# scrutineer を Homebrew でインストール

scrutineer のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

## インストール

```sh
sudo av install brew:scrutineer
```

追加のインストールコマンド:

### macOS

- Homebrew (100%):

```sh
brew install scrutineer
```

  証拠: local Homebrew formula metadata

## パッケージ情報

- **パッケージキー:** brew:scrutineer
- **パッケージマネージャ:** Homebrew
- **パッケージマネージャページ:** <https://formulae.brew.sh/formula/scrutineer>
- **バージョン:** 2026.07.14.1
- **ソース概要:** Security through scrutiny
- **ホームページ:** <https://github.com/alpha-omega-security/scrutineer>
- **リポジトリ:** <https://github.com/alpha-omega-security/scrutineer>
- **上流ドキュメント:** <https://github.com/alpha-omega-security/scrutineer>
- **ライセンス:** MIT
- **ソースアーカイブ:** <https://github.com/alpha-omega-security/scrutineer/archive/refs/tags/v2026.07.14.1.tar.gz>
- **最終更新:** 2026-07-14T21:44:50Z
- **生成日時:** 2026-07-26T07:20:29+00:00

## 実行可能ファイル

- scrutineer (cli)
- scrutineer (エイリアス)

## ビルド依存関係

- go

## インストール挙動

- post-install フック: 未定義
- Bottle: 利用可能 対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## バージョンと鮮度

- ページ生成日: 2026-07-26
- マネージャ版: 2026.07.14.1
- マネージャ更新日: 2026-07-14
- ローカルデータ: OK
- 上流リポジトリ: https://github.com/alpha-omega-security/scrutineer
- 情報: No cached GitHub release or tag data was available.
## プロジェクトの歴史と使われ方

Scrutineer is a local application-security workbench that scans open-source repositories with configurable agent skills, containerized language profiles, conventional analysis tools, and human-gated vulnerability-disclosure workflows. It combines a CLI-launched service with a local web interface for triage, verification, reporting, and release tracking.

### プロジェクトの歴史

Alpha-Omega introduced the public Scrutineer repository in April 2026 to make repeatable, evidence-focused open-source security review practical without overwhelming maintainers with untriaged reports. The project was packaged as a Go executable with embedded skills and runner profiles, and its first public GitHub release was v2026.07.14.1 in July 2026.

### 採用の歴史

Scrutineer is an early-stage project. Its distribution includes precompiled Linux and macOS archives, source builds, container images, and a Homebrew formula; the official README also supports Docker, rootless Podman, and Apple's container runtime for isolated scans.

### 使われ方

An operator starts Scrutineer, opens its local web UI, and adds a repository URL, organization, SBOM, external finding report, or local source directory. A triage skill fans out into metadata, dependency, advisory, static-analysis, threat-modeling, and model-backed audit tasks, after which the operator verifies findings and controls disclosure through explicit workflow gates.

### パッケージ好きにとっての重要性

Scrutineer treats package metadata as security context: it discovers manifests, builds SBOMs, looks up registry versions and dependents, checks advisories, and can import dependencies for deeper scans. Its per-ecosystem runner profiles cover common package managers and native-extension cases, making it especially relevant to maintainers interested in the boundary between package graphs, reproducible tooling, and vulnerability disclosure.

### タイムライン

- 2026-04: Public repository development began.
- 2026-07: First public GitHub release, v2026.07.14.1.

### Related projects

- Semgrep, zizmor, git-pkgs, and brief are integrated as conventional analysis and repository-inspection tools.
- Claude Code, Codex, and opencode are supported as pluggable agent backends.
- Docker, Podman, and Apple's container CLI provide the supported isolated runner environments.

### ソース

- <https://alpha-omega.dev/blog/scrutineer-scanning-open-source-without-flooding-maintainers/>
- <https://github.com/alpha-omega-security/scrutineer>
- <https://github.com/alpha-omega-security/scrutineer/releases>
- source_facts.package-manager.brew


## セキュリティノート

scrutineer に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: ./scrutineer.yaml
## ソースデータベース詳細

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** scrutineer
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable


## 関連リンク

- [Cloud CLI packages](https://www.automicvault.com/ja/pkg/cloud-clis/) - Belongs to a cloud or infrastructure command family.
- [Source-control packages](https://www.automicvault.com/ja/pkg/source-control-tools/) - Belongs to a source-control command family.
- [Terminal utility packages](https://www.automicvault.com/ja/pkg/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Language runtime packages](https://www.automicvault.com/ja/pkg/language-runtime-packages/) - Matched language runtime, compiler, or interpreter metadata.
- [go](https://www.automicvault.com/ja/pkg/brew/go/) - Build dependency declared by Homebrew.
- [cycode](https://www.automicvault.com/ja/pkg/brew/cycode/) - Shares av.db curated category or tags: application-security, cli, security.
- [clair](https://www.automicvault.com/ja/pkg/brew/clair/) - Shares av.db curated category or tags: cli, containers, security, vulnerability-scanning.
- [copa](https://www.automicvault.com/ja/pkg/brew/copa/) - Shares av.db curated category or tags: cli, containers, security, vulnerability-scanning.
- [cyclonedx-gomod](https://www.automicvault.com/ja/pkg/brew/cyclonedx-gomod/) - Shares av.db curated category or tags: cli, go, sbom, security.
- [govulncheck](https://www.automicvault.com/ja/pkg/brew/govulncheck/) - Shares av.db curated category or tags: cli, go, security, vulnerability-scanning.
- [retire](https://www.automicvault.com/ja/pkg/brew/retire/) - Shares av.db curated category or tags: cli, dependency-analysis, sbom, security.
- [syft](https://www.automicvault.com/ja/pkg/brew/syft/) - Shares av.db curated category or tags: cli, containers, sbom, security.
- [tern](https://www.automicvault.com/ja/pkg/brew/tern/) - Shares av.db curated category or tags: cli, containers, sbom, security.
- [retire](https://www.automicvault.com/ja/pkg/npm/retire/) - Security-sensitive metadata or terminology overlaps. Shared terms: analysis, cli, sbom, scanning, security.
- [cdxgen](https://www.automicvault.com/ja/pkg/brew/cdxgen/) - Security-sensitive metadata or terminology overlaps. Shared terms: audit, cli, disclosure, sbom, security.

## Combined YAML source

View the package source record on GitHub. [combined/scrutineer.yml](https://github.com/automic-vault/db/blob/main/combined/scrutineer.yml)


## ソース

- Nucleus package database
- package-page enrichment
- curated configuration and credential file locations
- curated package history
- package version freshness
- av.db category and tag curation
- package relationship graph
- cross-ecosystem install command graph
