pkg.soopen package index

brew / rang 7637

Installer gittuf avec Homebrew, apt, Nix, winget

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de gittuf pour les workflows d'agents IA.

installation

Commandes d'installation supplémentaires

macOS

Homebrewvérifié · 100%
brew install gittuf

local Homebrew formula metadata

Linux

Debian aptvérifié · 92%
sudo apt install gittuf

Debian stable package indexes · gittuf · Source: deb.debian.org

Nixvérifié · 92%
nix profile install nixpkgs#gittuf

nixpkgs package indexes · pkgs/by-name/gi/gittuf/package.nix · Source: api.github.com

Windows

Windows Package Managervérifié · 92%
winget install --id gittuf.gittuf -e

Windows Package Manager source index · gittuf.gittuf · Source: cdn.winget.microsoft.com

aperçu

Résumé du paquet

Security layer for Git repositories

Commandes et alias

  • git-remote-gittuf
  • gittuf

historique

Historique du projet et usages

gittuf is a Git repository security system that brings The Update Framework-style policy metadata, signed trust roots, and independent verification to source control. Its main claim to package-manager relevance is that it treats Git history and Git references as supply-chain assets rather than merely developer convenience data.

Historique du projet

The gittuf repository was opened in 2022, with the project describing itself as a platform-agnostic Git security system. Its README states that repository maintainers can use gittuf to protect repository contents from unauthorized or malicious changes and to avoid making a Git forge the single point of trust.

The first GitHub release, v0.1.0, was published in October 2023. The roadmap shows the project evolving through alpha and beta milestones, policy files, a reference state log, metadata synchronization, and dogfooding of the gittuf repository itself.

The design expanded beyond basic reference protection into supply-chain attestations. The roadmap records in-toto attestation support as reached by April 2024 and describes work on Git forge integration, including a GitHub app that records code-review and merge attestations and reports verification status on pull requests.

Historique d'adoption

gittuf's adoption story is institutional as well as technical: the README identifies it as an incubating Open Source Security Foundation project in the Supply Chain Integrity Working Group. Packaging across Homebrew, Debian, Nix, and WinGet gives the tool the installation surface expected for security tooling that may be evaluated by teams on different operating systems.

The project sits near Sigstore, gitsign, in-toto, and SLSA in the software supply-chain ecosystem. Its distinguishing role is source-control policy verification that can be checked outside any one forge.

Modes d'utilisation

A typical workflow starts by generating keys, initializing a Git repository, running `gittuf trust init`, adding policy keys, creating policy rules for protected branches or files, staging and applying policy metadata, and recording reference changes in the reference state log.

Practitioners use `gittuf verify-ref` to check whether a reference follows policy, `gittuf sync` or the `git-remote-gittuf` transport to move gittuf metadata with remote repositories, and manual Git ref pushes or fetches for environments that prefer explicit metadata handling.

Pourquoi les passionnés de paquets s'y intéressent

gittuf matters to package nerds because it frames source repository state as an input to downstream package trust. It complements artifact signing and provenance by asking whether the Git branch, tag, or file path that produced a package was changed by an authorized identity under an auditable policy.

Chronologie

  • 2022: Public GitHub repository opened.
  • 2023: v0.1.0 release published.
  • 2024: Roadmap records in-toto attestation integration as reached.
  • 2025: Roadmap describes GitHub app integration work for pull-request attestations and policy verification status checks.

Related projects

  • The Update Framework.
  • OpenSSF Supply Chain Integrity Working Group.
  • Sigstore, gitsign, in-toto, and SLSA.
  • GitHub and GitLab repository policy systems.

posture de sécurité

Niveau de risque : vert

narrow executable package without higher-risk signals.

Classificateur de risque

risque vert · confiance faible · appliance

Pourquoi

  • narrow executable package without higher-risk signals

Signaux

  • metadata:no-higher-risk-signals

Comportement d'installation

  • Aucune métadonnée de bottle Homebrew n’a été enregistrée.

Revue recommandée

Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.

exécutables

Exécutables installés

CommandeTypeExpositionNote
git-remote-gittufexécutableexécutable indexéDécouvert depuis l'index local des exécutables.
gittufexécutableexécutable indexéDécouvert depuis l'index local des exécutables.

fraîcheur

Version et fraîcheur

Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.

page générée2026-08-03
version du gestionnaire0.15.0
gestionnaire mis à jour2026-07-27
données localesinconnu
amontnon disponible
dernière version détectéenon détecté
  • OKAucun avertissement de fraîcheur n'a été généré.

métadonnées d'installation

Métadonnées du paquet

Clé du paquetbrew:gittuf
Version0.15.0
Gestionnaire de paquetsHomebrew
Page d'accueilhttps://gittuf.dev/
Dépôthttps://github.com/gittuf/gittuf
Dernière mise à jour2026-07-27T14:57:49+02:00
Pulseupdated
Bouteillenon enregistré
Serviceaucun déclaré

correspondances dans les bases sources

Autres enregistrements de gestionnaires de paquets

Les correspondances proviennent d’index externes de gestionnaires de paquets et restent séparées des liens de paquets Automic Vault locaux.

Debian apt95%

gittuf 0.9.0-5+b6

security layer for Git repositories (program)

https://github.com/gittuf/gittuf

sudo apt install gittuf
  • Section: vcs
  • Architecture: amd64
  • Source Package: gittuf
  • 1 Dépendances
  • normalized package name match
  • Correspondance par : Gittuf
Debian stable package indexes · deb.debian.org · Debian stable package indexes: gittuf from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Debian apt95%

golang-github-gittuf-gittuf-dev 0.9.0-5

security layer for Git repositories (Go library)

https://github.com/gittuf/gittuf

sudo apt install golang-github-gittuf-gittuf-dev
  • Section: golang
  • Architecture: all
  • Source Package: gittuf
  • 21 Dépendances
  • normalized package name match
  • Correspondance par : Gittuf
Debian stable package indexes · deb.debian.org · Debian stable package indexes: golang-github-gittuf-gittuf-dev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Nix95%

gittuf

nix profile install nixpkgs#gittuf
  • normalized package name match
  • Correspondance par : Gittuf
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/gi/gittuf/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
winget95%

gittuf.gittuf

winget install --id gittuf.gittuf -e
  • normalized package name match
  • Correspondance par : Gittuf
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: gittuf.gittuf from https://cdn.winget.microsoft.com/cache/source.msix
winget92%

gittuf.git-remote-gittuf

winget install --id gittuf.git-remote-gittuf -e
  • installed executable or alias match
  • Correspondance par : Git Remote Gittuf
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: gittuf.git-remote-gittuf from https://cdn.winget.microsoft.com/cache/source.msix

piste source

Généré depuis les données du dépôt

Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.

Sources utilisées

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation