Automic VaultAutomic Vault

brew

legitify mit Homebrew, Nix installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für legitify in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install legitify

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#legitify

nixpkgs package indexes · pkgs/by-name/le/legitify/package.nix · Quelle: api.github.com

Überblick

Paketzusammenfassung

Tool to detect/remediate misconfig and security risks of GitHub/GitLab assets

Befehle und Aliase

  • legitify

Verlauf

Projektgeschichte und Nutzung

Legitify is Legit Security's open-source CLI for finding and helping remediate security, compliance, and misconfiguration risks across GitHub and GitLab assets.

Projektgeschichte

Legit Security announced Legitify on 2022-10-05 as an open-source GitHub configuration scanner for security, DevOps, and developer teams. The repository and project site later described the scope as source-code-management posture across GitHub and GitLab assets, with built-in policies and remediation-oriented output.

Adoptionsgeschichte

The project was packaged as a standalone CLI, GitHub Action, Homebrew formula, Nix package, and GitHub CLI extension. That mix made it fit both one-off audits from a workstation and scheduled checks in CI for organizations managing many repositories, members, teams, runners, branch protections, and tokens.

Wie es verwendet wird

Typical usage is to authenticate to GitHub or GitLab, run `legitify analyze`, and review policy findings against repositories, organizations, runners, webhooks, actions, branch protection, and other SCM resources. Its Homebrew packaging matters because security teams can hand developers a familiar install path instead of a vendor-only SaaS workflow.

Warum Paket-Nerds sich dafür interessieren

Legitify is a package-nerd example of application-security posture management ideas escaping into a plain CLI. It packages policy checks and remediation hints as a tool that can live in local shells, CI jobs, and GitHub Actions, adjacent to linters and secret scanners.

Zeitleiste

  • 2022-07-26: The GitHub issue tracker showed early public project activity.
  • 2022-10-05: Legit Security published the introductory Legitify announcement.
  • 2023-01-19: Public issues tracked expansion into third-party application policies.
  • 2023-02-06: Public issues tracked auto-remediation work.

Related projects

  • Related projects include the `gh-legitify` GitHub CLI extension, the Legitify GitHub Action, OpenSSF Scorecard, GitHub Advanced Security configuration checks, GitLab security scanners, and policy-as-code tools used for SCM governance.

Sicherheitslage

Risikostufe: blue

broad file, network, media, or database tool signal.

Risikoklassifikator

blue Risiko · mittel Konfidenz · tool

Warum

  • broad file, network, media, or database tool signal

Signale

  • text:media

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
legitifycliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version1.0.11
Manager aktualisiert2026-05-19
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv1.0.11

https://github.com/Legit-Labs/legitify

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:legitify
Version1.0.11
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/legitify
Homepagehttps://legitify.dev/
Repositoryhttps://github.com/Legit-Labs/legitify
Upstream-Dokumentationhttps://legitify.dev/
LizenzApache-2.0
Quellarchivhttps://github.com/Legit-Labs/legitify/archive/refs/tags/v1.0.11.tar.gz
Zuletzt aktualisiert2026-05-19T13:03:29-04:00
Pulseupdated
Build-Abhängigkeitengo@1.24
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namelegitify
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedyes
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

legitify

nix profile install nixpkgs#legitify
  • normalized package name match
  • Abgeglichen nach: Legitify
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/le/legitify/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment