Automic VaultAutomic Vault

brew

bashate を Homebrew, Nix でインストール

bashate のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install bashate

local Homebrew formula metadata

Linux

Nix確認済み · 92%
nix profile install nixpkgs#bashate

nixpkgs package indexes · pkgs/by-name/ba/bashate/package.nix · ソース: api.github.com

概要

パッケージ概要

Code style enforcement for bash programs

コマンドとエイリアス

  • bashate

履歴

プロジェクトの歴史と使われ方

bashate is OpenStack's style checker for Bash scripts. It is essentially a pycodestyle-style lint gate for shell code, built for projects where Bash scripts are part of the reviewed and tested codebase.

プロジェクトの歴史

The official README calls bashate a pep8 equivalent for Bash scripts and says it attempts to fill the same automated code-review role for Bash that pep8 did in many OpenStack projects. It also states that bashate started in the DevStack project and would continue to evolve over time.

The OpenStack documentation and Opendev source identify it as an Apache-licensed OpenStack project with docs, source, bugs, release notes, and contribution pages. Its documented checks cover whitespace, indentation, line endings, line length, structure rules, `bash -n` syntax errors, and obsolete or unsafe syntax.

採用の歴史

bashate's adoption is tied to OpenStack's large shell-script surface, especially DevStack and project automation. The batch input shows Homebrew and Nix packaging; in practice, the tool is most valuable to contributors and CI jobs enforcing OpenStack-adjacent shell style.

The release notes and official tag list show a 0.x line followed by 1.0.0 and 2.x releases, enough history to treat it as a maintained OpenStack utility rather than a one-off script.

使われ方

Users run `bashate` against shell scripts to catch style and safety issues before review or CI. Its output intentionally follows the default pycodestyle output format, making it familiar in OpenStack's Python-heavy review culture.

The documented checks include trailing whitespace, hard tabs, non-multiple-of-four indents, missing final newline, missing shebang or `.sh` suffix, long lines, malformed control structures, heredoc termination, function declaration style, `bash -n` syntax errors, deprecated `$[` arithmetic, risky `local` declarations, and `[[` recommendations for comparisons.

パッケージ好きにとっての重要性

bashate is package-nerd significant because it shows shell scripts becoming first-class reviewed artifacts in a large infrastructure project. It is not a general-purpose shell parser revolution; it is the small enforcement tool that makes a project's Bash style reproducible across laptops and CI workers.

It also captures an OpenStack packaging pattern: a narrow Python CLI published as a standalone package, documented by Sphinx, hosted in Opendev, and installed by package managers for repeatable developer workflows.

タイムライン

  • 2010s: bashate starts in the DevStack project, according to the official README.
  • 2010s: 0.x release tags establish the early style-checker line.
  • 2020: OpenStack release-notes build documents the 0.5.x, 0.6.0, and 1.0.0 release notes.
  • 2020s: Official tag list reaches the 2.x release line.
  • 2020s: Homebrew and Nix package the `bashate` CLI.

Related projects

  • Related projects include DevStack, OpenStack's broader CI/review tooling, pycodestyle/pep8, ShellCheck, shfmt, and Bash itself. bashate's own README explicitly compares its role to pycodestyle.

ソース

  • Official Opendev tag list shows 0.1.0 through 2.1.1 tags.
  • Official README says bashate is a pep8 equivalent for Bash scripts, started in DevStack, and follows pycodestyle output format.
  • Official docs list project documentation, source, bug tracker, release notes, contributing docs, and supported checks.
  • Official release notes page documents 0.5.x, 0.6.0, and 1.0.0 notes.
  • input.source_facts.package-manager lists Homebrew and Nix packaging.

セキュリティ状態

リスクレベル: グリーン

narrow executable package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 1 個のプラットフォームターゲットで利用できます。
  • 1 件の実行時依存関係とともにインストールされます。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
bashatecliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版2.1.1
マネージャ更新日2026-07-15
ローカルデータOK
上流not checked
検出された最新未検出

https://opendev.org/openstack/bashate

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:bashate
バージョン2.1.1
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/bashate
ホームページhttps://opendev.org/openstack/bashate
リポジトリhttps://opendev.org/openstack/bashate
上流ドキュメントhttps://docs.openstack.org/bashate/latest
ライセンスApache-2.0
ソースアーカイブhttps://files.pythonhosted.org/packages/4d/0c/35b92b742cc9da7788db16cfafda2f38505e19045ae1ee204ec238ece93f/bashate-2.1.1.tar.gz
最終更新2026-07-15T10:20:03Z
Pulseupdated
依存関係python@3.14
Bottle利用可能 (対象 all)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namebashate
Version Scheme0
Revision3
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

bashate

nix profile install nixpkgs#bashate
  • normalized package name match
  • 一致条件: Bashate
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ba/bashate/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment