Automic VaultAutomic Vault

brew

diffoci を Homebrew, Nix, pacman でインストール

diffoci のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install diffoci

local Homebrew formula metadata

Linux

Nix確認済み · 92%
nix profile install nixpkgs#diffoci

nixpkgs package indexes · pkgs/by-name/di/diffoci/package.nix · ソース: api.github.com

Arch Linux pacman確認済み · 92%
sudo pacman -S diffoci

Arch Linux sync databases · diffoci · ソース: geo.mirror.pkgbuild.com

概要

パッケージ概要

Diff for Docker and OCI container images

コマンドとエイリアス

  • diffoci

履歴

プロジェクトの歴史と使われ方

diffoci is a command-line comparison tool for Docker and OCI container images, aimed at finding the practical differences between two image artifacts in reproducible-builds work.

プロジェクトの歴史

The project lives under the reproducible-containers organization and frames itself as a diff tool for Docker and OCI images. Its README presents strict comparison as the baseline and semantic comparison as the more useful mode for image reproducibility checks.

採用の歴史

The official README documents binary releases for Linux and macOS, installation through mise, and source installation with Go, which places diffoci in the familiar package-manager and single-binary CLI lane for container tooling.

使われ方

Typical use compares two image references with `diffoci diff IMAGE0 IMAGE1`; the README recommends `--semantic` when timestamp, layer ordering, build history, or image-name annotation noise would make strict output too noisy. It can also compare local Docker or Podman images with `docker://` and `podman://` prefixes and can dump differing files to a report directory.

パッケージ好きにとっての重要性

For package maintainers and reproducible-builds people, diffoci fills the gap between byte-level archive comparison and the layered, metadata-heavy world of OCI images. It is useful when the artifact being packaged is not a tarball or binary but a container image with registry, platform, and layer semantics.

タイムライン

  • 2023: README examples focus on comparing Alpine and Docker Hub images in reproducibility investigations.
  • 2020s: Project distributed as a Go CLI with Linux and macOS binary releases.

Related projects

  • diffoci is adjacent to diffoscope for deep artifact comparison, but specializes in Docker and OCI image layout, containerd, Docker, Podman, and registry workflows.

セキュリティ状態

リスクレベル: orange

broad file, network, media, or database tool signal. infrastructure mutation or orchestration signal.

リスク分類器

リスク orange · 信頼度 中 · infrastructure

理由

  • broad file, network, media, or database tool signal
  • infrastructure mutation or orchestration signal

信号

  • text:container
  • text:image

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 6 個のプラットフォームターゲットで利用できます。
  • ビルドメタデータには 1 件のビルド依存関係があります。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
diffocicliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版0.1.8
マネージャ更新日
ローカルデータOK
上流最新
検出された最新v0.1.8

https://github.com/reproducible-containers/diffoci

  • 情報No package-manager update timestamp was available.信頼度 低

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:diffoci
バージョン0.1.8
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/diffoci
ホームページhttps://github.com/reproducible-containers/diffoci
リポジトリhttps://github.com/reproducible-containers/diffoci
上流ドキュメントhttps://github.com/reproducible-containers/diffoci#readme
ライセンスApache-2.0
ソースアーカイブhttps://github.com/reproducible-containers/diffoci/archive/refs/tags/v0.1.8.tar.gz
ビルド依存関係go
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namediffoci
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

diffoci

nix profile install nixpkgs#diffoci
  • normalized package name match
  • 一致条件: Diffoci
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/di/diffoci/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
pacman95%

diffoci 0.1.8-1

diff for Docker and OCI container images

https://github.com/reproducible-containers/diffoci

sudo pacman -S diffoci
  • License: Apache-2.0
  • Architecture: x86_64
  • 1 依存関係
  • normalized package name match
  • 一致条件: Diffoci
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: diffoci from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment