Automic VaultAutomic Vault

brew

depsguard mit Homebrew, winget installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für depsguard in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install depsguard

local Homebrew formula metadata

Windows

Windows Package Managerverifiziert · 92%
winget install --id Arnica.DepsGuard -e

Windows Package Manager source index · Arnica.DepsGuard · Quelle: cdn.winget.microsoft.com

Überblick

Paketzusammenfassung

Harden package manager configs against supply chain attacks

Befehle und Aliase

  • depsguard

Verlauf

Projektgeschichte und Nutzung

DepsGuard is a young supply-chain hardening CLI that scans package-manager and dependency-bot configuration files for safer defaults. It focuses on release cooldowns, install-script risk, provenance-related settings, and other package-manager knobs that reduce exposure to dependency confusion and malicious fresh releases.

Projektgeschichte

The official arnica/depsguard repository was created in 2026. The README presents DepsGuard as a single static Rust binary with no third-party Rust crate dependencies, built to scan npm, pnpm, yarn, bun, uv, pip, poetry, aube, Renovate, and Dependabot configs.

The project website and README emphasize interactive scanning and fixing: DepsGuard reads known config locations, compares settings to recommended supply-chain defaults, previews diffs, writes backups, and can restore changes.

Adoptionsgeschichte

Because DepsGuard is new, its official adoption record is still mostly packaging and distribution: prebuilt GitHub release binaries, Homebrew core, APT setup, crates.io, WinGet, and Scoop. That packaging breadth suggests the tool is meant for developer workstations as much as CI hardening checks.

Wie es verwendet wird

Users can run `depsguard` for an interactive TUI, `depsguard scan` for read-only reporting, or `depsguard restore` to roll back from backups. The tool searches user-level and repo-level package-manager configuration files, including `.github/dependabot.yml` and Renovate files, and only edits files after user approval.

Warum Paket-Nerds sich dafür interessieren

For package nerds, DepsGuard is notable because it packages a cross-ecosystem security checklist into one binary. Its config table is a snapshot of how many different package managers have grown similar but incompatible concepts for cooldowns, script blocking, trust policy, and registry hardening.

Zeitleiste

  • 2026: Official arnica/depsguard repository created.
  • 2026: README documents Homebrew core, APT, crates.io, WinGet, and Scoop installation channels.
  • 2026: Website describes DepsGuard as a one-command scanner and fixer for package-manager security settings.

Related projects

  • Related configuration surfaces include npm, pnpm, Yarn, Bun, uv, pip, Poetry, aube, Renovate, and Dependabot.

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für depsguard wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Linux
~/.npmrc~/.config/pnpm/rc~/.config/pnpm/config.yaml~/.yarnrc.yml$XDG_CONFIG_HOME/.bunfig.toml~/.config/uv/uv.toml~/.config/pip/pip.conf~/.config/pypoetry/config.toml
macOS
~/.npmrc~/Library/Preferences/pnpm/rc~/Library/Preferences/pnpm/config.yaml~/.yarnrc.yml~/.bunfig.toml~/.config/uv/uv.toml~/Library/Application Support/pip/pip.conf~/Library/Application Support/pypoetry/config.toml
Windows
%LOCALAPPDATA%\pnpm\config\rc%LOCALAPPDATA%\pnpm\config\config.yaml%APPDATA%\uv\uv.toml%APPDATA%\pip\pip.ini%APPDATA%\pypoetry\config.toml

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
depsguardcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version0.1.40
Manager aktualisiert2026-06-30
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv0.1.40

https://github.com/arnica/depsguard

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:depsguard
Version0.1.40
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/depsguard
Homepagehttps://depsguard.com
Repositoryhttps://github.com/arnica/depsguard
Upstream-Dokumentationhttps://depsguard.com/
LizenzMIT
Quellarchivhttps://github.com/arnica/depsguard/archive/refs/tags/v0.1.40.tar.gz
Zuletzt aktualisiert2026-06-30T21:29:11Z
Pulseupdated
Build-Abhängigkeitenrust
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namedepsguard
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

winget95%

Arnica.DepsGuard

winget install --id Arnica.DepsGuard -e
  • normalized package name match
  • Abgeglichen nach: Depsguard
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: Arnica.DepsGuard from https://cdn.winget.microsoft.com/cache/source.msix

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment