Automic VaultAutomic Vault

brew

scrutineer mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für scrutineer in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install scrutineer

local Homebrew formula metadata

Überblick

Paketzusammenfassung

Security through scrutiny

Befehle und Aliase

  • scrutineer

Verlauf

Projektgeschichte und Nutzung

Scrutineer is a local application-security workbench that scans open-source repositories with configurable agent skills, containerized language profiles, conventional analysis tools, and human-gated vulnerability-disclosure workflows. It combines a CLI-launched service with a local web interface for triage, verification, reporting, and release tracking.

Projektgeschichte

Alpha-Omega introduced the public Scrutineer repository in April 2026 to make repeatable, evidence-focused open-source security review practical without overwhelming maintainers with untriaged reports. The project was packaged as a Go executable with embedded skills and runner profiles, and its first public GitHub release was v2026.07.14.1 in July 2026.

Adoptionsgeschichte

Scrutineer is an early-stage project. Its distribution includes precompiled Linux and macOS archives, source builds, container images, and a Homebrew formula; the official README also supports Docker, rootless Podman, and Apple's container runtime for isolated scans.

Wie es verwendet wird

An operator starts Scrutineer, opens its local web UI, and adds a repository URL, organization, SBOM, external finding report, or local source directory. A triage skill fans out into metadata, dependency, advisory, static-analysis, threat-modeling, and model-backed audit tasks, after which the operator verifies findings and controls disclosure through explicit workflow gates.

Warum Paket-Nerds sich dafür interessieren

Scrutineer treats package metadata as security context: it discovers manifests, builds SBOMs, looks up registry versions and dependents, checks advisories, and can import dependencies for deeper scans. Its per-ecosystem runner profiles cover common package managers and native-extension cases, making it especially relevant to maintainers interested in the boundary between package graphs, reproducible tooling, and vulnerability disclosure.

Zeitleiste

  • 2026-04: Public repository development began.
  • 2026-07: First public GitHub release, v2026.07.14.1.

Related projects

  • Semgrep, zizmor, git-pkgs, and brief are integrated as conventional analysis and repository-inspection tools.
  • Claude Code, Codex, and opencode are supported as pluggable agent backends.
  • Docker, Podman, and Apple's container CLI provide the supported isolated runner environments.

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für scrutineer wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
./scrutineer.yaml

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
scrutineercliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version2026.07.14.1
Manager aktualisiert2026-07-14
lokale DatenOK
Upstreamnot checked
neueste erkannte Versionnicht erkannt

https://github.com/alpha-omega-security/scrutineer

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:scrutineer
Version2026.07.14.1
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/scrutineer
Homepagehttps://github.com/alpha-omega-security/scrutineer
Repositoryhttps://github.com/alpha-omega-security/scrutineer
Upstream-Dokumentationhttps://github.com/alpha-omega-security/scrutineer
LizenzMIT
Quellarchivhttps://github.com/alpha-omega-security/scrutineer/archive/refs/tags/v2026.07.14.1.tar.gz
Zuletzt aktualisiert2026-07-14T21:44:50Z
Pulseupdated
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namescrutineer
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment