Automic Vault

brew 软件包情报

安装 git

查看 git 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

安装

使用 Automic Vault 安装

Automic Vault
下载 AV
sudo av install brew:git

macOS

Homebrew 已验证 · 100%
brew install git

local Homebrew formula metadata

MacPorts 已验证 · 94%
sudo port install git

MacPorts ports tree · devel/git/Portfile · 来源: api.github.com

Linux

Alpine Linux apk 已验证 · 92%
sudo apk add git

Alpine Linux edge package indexes · git · 来源: dl-cdn.alpinelinux.org

Debian apt 已验证 · 92%
sudo apt install git

Debian stable package indexes · git · 来源: deb.debian.org

Fedora dnf 已验证 · 92%
sudo dnf install git

Fedora Rawhide package metadata · git · 来源: dl.fedoraproject.org

Nix 已验证 · 92%
nix profile install nixpkgs#git

nixpkgs package indexes · pkgs/by-name/gi/git/package.nix · 来源: api.github.com

Arch Linux pacman 已验证 · 92%
sudo pacman -S git

Arch Linux sync databases · git · 来源: geo.mirror.pkgbuild.com

openSUSE zypper 已验证 · 92%
sudo zypper install git

openSUSE Tumbleweed package metadata · git · 来源: download.opensuse.org

Windows

Chocolatey 已验证 · 92%
choco install git

Chocolatey community package catalog · git · 来源: community.chocolatey.org

Scoop 已验证 · 92%
scoop install main/git

Scoop official bucket manifest trees · bucket/git.json · 来源: api.github.com

Windows Package Manager 已验证 · 92%
winget install --id DuckStudio.ChineseGit -e

Windows Package Manager source index · DuckStudio.ChineseGit · 来源: cdn.winget.microsoft.com

平台说明

  • 没有特定于此软件包的平台说明。

概览

软件包摘要

Automic Vault 根据本地软件包数据发布 git 的安装路径、可执行文件事实和安全元数据。

命令和别名

  • git
  • git-cvsserver
  • git-receive-pack
  • git-shell
  • git-upload-archive
  • git-upload-pack
  • scalar

来源摘要

Distributed revision control system

radioisotope

Plain Text Git Credentials

`git` can store HTTPS credentials in plaintext credential-store files such as ~/.git-credentials. Automic Vault currently detects this exposure but does not yet provide a migration or package modification for Git credential stores.

风险分类器

blue 风险 · high 置信度 · tool

原因

  • doc example: broad file and network tool

信号

  • override:git

安装行为

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • 安装时包含 2 个运行时依赖。
  • 构建元数据列出 2 个构建依赖。

本地 README 摘录

Git Radioisotope Detector

This detector reports plaintext Git credential-store files. It does not currently migrate credentials or modify Git.

Detected hazards:

  • ~/.git-credentials
  • global credential.helper = store --file ... paths

Git helpers backed by Keychain or other secret stores are not reported.

来源: data/radioisotopes/git/README.md

Caveats

  • We detect the default ~/.git-credentials file.
  • We detect global credential.helper store files with explicit --file paths.
  • osxkeychain, cache, and other non-plaintext helpers are not reported.

审批门

Human review metadata for risky commands

The local approval-gate seed includes 6 rules for git. Covered entrypoints: git. Severity labels: critical, high, medium. Coverage: partial, 已审查 2026-05-21.

受控操作示例

  • Push commits, tags, or refs to a remote repository.
  • Force-push or delete remote refs.
  • Reset local worktree and index destructively.
  • Delete untracked files from the worktree.
  • Read, approve, reject, or fill credentials through Git credential helpers.
  • Change credential helper configuration.

可执行文件

已安装的可执行文件

命令类型暴露范围备注
gitcliglobal executable
git-cvsservercliglobal executable
git-receive-packcliglobal executable
git-shellcliglobal executable
git-upload-archivecliglobal executable
git-upload-packcliglobal executable
scalarcliglobal executable

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-05-26
管理器版本2.54.0
管理器更新时间2026-04-21
本地数据ok
上游not checked
检测到的最新版本未检测到

https://git-scm.com

  • info Release/tag comparison is only available for GitHub repositories. https://git-scm.com none 置信度

安装元数据

软件包元数据

软件包键brew:git
版本2.54.0
软件包管理器Homebrew
软件包管理器页面https://formulae.brew.sh/formula/git
主页https://git-scm.com
上游文档https://git-scm.com
许可证GPL-2.0-only AND GPL-2.0-or-later AND LGPL-2.1-or-later AND BSD-3-Clause AND MIT
源码归档https://mirrors.edge.kernel.org/pub/software/scm/git/git-2.54.0.tar.xz
更新2026-04-21T02:44:54Z
Pulseupdated
依赖gettext, pcre2
构建依赖gettext, pkgconf
macOS 提供的库curl, expat
Bottle可用 (arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定义
服务未声明
CaveatsThe Tcl/Tk GUIs (e.g. gitk, git-gui) are now in the `git-gui` formula. Subversion interoperability (git-svn) is now in the `git-svn` formula.

来源线索

由仓库数据生成

此页面由 scripts/generate-pkg-pages.py 写入。如果 www/pkg/ 相对于本地软件包数据已过期,部署会拒绝发布。

使用的来源

  • Geiger risk classifier
  • Nucleus package database
  • approval-gate seed metadata
  • cross-ecosystem install command graph
  • local isotope README
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • radioisotope security manifest