macOS
brew install copalocal Homebrew formula metadata
brew
Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für copa in AI-Agent-Workflows.
Installation
brew install copalocal Homebrew formula metadata
Überblick
Tool to directly patch container images given the vulnerability scanning results
Verlauf
Copa is the CLI for Project Copacetic, a Go and BuildKit-based tool for patching vulnerable container images without doing a full image rebuild.
The official repository was created in January 2023 and released v0.1.0 the next day. The project developed around direct vulnerability patching: adding a patch layer to existing images based on scanner output rather than forcing users to rebuild from source.
The official site identifies Copacetic as a CNCF Sandbox project and lists ecosystem adoption by Azure Container Registry Continuous Patching, Kubescape, Devtron, and Helmper. It also documents featured talks at KubeCon North America 2024 and OpenSSF SOSS Fusion Conference 2024.
Copa is commonly used in CI/CD and image-maintenance workflows. It consumes vulnerability scanning results, has built-in Trivy support, supports third-party scanners, and patches images across multiple Linux package-manager families and platforms.
For package and container maintainers, Copa sits at the boundary between OS package updates and container distribution. It is interesting because it turns package-manager-level remediation into a post-build image operation, which can reduce rebuild churn for downstream image consumers.
Sicherheitslage
infrastructure mutation or orchestration signal.
orange Risiko · mittel Konfidenz · infrastructure
Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.
Executables
| Befehl | Art | Sichtbarkeit | Hinweis |
|---|---|---|---|
copa | cli | globales Executable |
Aktualität
Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.
https://github.com/project-copacetic/copacetic
Installationsmetadaten
| Paketschlüssel | brew:copa |
|---|---|
| Version | 0.14.2 |
| Paketmanager | Homebrew |
| Paketmanager-Seite | https://formulae.brew.sh/formula/copa |
| Homepage | https://project-copacetic.github.io/copacetic/ |
| Repository | https://github.com/project-copacetic/copacetic |
| Upstream-Dokumentation | https://project-copacetic.github.io/copacetic |
| Lizenz | Apache-2.0 |
| Quellarchiv | https://github.com/project-copacetic/copacetic/archive/refs/tags/v0.14.2.tar.gz |
| Zuletzt aktualisiert | 2026-07-03T03:35:43Z |
| Pulse | updated |
| Build-Abhängigkeiten | go |
| Bottle | verfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | nicht definiert |
| Dienst | keiner deklariert |
Registry-Fakten
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | copa |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
Quellspur
Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.
View the package source record on GitHub.