Automic VaultAutomic Vault

brew / Approval Gates

mkcert mit Homebrew, apk, chocolatey, apt, dnf, MacPorts, Nix, pacman, zypper, scoop, winget installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für mkcert in AI-Agent-Workflows.

Agent-Sicherheit

Antwort zur Agent-Sicherheit

mkcert creates local certificate authorities and development certificates.

Credential-Zugriff

Touches local trust stores and private key material.

Änderungen an Remote-Zustand

Primarily mutates local trust state, not remote systems.

Publish-/Artefakt-Risiko

Can create certificates that influence development service trust.

Empfohlene Kontrolle

Gate CA installation and private-key handling.

Hinweise für Agent-Nutzung

Allow certificate inspection; require approval before installing trust roots or writing private keys.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install mkcert

local Homebrew formula metadata

MacPortsverifiziert · 94%
sudo port install mkcert

MacPorts ports tree · security/mkcert/Portfile · Quelle: api.github.com

Linux

Alpine Linux apkverifiziert · 92%
sudo apk add mkcert

Alpine Linux edge package indexes · mkcert · Quelle: dl-cdn.alpinelinux.org

Debian aptverifiziert · 92%
sudo apt install mkcert

Debian stable package indexes · mkcert · Quelle: deb.debian.org

Fedora dnfverifiziert · 92%
sudo dnf install mkcert

Fedora Rawhide package metadata · mkcert · Quelle: dl.fedoraproject.org

Nixverifiziert · 92%
nix profile install nixpkgs#mkcert

nixpkgs package indexes · pkgs/by-name/mk/mkcert/package.nix · Quelle: api.github.com

Arch Linux pacmanverifiziert · 92%
sudo pacman -S mkcert

Arch Linux sync databases · mkcert · Quelle: geo.mirror.pkgbuild.com

openSUSE zypperverifiziert · 92%
sudo zypper install mkcert

openSUSE Tumbleweed package metadata · mkcert · Quelle: download.opensuse.org

Windows

Chocolateyverifiziert · 92%
choco install mkcert

Chocolatey community package catalog · mkcert · Quelle: community.chocolatey.org

Scoopverifiziert · 92%
scoop install extras/mkcert

Scoop official bucket manifest trees · bucket/mkcert.json · Quelle: api.github.com

Windows Package Managerverifiziert · 92%
winget install --id FiloSottile.mkcert -e

Windows Package Manager source index · FiloSottile.mkcert · Quelle: cdn.winget.microsoft.com

Überblick

Paketzusammenfassung

Simple tool to make locally trusted development certificates

Befehle und Aliase

  • mkcert

Verlauf

Projektgeschichte und Nutzung

mkcert is Filippo Valsorda's small Go tool for locally trusted development certificates. It appeared in the 2018 developer conversation around localhost HTTPS and was explained by Valsorda in a January 2019 post: deployment certificates had become easier through ACME and Let's Encrypt, but development still fell back to HTTP because localhost and private development names cannot use ordinary public CA validation.

Projektgeschichte

The tool's core idea is deliberately narrow. Instead of asking each developer to memorize OpenSSL invocations or manage browser trust stores by hand, mkcert creates a local certificate authority, installs it into the system and Firefox/NSS trust stores where supported, and issues certificates for local hostnames, IP addresses, and wildcards. The upstream README also warns that the generated root CA private key can intercept secure requests from the machine, which is why mkcert is framed as a local development tool rather than production CA infrastructure.

Wie es verwendet wird

mkcert became a common package-manager utility because it solves a recurring web-development pain point with one command and no project-specific configuration. Homebrew, MacPorts, Linux packages, and prebuilt binaries cover the usual developer platforms, while the README leaves web-server configuration to the user after the certificate and key are generated.

Approval Gates

Metadaten für menschliche Prüfung riskanter Befehle

Der lokale Approval-Gate-Seed enthält 4 Regeln für mkcert. Abgedeckte Einstiegspunkte: mkcert. Schweregrade: kritisch, hoch. Abdeckung: partial, geprüft am 2026-05-21.

Beispiele für gated Aktionen

  • Install the local CA into system or browser trust stores.
  • Remove the local CA from trust stores.
  • Generate local certificates and private keys.
  • Write certificate or key files to caller-specified paths.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Credential files

Credential-bearing paths to review before unattended agent runs.

macOS
~/Library/Application Support/mkcert/rootCA-key.pem

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
mkcertcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version1.4.4
Manager aktualisiert
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv1.4.4

https://github.com/FiloSottile/mkcert

  • InfoNo package-manager update timestamp was available.niedrig Konfidenz

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:mkcert
Version1.4.4
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/mkcert
Homepagehttps://github.com/FiloSottile/mkcert
Repositoryhttps://github.com/FiloSottile/mkcert
Upstream-Dokumentationhttps://github.com/FiloSottile/mkcert#readme
LizenzBSD-3-Clause
Quellarchivhttps://github.com/FiloSottile/mkcert/archive/refs/tags/v1.4.4.tar.gz
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_big_sur, arm64_linux, arm64_monterey, arm64_sequoia, arm64_sonoma, arm64_tahoe, arm64_ventura, big_sur, catalina, monterey, sonoma, ventura, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namemkcert
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Debian apt95%

mkcert 1.4.4-1+b18

Simple zero-config tool to make locally trusted certificates

https://github.com/FiloSottile/mkcert

sudo apt install mkcert
  • Section: utils
  • Architecture: amd64
  • Source Package: mkcert
  • 1 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Mkcert
Debian stable package indexes · deb.debian.org · Debian stable package indexes: mkcert from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Nix95%

mkcert

nix profile install nixpkgs#mkcert
  • normalized package name match
  • Abgeglichen nach: Mkcert
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/mk/mkcert/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Ubuntu apt95%

mkcert 1.4.4-1ubuntu2

Simple zero-config tool to make locally trusted certificates

https://github.com/FiloSottile/mkcert

sudo apt install mkcert
  • Section: universe/utils
  • Architecture: amd64
  • 1 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Mkcert
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: mkcert from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
apk95%

mkcert 1.4.4-r29

simple zero-config tool to make locally trusted development certificates with any names you'd like

https://mkcert.dev/

sudo apk add mkcert
  • License: BSD-3-Clause
  • Architecture: x86_64
  • Source Package: mkcert
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Mkcert
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: mkcert from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
dnf95%

mkcert 1.4.4-9.fc45

Make and install locally trusted development certificates

https://github.com/FiloSottile/mkcert

sudo dnf install mkcert
  • License: BSD-2-Clause-Views AND BSD-3-Clause
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: mkcert
  • 4 Abhängigkeiten
  • 2 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Mkcert
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: mkcert from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
pacman95%

mkcert 1.4.4-3

Simple tool for making locally-trusted development certificates

https://github.com/FiloSottile/mkcert

sudo pacman -S mkcert
  • License: BSD
  • Architecture: x86_64
  • 1 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Mkcert
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: mkcert from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
zypper95%

mkcert 1.4.4-1.4

CLI tool for making locally-trusted development certificates

https://github.com/FiloSottile/mkcert

sudo zypper install mkcert
  • License: BSD-3-Clause
  • Category: Development/Tools/Other
  • Architecture: x86_64
  • Source Package: mkcert
  • 2 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Mkcert
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: mkcert from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
MacPorts95%

mkcert

sudo port install mkcert
  • normalized package name match
  • Abgeglichen nach: Mkcert
MacPorts ports tree · api.github.com · MacPorts ports tree: security/mkcert/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Chocolatey95%

mkcert

choco install mkcert
  • normalized package name match
  • Abgeglichen nach: Mkcert
Chocolatey community package catalog · community.chocolatey.org · Chocolatey community package catalog: mkcert from http://community.chocolatey.org/api/v2/Packages?$filter=IsLatestVersion&$select=Id&$top=1000&$skiptoken='11','mirc'
Scoop95%

extras/mkcert

scoop install extras/mkcert
  • normalized package name match
  • Abgeglichen nach: Mkcert
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/mkcert.json from https://api.github.com/repos/ScoopInstaller/Extras/git/trees/master?recursive=1
winget95%

FiloSottile.mkcert

winget install --id FiloSottile.mkcert -e
  • normalized package name match
  • Abgeglichen nach: Mkcert
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: FiloSottile.mkcert from https://cdn.winget.microsoft.com/cache/source.msix

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • approval-gate seed metadata
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated agent safety answer
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment