count":460,"open_issues_count":68,"forks_count":32,"subscribers_count":18,"default_branch":"main","last_synced_at":"2024-10-30T01:47:37.439Z","etag":null,"topics":["access-control","git","git-security","gittuf","tuf"],"latest_commit_sha":null,"homepage":"https://gittuf.dev","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/gittuf.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":"docs/roadmap.md","authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-10-28T18:03:43.000Z","updated_at":"2024-10-28T14:17:50.000Z","dependencies_parsed_at":"2023-11-20T01:30:56.469Z","dependency_job_id":"983ccdd4-cb45-47e8-b733-53a7af921dec","html_url":"https://github.com/gittuf/gittuf","commit_stats":null,"previous_names":[],"tags_count":12,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gittuf%2Fgittuf","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gittuf%2Fgittuf/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gittuf%2Fgittuf/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gittuf%2Fgittuf/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/gittuf","download_url":"https://codeload.github.com/gittuf/gittuf/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247046920,"owners_count":20874740,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["access-control","git","git-security","gittuf","tuf"],"created_at":"2024-08-01T13:00:59.763Z","updated_at":"2025-04-03T17:31:18.749Z","avatar_url":"https://github.com/gittuf.png","language":"Go","funding_links":[],"categories":["Go"],"sub_categories":[],"readme":"\u003cimg src=\"https://raw.githubusercontent.com/gittuf/community/bd8b367fa91fab0fddaa1943e0131e90e04e6b10/artwork/PNG/gittuf_horizontal-color.png\" alt=\"gittuf logo\" width=\"25%\"/\u003e\n\n[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/7789/badge)](https://www.bestpractices.dev/projects/7789)\n![Build and Tests (CI)](https://github.com/gittuf/gittuf/actions/workflows/ci.yml/badge.svg)\n[![Coverage Status](https://coveralls.io/repos/github/gittuf/gittuf/badge.svg)](https://coveralls.io/github/gittuf/gittuf)\n\ngittuf is a security layer for Git repositories. With gittuf, any developer who\ncan pull from a Git repository can independently verify that the repository's\nsecurity policies were followed. gittuf's policy, inspired by [The Update\nFramework (TUF)], handles key management for all trusted developers in a\nrepository, allows for setting permissions for repository branches, tags, files,\netc., protects against [other attacks] Git is vulnerable to, and more — all\nwhile being backwards compatible with forges such as GitHub and GitLab.\n\ngittuf is a sandbox project at the [Open Source Security Foundation (OpenSSF)]\nas part of the [Supply Chain Integrity Working Group].\n\n## Current Status\n\ngittuf is currently in alpha. gittuf's metadata may have breaking changes,\nmeaning a repository's gittuf policy may have to be reinitialized from time to\ntime. As such, gittuf is currently not intended to be the primary mechanism for\nenforcing a repository's security.\n\nThat said, we're actively seeking feedback from users. Take a look at the [get\nstarted guide] to learn how to install and try gittuf out! Additionally,\ncontributions are welcome, please refer to the [contributing guide], our\n[roadmap], and the issue tracker for ways to get involved.\n\n## Installation \u0026 Get Started\n\nSee the [get started guide].\n\n[The Update Framework (TUF)]: https://theupdateframework.io/\n[other attacks]: https://ssl.engineering.nyu.edu/papers/torres_toto_usenixsec-2016.pdf\n[contributing guide]: /CONTRIBUTING.md\n[roadmap]: /docs/roadmap.md\n[Open Source Security Foundation (OpenSSF)]: https://openssf.org/\n[Supply Chain Integrity Working Group]: https://github.com/ossf/wg-supply-chain-integrity\n[get started guide]: /docs/get-started.md\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgittuf%2Fgittuf","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgittuf%2Fgittuf","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgittuf%2Fgittuf/lists"}