Automic VaultAutomic Vault

brew

goshs mit Homebrew, apk, Nix, zypper, scoop, winget installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für goshs in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install goshs

local Homebrew formula metadata

Linux

Alpine Linux apkverifiziert · 92%
sudo apk add goshs

Alpine Linux edge package indexes · goshs · Quelle: dl-cdn.alpinelinux.org

Nixverifiziert · 92%
nix profile install nixpkgs#goshs

nixpkgs package indexes · pkgs/by-name/go/goshs/package.nix · Quelle: api.github.com

openSUSE zypperverifiziert · 92%
sudo zypper install goshs

openSUSE Tumbleweed package metadata · goshs · Quelle: download.opensuse.org

Windows

Scoopverifiziert · 92%
scoop install extras/goshs

Scoop official bucket manifest trees · bucket/goshs.json · Quelle: api.github.com

Windows Package Managerverifiziert · 92%
winget install --id GoshsLabs.Goshs -e

Windows Package Manager source index · GoshsLabs.Goshs · Quelle: cdn.winget.microsoft.com

Überblick

Paketzusammenfassung

Simple, yet feature-rich web server written in Go

Verlauf

Projektgeschichte und Nutzung

goshs is a Go single-binary file server aimed at situations where Python's SimpleHTTPServer style sharing is too limited. Its project materials frame it for red-team, pentest, CTF, and quick file-transfer workflows, combining HTTP/S with protocols and security-oriented helpers such as WebDAV, FTP/SFTP, SMB, LDAP/S, DNS and SMTP callbacks, NTLM hash capture, share links, authentication, and a terminal dashboard.

Projektgeschichte

The project grew from the familiar local-file-server niche into a penetration-testing utility. The README explicitly credits updog as inspiration, which places goshs in the lineage of small engagement-friendly servers that trade web-server configuration for a single command.

The 2.x documentation and release notes show a broadening scope: v2.0.0 emphasized SMB, DNS, SMTP, redirects, ACLs, and share links; later 2.1 releases added a TUI, self-destruct timers, payload templating, range downloads, TFTP, and reverse-shell payload generation. The project also moved to the goshs-labs GitHub organization during the v2.1.0 line.

Adoptionsgeschichte

goshs is packaged for Homebrew and is also advertised by the project for Kali/Parrot, Arch AUR, BlackArch, Alpine, Snap, Fedora/RHEL COPR, openSUSE, Nix/NixOS, Scoop, winget, Chocolatey, Docker, Go install, and GitHub Releases. That spread matches a tool meant to be dropped quickly onto operator workstations, lab VMs, and disposable engagement environments.

Wie es verwendet wird

Typical usage starts a web server for the working directory, then enables only the pieces needed for a task: HTTPS and basic auth for protected sharing, SMB or LDAP for credential and hash capture, DNS/SMTP callbacks for interaction tracking, WebDAV/FTP/SFTP/TFTP for protocol-specific transfer, TTL for temporary servers, or the TUI for SSH sessions without a browser.

Warum Paket-Nerds sich dafür interessieren

Package maintainers care about goshs because it is a feature-dense single binary with a Go module path, release artifacts, shell completions, container images, and many optional behaviors hidden behind flags rather than separate services. It also carries security-sensitive behavior, so packaging and upgrade cadence matter more than for a plain static file server.

Zeitleiste

  • 2025: Security advisory GHSA-rwj2-w85g-5cmm documents a command-execution exposure tested against goshs 1.0.4 and notes the command feature was introduced in 0.3.4.
  • 2026-05: v2.1.0 release notes record the move to github.com/goshs-labs/goshs and several security fixes.
  • 2026-06: 2.1 releases add a TUI, TTL shutdown, payload templating, resumable downloads, TFTP, reverse-shell payload generation, and packaging/CI updates.

Related projects

  • updog is credited by goshs as project inspiration.
  • Python's SimpleHTTPServer/http.server is the baseline goshs positions itself beyond.
  • ConPtyShell appears in goshs release notes as an on-demand helper for Windows shell upgrades.

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für goshs wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
.goshs

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
goshscliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version2.1.4
Manager aktualisiert2026-07-03
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv2.1.4

https://github.com/goshs-labs/goshs

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:goshs
Version2.1.4
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/goshs
Homepagehttps://goshs.de
Repositoryhttps://github.com/goshs-labs/goshs
Upstream-Dokumentationhttps://docs.goshs.de/
LizenzMIT
Quellarchivhttps://github.com/goshs-labs/goshs/archive/refs/tags/v2.1.4.tar.gz
Zuletzt aktualisiert2026-07-03T10:38:16Z
Pulseupdated
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namegoshs
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

goshs

nix profile install nixpkgs#goshs
  • normalized package name match
  • Abgeglichen nach: Goshs
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/go/goshs/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

goshs 2.1.0-r0

A SimpleHTTPServer written in Go, enhanced with features and with a nice design.

https://goshs.de

sudo apk add goshs
  • License: MIT
  • Architecture: x86_64
  • Source Package: goshs
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Goshs
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: goshs from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

goshs-doc 2.1.0-r0

A SimpleHTTPServer written in Go, enhanced with features and with a nice design. (documentation)

https://goshs.de

sudo apk add goshs-doc
  • License: MIT
  • Architecture: x86_64
  • Source Package: goshs
  • normalized package name match
  • Abgeglichen nach: Goshs
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: goshs-doc from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
zypper95%

goshs 2.1.0-1.1

A simple HTTP server

https://goshs.de/

sudo zypper install goshs
  • License: MIT
  • Category: Productivity/Networking/Web/Servers
  • Architecture: x86_64
  • Source Package: goshs
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Goshs
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: goshs from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
Scoop95%

extras/goshs

scoop install extras/goshs
  • normalized package name match
  • Abgeglichen nach: Goshs
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/goshs.json from https://api.github.com/repos/ScoopInstaller/Extras/git/trees/master?recursive=1
winget95%

GoshsLabs.Goshs

winget install --id GoshsLabs.Goshs -e
  • normalized package name match
  • Abgeglichen nach: Goshs
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: GoshsLabs.Goshs from https://cdn.winget.microsoft.com/cache/source.msix
winget95%

PatrickHener.Goshs

winget install --id PatrickHener.Goshs -e
  • normalized package name match
  • Abgeglichen nach: Goshs
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: PatrickHener.Goshs from https://cdn.winget.microsoft.com/cache/source.msix

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment