macOS
brew install kube-scorelocal Homebrew formula metadata
brew
kube-score のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。
インストール
brew install kube-scorelocal Homebrew formula metadata
nix profile install nixpkgs#kube-scorenixpkgs package indexes · pkgs/by-name/ku/kube-score/package.nix · ソース: api.github.com
概要
Kubernetes object analysis recommendations for improved reliability and security
履歴
kube-score is a Kubernetes manifest analysis CLI that scores object definitions and recommends reliability and security improvements. It is aimed at the pre-deployment stage, where YAML, Helm output, or Kustomize output can still be changed cheaply.
The kube-score repository was created on 2018-09-16, and its first beta release, v0.1.0-beta1, was published on 2018-09-26. The README presents it as static code analysis for Kubernetes object definitions, with checks for resources, network policy coverage, pod disruption budgets, probes, security contexts, and stable APIs.
Unlike cluster-side policy systems, kube-score kept a developer-tool shape: a single CLI that reads manifests, prints human or machine-readable findings, and exits with a CI-friendly status code.
The project documents several distribution paths: GitHub release binaries for macOS, Linux, and Windows, a Docker image, Homebrew, and Krew as the kubectl score plugin. Its website also hosts an online demo backed by the kube-score/web repository, giving users a low-friction way to try the checks without installing the CLI.
Typical usage pipes rendered Kubernetes resources into kube-score, for example from helm template or kustomize build. The tool can also read static YAML files or resources exported from a live cluster, then produce recommendations in human, JSON, CI, or SARIF-oriented formats.
Annotations such as kube-score/ignore and kube-score/enable let users suppress or opt into checks on individual objects, which keeps the linter usable in repositories where not every workload has the same operational constraints.
kube-score matters in package-manager culture because it is a small, composable quality gate for Kubernetes manifests. It turns a broad operational checklist into a command that can live in a Makefile, pre-commit hook, GitHub Action, or CI job.
It also illustrates a common Kubernetes packaging pattern: one Go binary, release artifacts for multiple platforms, a Docker image for containerized CI, Homebrew for local developer machines, and Krew for kubectl-plugin users.
セキュリティ状態
infrastructure mutation or orchestration signal.
リスク orange · 信頼度 中 · infrastructure
エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。
実行可能ファイル
| コマンド | 種類 | 公開範囲 | メモ |
|---|---|---|---|
kube-score | cli | グローバル実行可能ファイル |
鮮度
これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。
https://github.com/zegl/kube-score
インストールメタデータ
| パッケージキー | brew:kube-score |
|---|---|
| バージョン | 1.20.0 |
| パッケージマネージャ | Homebrew |
| パッケージマネージャページ | https://formulae.brew.sh/formula/kube-score |
| ホームページ | https://kube-score.com |
| リポジトリ | https://github.com/zegl/kube-score |
| 上流ドキュメント | https://github.com/zegl/kube-score#readme |
| ライセンス | MIT |
| ソースアーカイブ | https://github.com/zegl/kube-score.git |
| ビルド依存関係 | go |
| Bottle | 利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, arm64_ventura, sonoma, ventura, x86_64_linux) |
| Homebrew post-install | 未定義 |
| サービス | 宣言なし |
レジストリ情報
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | kube-score |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
ソースデータベース一致
一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。
kube-score
nix profile install nixpkgs#kube-scoreソース経路
このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。
View the package source record on GitHub.