Automic VaultAutomic Vault

brew

kics を Homebrew, Nix でインストール

kics のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install kics

local Homebrew formula metadata

Linux

Nix確認済み · 92%
nix profile install nixpkgs#kics

nixpkgs package indexes · pkgs/by-name/ki/kics/package.nix · ソース: api.github.com

概要

パッケージ概要

Detect vulnerabilities, compliance issues, and misconfigurations

履歴

プロジェクトの歴史と使われ方

KICS, short for Keeping Infrastructure as Code Secure, is Checkmarx's open-source scanner for infrastructure-as-code vulnerabilities, compliance problems, and misconfigurations.

プロジェクトの歴史

Checkmarx created the public KICS repository in 2020 and published v1.0.0 on 2020-11-30. The project arrived during the wider shift from manually provisioned infrastructure toward Terraform, Kubernetes, Helm, CloudFormation, Docker Compose, and other declarative infrastructure formats, where configuration mistakes can become security defects.

採用の歴史

KICS adoption is tied to CI and DevSecOps workflows. Official materials document a GitHub Action, a Docker image, a standalone CLI, and broad platform coverage across Terraform, Kubernetes, Docker, CloudFormation, Ansible, Helm, OpenAPI, gRPC, Azure Resource Manager, Pulumi, Serverless Framework, OpenTofu, Bicep, and more.

使われ方

Users run `kics scan` or CI integrations against infrastructure repositories to catch risky cloud and orchestration settings before deployment. Query packs and documentation make it useful both for one-off audits and for policy-style checks in build pipelines.

パッケージ好きにとっての重要性

KICS is significant because it packages a large IaC security rule corpus as a Go CLI that can be installed by package managers, run in containers, or embedded in GitHub workflows. It sits in the same package-nerd mental shelf as Terraform linters, policy engines, and static analyzers, but focuses on concrete misconfiguration checks across many IaC syntaxes.

タイムライン

  • 2020: Checkmarx/kics repository created on GitHub.
  • 2020: v1.0.0 release published on 2020-11-30.
  • 2021: The 1.1 and 1.2 release series expanded after the initial 1.0 release.
  • 2025: The 2.1 release series was active through repeated published releases.
  • 2026: v2.1.20 release published on 2026-03-03.

Related projects

  • Official KICS materials include a companion Checkmarx/kics-github-action repository for GitHub Actions integration and documentation for scanning common IaC ecosystems such as Terraform, Kubernetes, Helm, CloudFormation, and Docker Compose.

セキュリティ状態

リスクレベル: グリーン

narrow executable package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 6 個のプラットフォームターゲットで利用できます。
  • ビルドメタデータには 1 件のビルド依存関係があります。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
kics.config

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
kicscliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版2.1.20
マネージャ更新日
ローカルデータOK
上流最新
検出された最新v2.1.20

https://github.com/Checkmarx/kics

  • 情報No package-manager update timestamp was available.信頼度 低

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:kics
バージョン2.1.20
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/kics
ホームページhttps://kics.io/
リポジトリhttps://github.com/Checkmarx/kics
上流ドキュメントhttps://docs.kics.io/
ライセンスApache-2.0
ソースアーカイブhttps://github.com/Checkmarx/kics/archive/refs/tags/v2.1.20.tar.gz
ビルド依存関係go
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし
注意点KICS queries are placed under $HOMEBREW_PREFIX/opt/kics/share/kics/assets/queries To use KICS default queries add KICS_QUERIES_PATH env to your ~/.zshrc or ~/.zprofile: "echo 'export KICS_QUERIES_PATH=$HOMEBREW_PREFIX/opt/kics/share/kics/assets/queries' >> ~/.zshrc" usage of CLI flag --queries-path takes precedence.

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namekics
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

kics

nix profile install nixpkgs#kics
  • normalized package name match
  • 一致条件: Kics
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ki/kics/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment