macOS
brew install gh
local Homebrew formula metadata
sudo port install gh
MacPorts ports tree · devel/gh/Portfile · Quelle: api.github.com
brew-Paketinformationen
Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für gh in AI-Agent-Workflows.
Installation
sudo av install brew:gh
brew install gh
local Homebrew formula metadata
sudo port install gh
MacPorts ports tree · devel/gh/Portfile · Quelle: api.github.com
sudo apt install gh
Debian stable package indexes · gh · Quelle: deb.debian.org
sudo dnf install gh
Fedora Rawhide package metadata · gh · Quelle: dl.fedoraproject.org
nix profile install nixpkgs#gh
nixpkgs package indexes · pkgs/by-name/gh/gh/package.nix · Quelle: api.github.com
sudo zypper install gh
openSUSE Tumbleweed package metadata · gh · Quelle: download.opensuse.org
choco install gh
Chocolatey community package catalog · gh · Quelle: community.chocolatey.org
scoop install main/gh
Scoop official bucket manifest trees · bucket/gh.json · Quelle: api.github.com
winget install --id GitHub.cli -e
Windows Package Manager source index · GitHub.cli · Quelle: cdn.winget.microsoft.com
Überblick
Automic Vault veröffentlicht paketspezifische Installationswege, Executable-Fakten und Sicherheitsmetadaten für gh aus lokalen Paketdaten.
GitHub command-line tool
Radioisotope
`gh` stores its secrets in the Keychain but they can be trivially obtained: 1. `gh auth token` 2. `security find-generic-password -s 'gh:github.com' -w` Our isotope prevents anything but `gh` itself from accessing its secrets by gating `gh auth token` behind a Automic Vault human-approval prompt and gating attempts to use the macOS `security` tool behind a keychain approval prompt.
blue Risiko · high Konfidenz · tool
Lokaler README-Auszug
This repository is the Automic Vault fork of GitHub CLI.
Automic Vault is a macOS-first secret and execution control system that keeps sensitive credentials behind explicit human approval in the Automic Vault GUI app instead of exposing them directly to terminal tools.
This fork currently adds the following behavior on top of upstream cli/cli:
gh binary instead of/usr/bin/security, so Keychain trust is attached to this app binary.
print stored tokens in plain text. This covers gh auth token, gh auth status --show-token, gh config get -h HOST oauth_token, and the hidden gh auth git-credential get helper.
secrets from the factory-release to our isotope.
gh installs, including plaintexthosts.yml tokens and Keychain ACLs that allow /usr/bin/security to read gh secrets.
Quelle: data/isotopes/gh-cli/README.md
https://github.com/automic-vault/gh-cli/releases/tag/v2.92.0
Approval Gates
The local approval-gate seed includes 7 rules for gh. Covered entrypoints: gh. Severity labels: critical, high. Coverage: partial, geprüft 2026-05-21.
Executables
| Befehl | Art | Sichtbarkeit | Hinweis |
|---|---|---|---|
gh | cli | global executable |
Aktualität
Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.
Installationsmetadaten
| Paketschlüssel | brew:gh |
|---|---|
| Version | 2.92.0 |
| Paketmanager | Homebrew |
| Paketmanager-Seite | https://formulae.brew.sh/formula/gh |
| Homepage | https://cli.github.com/ |
| Repository | https://github.com/cli/cli |
| Upstream-Dokumentation | https://cli.github.com/ |
| Lizenz | MIT |
| Quellarchiv | https://github.com/cli/cli/archive/refs/tags/v2.92.0.tar.gz |
| Aktualisiert | 2026-05-21T14:58:05+02:00 |
| Pulse | updated |
| Build-Abhängigkeiten | go |
| Bottle | verfügbar (arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | nicht definiert |
| Dienst | keiner deklariert |
Quellspur
Diese Seite wird von scripts/generate-pkg-pages.py geschrieben. Deployments verweigern die Veröffentlichung, wenn www/pkg/ gegenüber lokalen Paketdaten veraltet ist.