Tuf 1.0.1

There is a newer prerelease version of this package available.
See the version list below for details.
dotnet add package Tuf --version 1.0.1
                    
NuGet\Install-Package Tuf -Version 1.0.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Tuf" Version="1.0.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Tuf" Version="1.0.1" />
                    
Directory.Packages.props
<PackageReference Include="Tuf" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Tuf --version 1.0.1
                    
#r "nuget: Tuf, 1.0.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Tuf@1.0.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Tuf&version=1.0.1
                    
Install as a Cake Addin
#tool nuget:?package=Tuf&version=1.0.1
                    
Install as a Cake Tool

Tuf

A .NET implementation of The Update Framework (TUF) client for secure software update verification.

Overview

Tuf provides a standards-compliant TUF client that securely downloads and verifies metadata from a TUF repository. It handles the full metadata verification workflow including root rotation, timestamp/snapshot freshness checks, and signature validation.

Features

  • TUF specification compliant — implements the client workflow from the TUF specification
  • Secure root rotation — safely updates trust anchors across key rotations
  • Metadata verification — validates signatures, expiration, and version consistency
  • Pluggable caching — in-memory and file-system cache implementations included
  • Pluggable repository — HTTP repository included, custom transports supported
  • AOT-compatible — fully trimmer and NativeAOT safe

Quick Start

using Tuf;

// Create a TUF client with HTTP repository and file-system cache
var options = new TufClientOptions
{
    RepositoryUri = new Uri("https://tuf-repo-cdn.sigstore.dev"),
    Cache = new FileSystemTufCache("/path/to/cache")
};

var client = new TufClient(options);

// Refresh metadata (downloads and verifies latest metadata)
await client.RefreshAsync();

Documentation

📖 Full documentation

License

MIT — see LICENSE.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on Tuf:

Package Downloads
Sigstore

A .NET library for generating and verifying Sigstore signatures.

GitHub repositories (1)

Showing the top 1 popular GitHub repositories that depend on Tuf:

Repository Stars
microsoft/aspire
Aspire is the tool for code-first, extensible, observable dev and deploy.
Version Downloads Last Updated
1.1.0-alpha.135.1.399a6e9 57 8/29/2026
1.1.0-alpha.131.1.fd8696f 140 8/24/2026
1.1.0-alpha.129.1.d458555 61 8/24/2026
1.1.0-alpha.120.1.e78e1a9 57 8/22/2026
1.1.0-alpha.117.1.09281bc 64 8/22/2026
1.1.0-alpha.111.1.15fc60d 63 8/14/2026
1.1.0-alpha.108.1.d72863b 53 8/14/2026
1.0.1 530 8/24/2026
1.0.1-beta.122.1.7bc133a 101 8/22/2026
1.0.1-beta.112.1.de60e02 66 8/14/2026
1.0.1-beta.107.1.9ecbab6 51 8/14/2026
1.0.0 468 8/14/2026
1.0.0-beta.101.1.dd7cd33 78 8/14/2026
1.0.0-alpha.100.1.dd7cd33 110 8/13/2026
0.5.0 6,530 3/20/2026
0.4.0 736 3/11/2026
0.3.0 324 3/3/2026
0.2.0 170 3/3/2026