Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
SingularityCE does not use the legacy TUF client directly. In addition, it does not use cosign routines which call the legacy TUF client for verification - it calls into sigstore verification routines directly, verifying against simple keys only. There is no TUF root support.