Automic VaultAutomic Vault

brew

kubeconform mit Homebrew, apk, MacPorts, Nix, pacman, zypper, scoop, winget installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für kubeconform in AI-Agent-Workflows.

Agent-Sicherheit

Antwort zur Agent-Sicherheit

kubeconform validates Kubernetes manifests and may read deployment configuration.

Credential-Zugriff

Reads manifest files that may include secret references or generated values.

Änderungen an Remote-Zustand

Validation is local and does not mutate clusters.

Publish-/Artefakt-Risiko

Can validate deployable artifacts before cluster application.

Empfohlene Kontrolle

Gate only when scanning secret-bearing files or feeding apply pipelines.

Hinweise für Agent-Nutzung

Allow local validation; require approval before passing output into deployment commands.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install kubeconform

local Homebrew formula metadata

MacPortsverifiziert · 94%
sudo port install kubeconform

MacPorts ports tree · sysutils/kubeconform/Portfile · Quelle: api.github.com

Linux

Alpine Linux apkverifiziert · 92%
sudo apk add kubeconform

Alpine Linux edge package indexes · kubeconform · Quelle: dl-cdn.alpinelinux.org

Nixverifiziert · 92%
nix profile install nixpkgs#kubeconform

nixpkgs package indexes · pkgs/by-name/ku/kubeconform/package.nix · Quelle: api.github.com

Arch Linux pacmanverifiziert · 92%
sudo pacman -S kubeconform

Arch Linux sync databases · kubeconform · Quelle: geo.mirror.pkgbuild.com

openSUSE zypperverifiziert · 92%
sudo zypper install kubeconform

openSUSE Tumbleweed package metadata · kubeconform · Quelle: download.opensuse.org

Windows

Scoopverifiziert · 92%
scoop install main/kubeconform

Scoop official bucket manifest trees · bucket/kubeconform.json · Quelle: api.github.com

Windows Package Managerverifiziert · 92%
winget install --id YannHamon.kubeconform -e

Windows Package Manager source index · YannHamon.kubeconform · Quelle: cdn.winget.microsoft.com

Überblick

Paketzusammenfassung

FAST Kubernetes manifests validator, with support for Custom Resources!

Befehle und Aliase

  • kubeconform

Verlauf

Projektgeschichte und Nutzung

Kubeconform is a Kubernetes manifest validator that grew out of the Kubeval lineage: its own documentation says it is inspired by, contains code from, and is designed to stay close to Kubeval while adding higher-throughput validation, configurable schema locations, CRD support, offline validation, and a schema registry fork for recent Kubernetes versions.

Projektgeschichte

The GitHub repository was created on 2020-05-30. The public documentation feed dates the overview, installation, usage, CRD support, JSON Schema conversion, GitHub Action, and Go-module documentation pages to 2021-07-02, which matches the period when the project presented itself as a standalone replacement for common Kubeval workflows.

Kubeconform kept the Unix-style single-binary validator shape that made Kubeval popular in CI, but its distinguishing evolution was schema flexibility: users can validate against Kubernetes versions, local or remote schema locations, and converted CRD schemas rather than only core Kubernetes resources.

Adoptionsgeschichte

Adoption has been strongest in CI/CD and GitOps-adjacent workflows where teams want to fail manifest changes before applying them to a cluster. The tool's package-manager footprint across Homebrew, Linux distributions, Windows package managers, and Nix reflects a cross-platform CLI audience rather than a cluster-installed controller audience.

The repository metadata observed on 2026-07-01 showed more than 3000 GitHub stars, making it one of the better-known third-party Kubernetes manifest validators outside kubectl itself.

Wie es verwendet wird

Typical use is to pass files, directories, or stdin to `kubeconform`, optionally choosing output such as text, JSON, JUnit, or TAP and enabling summary output for CI logs. For custom resources, users point `-schema-location` at local or HTTP(S) JSON schemas, or convert CRDs to JSON Schema with the project-provided conversion tooling.

The package matters in validation pipelines because it gives maintainers a fast, scriptable check for Kubernetes resource structure without needing live cluster access.

Warum Paket-Nerds sich dafür interessieren

For package-manager users, Kubeconform is the kind of small Go CLI that fits neatly into `brew install`, CI images, pre-commit hooks, and reproducible Nix shells. Its significance is not a broad runtime platform but a sharp replacement-class tool for a once-common Kubernetes validation gap.

Zeitleiste

  • 2020-05-30: GitHub repository created.
  • 2021-07-02: Documentation pages published for overview, installation, usage, CRD support, JSON Schema conversion, GitHub Action usage, and Go-module usage.
  • 2024-07-30: Release v0.6.7 published.
  • 2025-05-12: Release v0.7.0 published.
  • 2026-06-04: Release v0.8.0 published.

Related projects

  • Kubeval is the direct predecessor named by the Kubeconform documentation. The kubernetes-json-schema registry is part of the validation ecosystem because Kubeconform uses JSON schemas for Kubernetes resources and supports schema-location overrides for CRDs.

Sicherheitslage

Risikostufe: orange

infrastructure mutation or orchestration signal.

Risikoklassifikator

orange Risiko · mittel Konfidenz · infrastructure

Warum

  • infrastructure mutation or orchestration signal

Signale

  • text:kubernetes

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
kubeconformcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version0.8.0
Manager aktualisiert2026-06-04
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv0.8.0

https://github.com/yannh/kubeconform

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:kubeconform
Version0.8.0
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/kubeconform
Homepagehttps://github.com/yannh/kubeconform
Repositoryhttps://github.com/yannh/kubeconform
Upstream-Dokumentationhttps://github.com/yannh/kubeconform#readme
LizenzApache-2.0
Quellarchivhttps://github.com/yannh/kubeconform/archive/refs/tags/v0.8.0.tar.gz
Zuletzt aktualisiert2026-06-04T22:29:59Z
Pulseupdated
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namekubeconform
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

kubeconform

nix profile install nixpkgs#kubeconform
  • normalized package name match
  • Abgeglichen nach: Kubeconform
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ku/kubeconform/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

kubeconform 0.7.0-r8

A FAST Kubernetes manifests validator, with support for Custom Resources!

https://github.com/yannh/kubeconform

sudo apk add kubeconform
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: kubeconform
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Kubeconform
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: kubeconform from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
pacman95%

kubeconform 0.7.0-2

FAST Kubernetes manifests validator, with support for Custom Resources!

https://github.com/yannh/kubeconform

sudo pacman -S kubeconform
  • License: Apache
  • Architecture: x86_64
  • 1 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Kubeconform
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: kubeconform from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
zypper95%

kubeconform 0.8.0-1.1

A fast Kubernetes manifests validator, with support for custom resources

https://github.com/yannh/kubeconform/

sudo zypper install kubeconform
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: kubeconform
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Kubeconform
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: kubeconform from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
MacPorts95%

kubeconform

sudo port install kubeconform
  • normalized package name match
  • Abgeglichen nach: Kubeconform
MacPorts ports tree · api.github.com · MacPorts ports tree: sysutils/kubeconform/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Scoop95%

main/kubeconform

scoop install main/kubeconform
  • normalized package name match
  • Abgeglichen nach: Kubeconform
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/kubeconform.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
winget95%

YannHamon.kubeconform

winget install --id YannHamon.kubeconform -e
  • normalized package name match
  • Abgeglichen nach: Kubeconform
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: YannHamon.kubeconform from https://cdn.winget.microsoft.com/cache/source.msix

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated agent safety answer
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment