Automic VaultAutomic Vault

brew / rang 6010

Installer gitsign

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de gitsign pour les workflows d'agents IA.

installation

Installer avec Automic Vault

Automic Vault
sudo av install brew:gitsign

macOS

Homebrewverified · 100%
brew install gitsign

local Homebrew formula metadata

MacPortsverified · 94%
sudo port install gitsign

MacPorts ports tree · security/gitsign/Portfile · source: api.github.com

Linux

Debian aptverified · 92%
sudo apt install gitsign

Debian stable package indexes · gitsign · source: deb.debian.org

Nixverified · 92%
nix profile install nixpkgs#gitsign

nixpkgs package indexes · pkgs/by-name/gi/gitsign/package.nix · source: api.github.com

Arch Linux pacmanverified · 92%
sudo pacman -S gitsign

Arch Linux sync databases · gitsign · source: geo.mirror.pkgbuild.com

openSUSE zypperverified · 92%
sudo zypper install gitsign

openSUSE Tumbleweed package metadata · gitsign · source: download.opensuse.org

Windows

Scoopverified · 92%
scoop install main/gitsign

Scoop official bucket manifest trees · bucket/gitsign.json · source: api.github.com

Notes de plateforme

  • Aucune note de plateforme propre au paquet n'était présente.

aperçu

Résumé du paquet

Keyless Git signing using Sigstore

Commandes et alias

  • gitsign
  • gitsign-credential-cache

posture de sécurité

Niveau de risque : green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Build metadata lists 1 build dependencies.

Revue recommandée

Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.

exécutables

Exécutables installés

CommandeTypeExpositionNote
gitsigncliglobal executable
gitsign-credential-cachecliglobal executable

fraîcheur

Version et fraîcheur

Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.

page générée2026-06-10
version du gestionnaire0.16.1
gestionnaire mis à jour2026-06-08
données localesok
amontcurrent
dernière version détectéev0.16.1

https://github.com/sigstore/gitsign

  • okNo freshness warnings were generated.

métadonnées d'installation

Métadonnées du paquet

Package keybrew:gitsign
Version0.16.1
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/gitsign
Homepagehttps://github.com/sigstore/gitsign
Repositoryhttps://github.com/sigstore/gitsign
Upstream docshttps://docs.sigstore.dev/
LicenseApache-2.0
Source archivehttps://github.com/sigstore/gitsign/archive/refs/tags/v0.16.1.tar.gz
Last updated2026-06-08T21:43:20Z
Pulseupdated
Build dependenciesgo
Bottleavailable (arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namegitsign
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Debian apt95%

gitsign 0.13.0-2+b2

Keyless Git signing using Sigstore (program)

https://github.com/sigstore/gitsign

sudo apt install gitsign
  • Section: vcs
  • Architecture: amd64
  • Source Package: gitsign
  • 1 dependencies
  • normalized package name match
  • Matched by: Gitsign
Debian stable package indexes · deb.debian.org · Debian stable package indexes: gitsign from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Debian apt95%

golang-github-sigstore-gitsign-dev 0.13.0-2

Keyless Git signing using Sigstore (library)

https://github.com/sigstore/gitsign

sudo apt install golang-github-sigstore-gitsign-dev
  • Section: golang
  • Architecture: all
  • Source Package: gitsign
  • 10 dependencies
  • normalized package name match
  • Matched by: Gitsign
Debian stable package indexes · deb.debian.org · Debian stable package indexes: golang-github-sigstore-gitsign-dev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Nix95%

gitsign

nix profile install nixpkgs#gitsign
  • normalized package name match
  • Matched by: Gitsign
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/gi/gitsign/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
pacman95%

gitsign 0.14.0-2

Keyless Git signing using Sigstore

https://github.com/sigstore/gitsign

sudo pacman -S gitsign
  • License: APACHE
  • Architecture: x86_64
  • normalized package name match
  • Matched by: Gitsign
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: gitsign from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
zypper95%

gitsign 0.16.0-1.1

Keyless Git signing using Sigstore

https://github.com/sigstore/gitsign

sudo zypper install gitsign
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: gitsign
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Gitsign
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: gitsign from https://download.opensuse.org/tumbleweed/repo/oss/repodata/155b97171d05e27afd950b6fe0d55513ff38f4597110664535bceedc680bbe6fd459f0733718dcc21dcf0efc7c8250fd1390c73d4790b42e62fb2c16a87242e5-primary.xml.zst
zypper95%

gitsign-credential-cache 0.16.0-1.1

Credential cache for gitsign

https://github.com/sigstore/gitsign

sudo zypper install gitsign-credential-cache
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: gitsign
  • 3 dependencies
  • 2 provides
  • normalized package name match
  • Matched by: Gitsign
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: gitsign-credential-cache from https://download.opensuse.org/tumbleweed/repo/oss/repodata/155b97171d05e27afd950b6fe0d55513ff38f4597110664535bceedc680bbe6fd459f0733718dcc21dcf0efc7c8250fd1390c73d4790b42e62fb2c16a87242e5-primary.xml.zst
MacPorts95%

gitsign

sudo port install gitsign
  • normalized package name match
  • Matched by: Gitsign
MacPorts ports tree · api.github.com · MacPorts ports tree: security/gitsign/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Scoop95%

main/gitsign

scoop install main/gitsign
  • normalized package name match
  • Matched by: Gitsign
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/gitsign.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

piste source

Généré depuis les données du dépôt

Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.

Sources utilisées

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment