Automic VaultAutomic Vault

brew

使用 Homebrew, apk, MacPorts, Nix, pacman, scoop, winget 安装 buf

查看 buf 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

代理安全

代理安全回答

buf manages protobuf linting, generation, and registry workflows.

凭据访问

Reads registry tokens, environment variables, and project schema files.

远程变更

Can push modules and interact with remote schema registries.

发布/制品风险

Can publish schema modules and generated artifacts.

推荐控制

Gate push, registry login, and token-backed commands.

代理使用指南

Allow lint/generate; require approval for registry writes and token use.

安装

其他安装命令

macOS

Homebrew已验证 · 100%
brew install buf

local Homebrew formula metadata

MacPorts已验证 · 94%
sudo port install buf

MacPorts ports tree · devel/buf/Portfile · 来源: api.github.com

Windows

Scoop已验证 · 92%
scoop install main/buf

Scoop official bucket manifest trees · bucket/buf.json · 来源: api.github.com

Windows Package Manager已验证 · 92%
winget install --id bufbuild.buf -e

Windows Package Manager source index · bufbuild.buf · 来源: cdn.winget.microsoft.com

概览

软件包摘要

New way of working with Protocol Buffers

命令和别名

  • buf
  • protoc-gen-buf-breaking
  • protoc-gen-buf-lint

历史

项目历史与用法

Buf is a modern Protocol Buffers toolchain centered on the `buf` CLI, replacing many direct `protoc` workflows with module-aware builds, linting, breaking-change detection, formatting, code generation, dependency management, API calls, and access to the Buf Schema Registry.

项目历史

Buf was created by Buf Technologies as a developer-tooling layer for Protobuf projects. Its public repository presents it as a modern toolchain for Protobuf rather than a replacement for the schema language itself: it keeps the plugin model familiar to `protoc` users while adding workspace configuration, deterministic checks, and registry-aware workflows.

The project grew beyond a formatter or wrapper into a broader ecosystem: the CLI, Buf Schema Registry, remote plugins, generated SDKs, ConnectRPC, Protobuf-ES, and Protovalidate are all positioned by Buf as related pieces of schema-driven API infrastructure.

采用历史

Buf adoption followed the pain points of larger Protobuf users: teams wanted one repeatable command for compiling, linting, compatibility checks, and generation instead of per-repository shell scripts around `protoc -I` paths. The CLI is distributed through Homebrew, npm, Docker, Windows installers, binary downloads, tarballs, source builds, and other package managers listed in the input.

Registry features widened its role from local CLI tooling to organization-level schema governance. The Buf Schema Registry stores modules, renders documentation, resolves dependencies, hosts remote plugins, produces generated SDKs, and can enforce schema checks for teams that publish APIs there.

使用方式

Typical CLI use starts with `buf config init`, then `buf build`, `buf format -w`, `buf lint`, `buf breaking --against ...`, and `buf generate`. Projects commonly check in `buf.yaml`, `buf.gen.yaml`, and `buf.lock` so CI and developer laptops run the same Protobuf workflow.

Core CLI features work without a Buf Schema Registry account, while signing in adds private module dependency resolution, remote plugins, generated SDKs, hosted documentation, and server-side checks.

为什么软件包爱好者会关心

Buf matters to package-tooling people because it treats `.proto` files as versioned modules instead of loose source files copied between repos. It brings package-lock and registry patterns familiar from language ecosystems into Protobuf schema distribution.

It is also a notable example of a package manager formula that installs not only the main `buf` binary but companion protoc plugins, making Homebrew a convenient entry point for Protobuf linting and compatibility checks.

时间线

  • 2020: Early public Buf releases established the CLI around Protobuf build, lint, breaking-change, and generation workflows.
  • 2021: Buf reached a stable v1 line and documented a no-breaking-changes-within-major-version CLI policy.
  • 2020s: The project expanded around the Buf Schema Registry, remote plugins, generated SDKs, ConnectRPC, Protobuf-ES, and Protovalidate.

Related projects

  • `protoc` is the historical compiler that Buf augments for day-to-day Protobuf workflows.
  • The Buf Schema Registry is the hosted registry used for modules, documentation, remote plugins, generated SDKs, and schema checks.
  • ConnectRPC, Protobuf-ES, and Protovalidate are related Buf ecosystem projects named by the official README.

安全态势

风险级别:绿色

narrow executable package without higher-risk signals.

风险分类器

绿色 风险 · 低 置信度 · appliance

原因

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

安装行为

  • formula 元数据中未记录 Homebrew post-install 钩子。
  • Homebrew bottle 元数据适用于 6 个平台目标。
  • 构建元数据列出 1 个构建依赖。

建议审查

在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
~/.netrc

可执行文件

已安装的可执行文件

命令类型暴露范围备注
bufcli全局可执行文件
protoc-gen-buf-breakingcli全局可执行文件
protoc-gen-buf-lintcli全局可执行文件

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-07-25
管理器版本1.72.0
管理器更新时间2026-07-17
本地数据OK
上游当前
检测到的最新版本v1.72.0

https://github.com/bufbuild/buf

  • OK没有生成新鲜度警告。

安装元数据

软件包元数据

软件包键brew:buf
版本1.72.0
软件包管理器Homebrew
软件包管理器页面https://formulae.brew.sh/formula/buf
主页https://buf.build
仓库https://github.com/bufbuild/buf
上游文档https://buf.build/docs/cli
许可证Apache-2.0
源码归档https://github.com/bufbuild/buf/archive/refs/tags/v1.72.0.tar.gz
最后更新2026-07-17T20:53:06Z
Pulseupdated
构建依赖go
Bottle可用 (于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定义
服务未声明

注册表事实

源数据库详情

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namebuf
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

源数据库匹配

其他软件包管理器记录

匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。

Nix95%

buf

nix profile install nixpkgs#buf
  • normalized package name match
  • 匹配方式:Buf
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/bu/buf/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

buf 1.59.0-r6

CLI to work with Protocol Buffers

https://buf.build/

sudo apk add buf
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: buf
  • 1 依赖
  • 1 提供
  • normalized package name match
  • 匹配方式:Buf
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: buf from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

buf-bash-completion 1.59.0-r6

Bash completions for buf

https://buf.build/

sudo apk add buf-bash-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: buf
  • normalized package name match
  • 匹配方式:Buf
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: buf-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

buf-fish-completion 1.59.0-r6

Fish completions for buf

https://buf.build/

sudo apk add buf-fish-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: buf
  • normalized package name match
  • 匹配方式:Buf
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: buf-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

buf-protoc-plugins 1.59.0-r6

CLI to work with Protocol Buffers (protoc plugins)

https://buf.build/

sudo apk add buf-protoc-plugins
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: buf
  • 1 依赖
  • 1 提供
  • normalized package name match
  • 匹配方式:Buf
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: buf-protoc-plugins from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

buf-zsh-completion 1.59.0-r6

Zsh completions for buf

https://buf.build/

sudo apk add buf-zsh-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: buf
  • normalized package name match
  • 匹配方式:Buf
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: buf-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
pacman95%

buf 1.70.0-1

A tool for working with Protocol Buffers

https://buf.build

sudo pacman -S buf
  • License: Apache-2.0
  • Architecture: x86_64
  • 1 依赖
  • normalized package name match
  • 匹配方式:Buf
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: buf from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

buf

sudo port install buf
  • normalized package name match
  • 匹配方式:Buf
MacPorts ports tree · api.github.com · MacPorts ports tree: devel/buf/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Scoop95%

main/buf

scoop install main/buf
  • normalized package name match
  • 匹配方式:Buf
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/buf.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
winget95%

bufbuild.buf

winget install --id bufbuild.buf -e
  • normalized package name match
  • 匹配方式:Buf
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: bufbuild.buf from https://cdn.winget.microsoft.com/cache/source.msix

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated agent safety answer
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment