Automic VaultAutomic Vault

brew

goshs を Homebrew, apk, Nix, zypper, scoop, winget でインストール

goshs のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install goshs

local Homebrew formula metadata

Windows

Scoop確認済み · 92%
scoop install extras/goshs

Scoop official bucket manifest trees · bucket/goshs.json · ソース: api.github.com

Windows Package Manager確認済み · 92%
winget install --id GoshsLabs.Goshs -e

Windows Package Manager source index · GoshsLabs.Goshs · ソース: cdn.winget.microsoft.com

概要

パッケージ概要

Simple, yet feature-rich web server written in Go

履歴

プロジェクトの歴史と使われ方

goshs is a Go single-binary file server aimed at situations where Python's SimpleHTTPServer style sharing is too limited. Its project materials frame it for red-team, pentest, CTF, and quick file-transfer workflows, combining HTTP/S with protocols and security-oriented helpers such as WebDAV, FTP/SFTP, SMB, LDAP/S, DNS and SMTP callbacks, NTLM hash capture, share links, authentication, and a terminal dashboard.

プロジェクトの歴史

The project grew from the familiar local-file-server niche into a penetration-testing utility. The README explicitly credits updog as inspiration, which places goshs in the lineage of small engagement-friendly servers that trade web-server configuration for a single command.

The 2.x documentation and release notes show a broadening scope: v2.0.0 emphasized SMB, DNS, SMTP, redirects, ACLs, and share links; later 2.1 releases added a TUI, self-destruct timers, payload templating, range downloads, TFTP, and reverse-shell payload generation. The project also moved to the goshs-labs GitHub organization during the v2.1.0 line.

採用の歴史

goshs is packaged for Homebrew and is also advertised by the project for Kali/Parrot, Arch AUR, BlackArch, Alpine, Snap, Fedora/RHEL COPR, openSUSE, Nix/NixOS, Scoop, winget, Chocolatey, Docker, Go install, and GitHub Releases. That spread matches a tool meant to be dropped quickly onto operator workstations, lab VMs, and disposable engagement environments.

使われ方

Typical usage starts a web server for the working directory, then enables only the pieces needed for a task: HTTPS and basic auth for protected sharing, SMB or LDAP for credential and hash capture, DNS/SMTP callbacks for interaction tracking, WebDAV/FTP/SFTP/TFTP for protocol-specific transfer, TTL for temporary servers, or the TUI for SSH sessions without a browser.

パッケージ好きにとっての重要性

Package maintainers care about goshs because it is a feature-dense single binary with a Go module path, release artifacts, shell completions, container images, and many optional behaviors hidden behind flags rather than separate services. It also carries security-sensitive behavior, so packaging and upgrade cadence matter more than for a plain static file server.

タイムライン

  • 2025: Security advisory GHSA-rwj2-w85g-5cmm documents a command-execution exposure tested against goshs 1.0.4 and notes the command feature was introduced in 0.3.4.
  • 2026-05: v2.1.0 release notes record the move to github.com/goshs-labs/goshs and several security fixes.
  • 2026-06: 2.1 releases add a TUI, TTL shutdown, payload templating, resumable downloads, TFTP, reverse-shell payload generation, and packaging/CI updates.

Related projects

  • updog is credited by goshs as project inspiration.
  • Python's SimpleHTTPServer/http.server is the baseline goshs positions itself beyond.
  • ConPtyShell appears in goshs release notes as an on-demand helper for Windows shell upgrades.

セキュリティ状態

保護ツール対応はまだ見つかっていません

goshs に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 6 個のプラットフォームターゲットで利用できます。
  • ビルドメタデータには 1 件のビルド依存関係があります。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
.goshs

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
goshscliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版2.1.4
マネージャ更新日2026-07-03
ローカルデータOK
上流最新
検出された最新v2.1.4

https://github.com/goshs-labs/goshs

  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:goshs
バージョン2.1.4
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/goshs
ホームページhttps://goshs.de
リポジトリhttps://github.com/goshs-labs/goshs
上流ドキュメントhttps://docs.goshs.de/
ライセンスMIT
ソースアーカイブhttps://github.com/goshs-labs/goshs/archive/refs/tags/v2.1.4.tar.gz
最終更新2026-07-03T10:38:16Z
Pulseupdated
ビルド依存関係go
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namegoshs
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

goshs

nix profile install nixpkgs#goshs
  • normalized package name match
  • 一致条件: Goshs
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/go/goshs/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

goshs 2.1.0-r0

A SimpleHTTPServer written in Go, enhanced with features and with a nice design.

https://goshs.de

sudo apk add goshs
  • License: MIT
  • Architecture: x86_64
  • Source Package: goshs
  • 1 依存関係
  • 1 提供
  • normalized package name match
  • 一致条件: Goshs
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: goshs from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

goshs-doc 2.1.0-r0

A SimpleHTTPServer written in Go, enhanced with features and with a nice design. (documentation)

https://goshs.de

sudo apk add goshs-doc
  • License: MIT
  • Architecture: x86_64
  • Source Package: goshs
  • normalized package name match
  • 一致条件: Goshs
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: goshs-doc from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
zypper95%

goshs 2.1.0-1.1

A simple HTTP server

https://goshs.de/

sudo zypper install goshs
  • License: MIT
  • Category: Productivity/Networking/Web/Servers
  • Architecture: x86_64
  • Source Package: goshs
  • 1 提供
  • normalized package name match
  • 一致条件: Goshs
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: goshs from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
Scoop95%

extras/goshs

scoop install extras/goshs
  • normalized package name match
  • 一致条件: Goshs
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/goshs.json from https://api.github.com/repos/ScoopInstaller/Extras/git/trees/master?recursive=1
winget95%

GoshsLabs.Goshs

winget install --id GoshsLabs.Goshs -e
  • normalized package name match
  • 一致条件: Goshs
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: GoshsLabs.Goshs from https://cdn.winget.microsoft.com/cache/source.msix
winget95%

PatrickHener.Goshs

winget install --id PatrickHener.Goshs -e
  • normalized package name match
  • 一致条件: Goshs
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: PatrickHener.Goshs from https://cdn.winget.microsoft.com/cache/source.msix

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment