Automic VaultAutomic Vault

brew

使用 Homebrew, Nix, scoop 安装 granted

查看 granted 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

安装

其他安装命令

macOS

Homebrew已验证 · 100%
brew install granted

local Homebrew formula metadata

Linux

Nix已验证 · 92%
nix profile install nixpkgs#granted

nixpkgs package indexes · pkgs/by-name/gr/granted/package.nix · 来源: api.github.com

Windows

Scoop已验证 · 92%
scoop install main/granted

Scoop official bucket manifest trees · bucket/granted.json · 来源: api.github.com

概览

软件包摘要

Easiest way to access your cloud

命令和别名

  • assume
  • assume.fish
  • assumego
  • granted

历史

项目历史与用法

Granted is a command-line tool for cloud access, focused on AWS role assumption, AWS SSO workflows, browser-based console access, and safer handling of cached credentials.

项目历史

The Granted README and docs describe the project as a CLI that simplifies access to cloud roles and lets users open multiple cloud accounts in a browser. Its goals are fast role discovery and assumption, browser isolation for simultaneous accounts, and encrypted cached credentials to avoid plaintext SSO tokens on disk.

Granted is developed under the fwdcloudsec GitHub organization and is documented through the Common Fate/Granted documentation site. The repository structure separates the granted management command and assume role-assumption workflow.

采用历史

Granted fits teams with many AWS accounts, especially organizations using AWS SSO/IAM Identity Center. Its adoption is driven by reducing friction around profile selection, browser sessions, and short-lived role credentials.

The Homebrew package is useful because the tool lives directly in shell workflows: users run assume, integrate it with AWS config and credentials files, and pair it with browsers and keychains rather than a server process.

使用方式

Users configure AWS profiles, run assume to select and assume a role, export credentials for terminal commands, or open cloud consoles in separate browser contexts. The docs recommend AWS SSO because it avoids long-lived IAM credentials on a device.

Granted also intersects with package-manager and OS security details because it can use platform credential stores and must behave correctly across macOS, Linux, Windows, shells, and browsers.

为什么软件包爱好者会关心

Granted is significant as a security-adjacent CLI package: it is small, but it touches AWS config conventions, credential files, shell initialization, browser integration, and OS credential stores. Those edges make packaging quality visible to day-to-day cloud operators.

时间线

  • 2024: Discussions and issues show active use around AWS SSO profile and keychain workflows.
  • 2026: The GitHub repository listed hundreds of commits and over a thousand stars, indicating a mature niche CLI package.

Related projects

  • AWS CLI and AWS IAM Identity Center are the primary external systems.
  • Browser container/profile features, OS keychains, and shell integrations are part of the user workflow.
  • Common Fate documentation and fwdcloudsec source control are the official project surfaces.

安全态势

风险级别:orange

infrastructure mutation or orchestration signal.

风险分类器

orange 风险 · 中 置信度 · infrastructure

原因

  • infrastructure mutation or orchestration signal

信号

  • text:cloud

安装行为

  • formula 元数据中未记录 Homebrew post-install 钩子。
  • Homebrew bottle 元数据适用于 6 个平台目标。
  • 构建元数据列出 1 个构建依赖。

建议审查

在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.granted~/.aws/config
Windows
%USERPROFILE%/.granted%UserProfile%\.aws\config

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
~/.aws/credentials
Windows
%UserProfile%\.aws\credentials

可执行文件

已安装的可执行文件

命令类型暴露范围备注
assumecli全局可执行文件
assume.fishcli全局可执行文件
assumegocli全局可执行文件
grantedcli全局可执行文件

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-07-26
管理器版本0.39.0
管理器更新时间
本地数据OK
上游当前
检测到的最新版本v0.39.0

https://github.com/fwdcloudsec/granted

  • 信息No package-manager update timestamp was available.低 置信度

安装元数据

软件包元数据

软件包键brew:granted
版本0.39.0
软件包管理器Homebrew
软件包管理器页面https://formulae.brew.sh/formula/granted
主页https://granted.dev/
仓库https://github.com/fwdcloudsec/granted
上游文档https://docs.granted.dev/
许可证MIT
源码归档https://github.com/fwdcloudsec/granted/archive/refs/tags/v0.39.0.tar.gz
构建依赖go
Bottle可用 (于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定义
服务未声明

注册表事实

源数据库详情

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namegranted
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

源数据库匹配

其他软件包管理器记录

匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。

Nix95%

granted

nix profile install nixpkgs#granted
  • normalized package name match
  • 匹配方式:Granted
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/gr/granted/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Scoop95%

main/granted

scoop install main/granted
  • normalized package name match
  • 匹配方式:Granted
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/granted.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment