Automic VaultAutomic Vault

brew

kics mit Homebrew, Nix installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für kics in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install kics

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#kics

nixpkgs package indexes · pkgs/by-name/ki/kics/package.nix · Quelle: api.github.com

Überblick

Paketzusammenfassung

Detect vulnerabilities, compliance issues, and misconfigurations

Verlauf

Projektgeschichte und Nutzung

KICS, short for Keeping Infrastructure as Code Secure, is Checkmarx's open-source scanner for infrastructure-as-code vulnerabilities, compliance problems, and misconfigurations.

Projektgeschichte

Checkmarx created the public KICS repository in 2020 and published v1.0.0 on 2020-11-30. The project arrived during the wider shift from manually provisioned infrastructure toward Terraform, Kubernetes, Helm, CloudFormation, Docker Compose, and other declarative infrastructure formats, where configuration mistakes can become security defects.

Adoptionsgeschichte

KICS adoption is tied to CI and DevSecOps workflows. Official materials document a GitHub Action, a Docker image, a standalone CLI, and broad platform coverage across Terraform, Kubernetes, Docker, CloudFormation, Ansible, Helm, OpenAPI, gRPC, Azure Resource Manager, Pulumi, Serverless Framework, OpenTofu, Bicep, and more.

Wie es verwendet wird

Users run `kics scan` or CI integrations against infrastructure repositories to catch risky cloud and orchestration settings before deployment. Query packs and documentation make it useful both for one-off audits and for policy-style checks in build pipelines.

Warum Paket-Nerds sich dafür interessieren

KICS is significant because it packages a large IaC security rule corpus as a Go CLI that can be installed by package managers, run in containers, or embedded in GitHub workflows. It sits in the same package-nerd mental shelf as Terraform linters, policy engines, and static analyzers, but focuses on concrete misconfiguration checks across many IaC syntaxes.

Zeitleiste

  • 2020: Checkmarx/kics repository created on GitHub.
  • 2020: v1.0.0 release published on 2020-11-30.
  • 2021: The 1.1 and 1.2 release series expanded after the initial 1.0 release.
  • 2025: The 2.1 release series was active through repeated published releases.
  • 2026: v2.1.20 release published on 2026-03-03.

Related projects

  • Official KICS materials include a companion Checkmarx/kics-github-action repository for GitHub Actions integration and documentation for scanning common IaC ecosystems such as Terraform, Kubernetes, Helm, CloudFormation, and Docker Compose.

Sicherheitslage

Risikostufe: grün

narrow executable package without higher-risk signals.

Risikoklassifikator

grün Risiko · niedrig Konfidenz · appliance

Warum

  • narrow executable package without higher-risk signals

Signale

  • metadata:no-higher-risk-signals

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
kics.config

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
kicscliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version2.1.20
Manager aktualisiert
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv2.1.20

https://github.com/Checkmarx/kics

  • InfoNo package-manager update timestamp was available.niedrig Konfidenz

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:kics
Version2.1.20
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/kics
Homepagehttps://kics.io/
Repositoryhttps://github.com/Checkmarx/kics
Upstream-Dokumentationhttps://docs.kics.io/
LizenzApache-2.0
Quellarchivhttps://github.com/Checkmarx/kics/archive/refs/tags/v2.1.20.tar.gz
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert
EinschränkungenKICS queries are placed under $HOMEBREW_PREFIX/opt/kics/share/kics/assets/queries To use KICS default queries add KICS_QUERIES_PATH env to your ~/.zshrc or ~/.zprofile: "echo 'export KICS_QUERIES_PATH=$HOMEBREW_PREFIX/opt/kics/share/kics/assets/queries' >> ~/.zshrc" usage of CLI flag --queries-path takes precedence.

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namekics
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

kics

nix profile install nixpkgs#kics
  • normalized package name match
  • Abgeglichen nach: Kics
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ki/kics/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment