Automic VaultAutomic Vault

brew

buf mit Homebrew, apk, MacPorts, Nix, pacman, scoop, winget installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für buf in AI-Agent-Workflows.

Agent-Sicherheit

Antwort zur Agent-Sicherheit

buf manages protobuf linting, generation, and registry workflows.

Credential-Zugriff

Reads registry tokens, environment variables, and project schema files.

Änderungen an Remote-Zustand

Can push modules and interact with remote schema registries.

Publish-/Artefakt-Risiko

Can publish schema modules and generated artifacts.

Empfohlene Kontrolle

Gate push, registry login, and token-backed commands.

Hinweise für Agent-Nutzung

Allow lint/generate; require approval for registry writes and token use.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install buf

local Homebrew formula metadata

MacPortsverifiziert · 94%
sudo port install buf

MacPorts ports tree · devel/buf/Portfile · Quelle: api.github.com

Windows

Scoopverifiziert · 92%
scoop install main/buf

Scoop official bucket manifest trees · bucket/buf.json · Quelle: api.github.com

Windows Package Managerverifiziert · 92%
winget install --id bufbuild.buf -e

Windows Package Manager source index · bufbuild.buf · Quelle: cdn.winget.microsoft.com

Überblick

Paketzusammenfassung

New way of working with Protocol Buffers

Befehle und Aliase

  • buf
  • protoc-gen-buf-breaking
  • protoc-gen-buf-lint

Verlauf

Projektgeschichte und Nutzung

Buf is a modern Protocol Buffers toolchain centered on the `buf` CLI, replacing many direct `protoc` workflows with module-aware builds, linting, breaking-change detection, formatting, code generation, dependency management, API calls, and access to the Buf Schema Registry.

Projektgeschichte

Buf was created by Buf Technologies as a developer-tooling layer for Protobuf projects. Its public repository presents it as a modern toolchain for Protobuf rather than a replacement for the schema language itself: it keeps the plugin model familiar to `protoc` users while adding workspace configuration, deterministic checks, and registry-aware workflows.

The project grew beyond a formatter or wrapper into a broader ecosystem: the CLI, Buf Schema Registry, remote plugins, generated SDKs, ConnectRPC, Protobuf-ES, and Protovalidate are all positioned by Buf as related pieces of schema-driven API infrastructure.

Adoptionsgeschichte

Buf adoption followed the pain points of larger Protobuf users: teams wanted one repeatable command for compiling, linting, compatibility checks, and generation instead of per-repository shell scripts around `protoc -I` paths. The CLI is distributed through Homebrew, npm, Docker, Windows installers, binary downloads, tarballs, source builds, and other package managers listed in the input.

Registry features widened its role from local CLI tooling to organization-level schema governance. The Buf Schema Registry stores modules, renders documentation, resolves dependencies, hosts remote plugins, produces generated SDKs, and can enforce schema checks for teams that publish APIs there.

Wie es verwendet wird

Typical CLI use starts with `buf config init`, then `buf build`, `buf format -w`, `buf lint`, `buf breaking --against ...`, and `buf generate`. Projects commonly check in `buf.yaml`, `buf.gen.yaml`, and `buf.lock` so CI and developer laptops run the same Protobuf workflow.

Core CLI features work without a Buf Schema Registry account, while signing in adds private module dependency resolution, remote plugins, generated SDKs, hosted documentation, and server-side checks.

Warum Paket-Nerds sich dafür interessieren

Buf matters to package-tooling people because it treats `.proto` files as versioned modules instead of loose source files copied between repos. It brings package-lock and registry patterns familiar from language ecosystems into Protobuf schema distribution.

It is also a notable example of a package manager formula that installs not only the main `buf` binary but companion protoc plugins, making Homebrew a convenient entry point for Protobuf linting and compatibility checks.

Zeitleiste

  • 2020: Early public Buf releases established the CLI around Protobuf build, lint, breaking-change, and generation workflows.
  • 2021: Buf reached a stable v1 line and documented a no-breaking-changes-within-major-version CLI policy.
  • 2020s: The project expanded around the Buf Schema Registry, remote plugins, generated SDKs, ConnectRPC, Protobuf-ES, and Protovalidate.

Related projects

  • `protoc` is the historical compiler that Buf augments for day-to-day Protobuf workflows.
  • The Buf Schema Registry is the hosted registry used for modules, documentation, remote plugins, generated SDKs, and schema checks.
  • ConnectRPC, Protobuf-ES, and Protovalidate are related Buf ecosystem projects named by the official README.

Sicherheitslage

Risikostufe: grün

narrow executable package without higher-risk signals.

Risikoklassifikator

grün Risiko · niedrig Konfidenz · appliance

Warum

  • narrow executable package without higher-risk signals

Signale

  • metadata:no-higher-risk-signals

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
~/.netrc

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
bufcliglobales Executable
protoc-gen-buf-breakingcliglobales Executable
protoc-gen-buf-lintcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version1.72.0
Manager aktualisiert2026-07-17
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv1.72.0

https://github.com/bufbuild/buf

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:buf
Version1.72.0
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/buf
Homepagehttps://buf.build
Repositoryhttps://github.com/bufbuild/buf
Upstream-Dokumentationhttps://buf.build/docs/cli
LizenzApache-2.0
Quellarchivhttps://github.com/bufbuild/buf/archive/refs/tags/v1.72.0.tar.gz
Zuletzt aktualisiert2026-07-17T20:53:06Z
Pulseupdated
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namebuf
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

buf

nix profile install nixpkgs#buf
  • normalized package name match
  • Abgeglichen nach: Buf
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/bu/buf/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

buf 1.59.0-r6

CLI to work with Protocol Buffers

https://buf.build/

sudo apk add buf
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: buf
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Buf
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: buf from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

buf-bash-completion 1.59.0-r6

Bash completions for buf

https://buf.build/

sudo apk add buf-bash-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: buf
  • normalized package name match
  • Abgeglichen nach: Buf
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: buf-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

buf-fish-completion 1.59.0-r6

Fish completions for buf

https://buf.build/

sudo apk add buf-fish-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: buf
  • normalized package name match
  • Abgeglichen nach: Buf
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: buf-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

buf-protoc-plugins 1.59.0-r6

CLI to work with Protocol Buffers (protoc plugins)

https://buf.build/

sudo apk add buf-protoc-plugins
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: buf
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Buf
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: buf-protoc-plugins from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

buf-zsh-completion 1.59.0-r6

Zsh completions for buf

https://buf.build/

sudo apk add buf-zsh-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: buf
  • normalized package name match
  • Abgeglichen nach: Buf
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: buf-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
pacman95%

buf 1.70.0-1

A tool for working with Protocol Buffers

https://buf.build

sudo pacman -S buf
  • License: Apache-2.0
  • Architecture: x86_64
  • 1 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Buf
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: buf from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

buf

sudo port install buf
  • normalized package name match
  • Abgeglichen nach: Buf
MacPorts ports tree · api.github.com · MacPorts ports tree: devel/buf/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Scoop95%

main/buf

scoop install main/buf
  • normalized package name match
  • Abgeglichen nach: Buf
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/buf.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
winget95%

bufbuild.buf

winget install --id bufbuild.buf -e
  • normalized package name match
  • Abgeglichen nach: Buf
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: bufbuild.buf from https://cdn.winget.microsoft.com/cache/source.msix

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated agent safety answer
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment