Automic Vault

brew package intelligence

buf

Automic Vault tracks buf because plain text buf registry token matters when AI agents run command-line tools on macOS.

overview

What Automic Vault knows about buf

New way of working with Protocol Buffers

Homepage

Not present in the local metadata.

Commands and aliases

No executable aliases were found in the local package database.

radioisotope

Plain Text Buf Registry Token

Buf registry login stores BSR tokens in ~/.netrc by default. Our isotope stores the buf.build token in the macOS keychain and injects it as BUF_TOKEN only while `buf` runs.

Local README excerpt

Buf Radioisotope

buf registry login stores Buf Schema Registry credentials in ~/.netrc by default. Buf also supports BUF_TOKEN, so the radioisotope migrates the default buf.build token into the macOS keychain and injects it only while buf runs.

The migration removes the matching single-line machine buf.build ... password ... entry from ~/.netrc and preserves unrelated machines.

Caveats

  • We currently migrate buf.build and legacy go.buf.build .netrc entries

only.

  • Multi-line or custom .netrc layouts are detected conservatively and are not

rewritten.

  • Direct execution of the original binary will not receive credentials.

Source: data/radioisotopes/buf/README.md

Caveats

  • Only buf.build and legacy go.buf.build .netrc entries are migrated.
  • Multi-line or custom .netrc layouts are not rewritten.
  • Direct execution of the original binary will not receive credentials.

install metadata

Resolver facts

Package keybrew:buf
Last updated2026-04-30T00:25:05Z
Pulseupdated

source trail

Generated from repository data

This page is regenerated by scripts/generate-pkg-pages.py. Deployments refuse to publish if www/pkg/ is stale relative to local package data.

Used sources

  • Nucleus package database
  • local isotope README
  • radioisotope security manifest