macOS
brew install awscli
local Homebrew formula metadata
brew パッケージインテリジェンス
awscli のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。
インストール
sudo av install brew:awscli
brew install awscli
local Homebrew formula metadata
sudo apt install awscli
Debian stable package indexes · awscli · ソース: deb.debian.org
nix profile install nixpkgs#awscli
nixpkgs package indexes · pkgs/by-name/aw/awscli/package.nix · ソース: api.github.com
sudo dnf install aws
Fedora Rawhide package metadata · aws · ソース: dl.fedoraproject.org
choco install awscli
Chocolatey community package catalog · awscli · ソース: community.chocolatey.org
scoop install main/aws
Scoop official bucket manifest trees · bucket/aws.json · ソース: api.github.com
概要
Automic Vault は、awscli のパッケージ固有のインストール経路、実行可能ファイル情報、セキュリティメタデータをローカルパッケージデータから公開します。
Official Amazon AWS command-line interface
radioisotope
`aws` stores credentials as plaintext at ~/.aws/credentials. Our isotope securely locks them in the macOS keychain such that only the root-controlled `aws` launcher running isolated Python can retrieve them through AWS' native credential_process protocol. External AWS CLI legacy plugins are disabled because they can run inside that credential-approved process. Explicit `aws config export-credentials` output is approval gated.
orange リスク · high 信頼度 · infrastructure
ローカル README 抜粋
aws-cli IsotopeThe isotope now uses AWS' native credential_process protocol instead of placing AWS secrets in the aws process environment.
Migration moves plain text keys from ~/.aws/credentials to the Keychain and installs this non-secret config in ~/.aws/config:
[default]
credential_process = /usr/local/bin/av credential-helper aws
The installed /opt/awscli/bin/aws launcher runs AWS Python in isolated mode and mints a short-lived AUTOMIC_VAULT_CREDENTIAL_HELPER_TOKEN for the AWS process. The helper only answers when that token is present and the parent process is the root-controlled AWS launcher path running under isolated Python, so unrelated processes cannot call the helper directly to retrieve credentials and cannot use PYTHONPATH/sitecustomize injection to make AWS Python call it. The isotope also disables AWS CLI legacy external plugins because those plugins run as Python code inside the credential-approved AWS process.
aws config export-credentials is approval gated before it can print the credential-process result, including invocations with AWS global options before the config command.
Detection also treats aws login cache files under ~/.aws/login/cache as plain text credentials. Migration warns when those files are present because this isotope cannot safely migrate the result of aws login.
We assume a single profile and user. If you have more complex credential requirements you should use brew:aws-vault-binary instead. It’s more cumbersome but also more capable.
AWS CLI legacy external plugins configured under [plugins] are intentionally disabled. If your workflow depends on them, use non-isotoped brew:awscli or a dedicated credential manager.
ソース: data/radioisotopes/aws-cli/README.md
承認ゲート
The local approval-gate seed includes 8 rules for awscli. Covered entrypoints: aws. Severity labels: critical, high. Coverage: partial, レビュー済み 2026-05-21.
実行可能ファイル
| コマンド | 種類 | 公開範囲 | メモ |
|---|---|---|---|
aws | cli | global executable | Primary AWS command-line interface. |
aws_completer | completion helper | Homebrew executable; excluded from Automic Vault stubs | Shell completion helper for aws. |
鮮度
これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。
https://github.com/aws/aws-cli
インストールメタデータ
| パッケージキー | brew:awscli |
|---|---|
| バージョン | 2.34.53 |
| パッケージマネージャ | Homebrew |
| パッケージマネージャページ | https://formulae.brew.sh/formula/awscli |
| ホームページ | https://aws.amazon.com/cli/ |
| リポジトリ | https://github.com/aws/aws-cli |
| 上流ドキュメント | https://docs.aws.amazon.com/cli/ |
| ライセンス | Apache-2.0 |
| ソースアーカイブ | https://github.com/aws/aws-cli/archive/refs/tags/2.34.53.tar.gz |
| 更新 | 2026-05-22T22:50:32Z |
| 確認済み | 2026-05-23 |
| Pulse | updated |
| 依存関係 | openssl@3, python@3.14 |
| ビルド依存関係 | cmake |
| macOS 提供ライブラリ | libffi, mandoc |
| Bottle | 利用可能 (arm64_tahoe, arm64_sequoia, arm64_sonoma, sonoma, arm64_linux, x86_64_linux) |
| Homebrew post-install | 未定義 |
| サービス | 宣言なし |
| Caveats | The examples directory has been installed to $HOMEBREW_PREFIX/share/awscli/examples. |
ソース経路
このページは scripts/generate-pkg-pages.py によって書かれます。www/pkg/ がローカルパッケージデータに対して古い場合、デプロイは公開を拒否します。