Automic VaultAutomic Vault

brew

actions-up mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für actions-up in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install actions-up

local Homebrew formula metadata

Überblick

Paketzusammenfassung

Tool to update GitHub Actions to latest versions with SHA pinning

Befehle und Aliase

  • actions-up

Verlauf

Projektgeschichte und Nutzung

Actions Up is an interactive CLI for finding newer GitHub Actions references in workflow and composite-action YAML, then updating them with SHA pinning by default.

Projektgeschichte

The project was created in August 2025 and released v0.1.0 the same day. Its README positions the tool around secure and reproducible CI by replacing mutable action tags with exact commit SHAs unless the user chooses to preserve tag-style references.

Adoptionsgeschichte

The README supports quick npx use, global npm installation, per-project dev dependency installation, and Homebrew installation, which puts it in the common JavaScript CLI plus package-manager distribution pattern.

Wie es verwendet wird

Actions Up scans .github/workflows, .github/actions, root action.yml/action.yaml files, and reusable workflow calls. Users can run interactive mode, --yes auto-update mode, --dry-run, --json report mode, recursive scans, custom directories, update modes, exclusions, and CI checks.

Warum Paket-Nerds sich dafür interessieren

It is notable in package-manager culture because it overlaps dependency-update bots while staying local and interactive: users can inspect updates, pin SHAs, and generate CI reports without adopting a hosted bot workflow.

Zeitleiste

  • 2025: Repository created.
  • 2025: v0.1.0 release published.
  • 2026: v1.15.0 release published on June 29.

Related projects

  • The README compares Actions Up with Dependabot, Renovate, and pinact.

Quellen

  • GitHub repository and releases API for creation and release chronology.
  • Official README for project positioning, usage, install paths, and related tools.

Sicherheitslage

Risikostufe: grün

narrow executable package without higher-risk signals.

Risikoklassifikator

grün Risiko · niedrig Konfidenz · appliance

Warum

  • narrow executable package without higher-risk signals

Signale

  • metadata:no-higher-risk-signals

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 1 Plattformziele verfügbar.
  • Installiert mit 1 Laufzeitabhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
actions-upcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version1.16.0
Manager aktualisiert2026-07-03
lokale DatenOK
Upstreamnot checked
neueste erkannte Versionnicht erkannt

https://github.com/azat-io/actions-up

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:actions-up
Version1.16.0
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/actions-up
Homepagehttps://github.com/azat-io/actions-up
Repositoryhttps://github.com/azat-io/actions-up
Upstream-Dokumentationhttps://github.com/azat-io/actions-up#readme
LizenzMIT
Quellarchivhttps://registry.npmjs.org/actions-up/-/actions-up-1.16.0.tgz
Zuletzt aktualisiert2026-07-03T15:04:32Z
Pulseupdated
Abhängigkeitennode
Bottleverfügbar (auf all)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameactions-up
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment