macOS
brew install kubescapelocal Homebrew formula metadata
sudo port install kubescapeMacPorts ports tree · sysutils/kubescape/Portfile · 来源: api.github.com
安装
brew install kubescapelocal Homebrew formula metadata
sudo port install kubescapeMacPorts ports tree · sysutils/kubescape/Portfile · 来源: api.github.com
nix profile install nixpkgs#kubescapenixpkgs package indexes · pkgs/by-name/ku/kubescape/package.nix · 来源: api.github.com
sudo zypper install kubescapeopenSUSE Tumbleweed package metadata · kubescape · 来源: download.opensuse.org
scoop install main/kubescapeScoop official bucket manifest trees · bucket/kubescape.json · 来源: api.github.com
winget install --id kubescape.kubescape -eWindows Package Manager source index · kubescape.kubescape · 来源: cdn.winget.microsoft.com
概览
Kubernetes testing according to Hardening Guidance by NSA and CISA
历史
Kubescape is an open source Kubernetes security and compliance platform, created by ARMO and hosted as a CNCF project. The CLI scans clusters, Kubernetes YAML, Helm charts, repositories, container registries, and images for misconfigurations, vulnerabilities, and risk.
Kubescape began as a Kubernetes-focused security scanner and expanded into a broader platform covering posture management, hardening, runtime security, image vulnerability scanning, admission control, and remediation workflows. Its repository describes coverage from development through runtime, including NSA-CISA, MITRE ATT&CK, and CIS benchmark-oriented checks.
The CNCF project page records Kubescape's acceptance into CNCF on December 13, 2022 and its move to Incubating maturity on January 13, 2025.
Kubescape's packaging shows adoption across developer and CI workflows: official docs list Homebrew installation, the project maintains a GitHub Action, and the README lists package-manager paths for Homebrew, Krew, Arch, Ubuntu, Nix, Chocolatey, and Scoop.
The CLI is commonly used to scan a running Kubernetes cluster, scan local manifest directories, scan container images, list controls and frameworks, and integrate security checks into pull-request or CI pipelines.
Kubescape matters to package maintainers because it sits at the intersection of Kubernetes CLI tooling, security scanning databases, and policy frameworks. It is also an example of a CNCF security project with both a standalone CLI and in-cluster components.
安全态势
infrastructure mutation or orchestration signal.
orange 风险 · 中 置信度 · infrastructure
在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。
可执行文件
| 命令 | 类型 | 暴露范围 | 备注 |
|---|---|---|---|
kubescape | cli | 全局可执行文件 |
新鲜度
这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。
https://github.com/kubescape/kubescape
安装元数据
| 软件包键 | brew:kubescape |
|---|---|
| 版本 | 4.0.11 |
| 软件包管理器 | Homebrew |
| 软件包管理器页面 | https://formulae.brew.sh/formula/kubescape |
| 主页 | https://kubescape.io |
| 仓库 | https://github.com/kubescape/kubescape |
| 上游文档 | https://kubescape.io/docs |
| 许可证 | Apache-2.0 |
| 源码归档 | https://github.com/kubescape/kubescape.git |
| 最后更新 | 2026-07-22T17:13:32Z |
| Pulse | updated |
| 构建依赖 | go |
| Bottle | 可用 (于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | 未定义 |
| 服务 | 未声明 |
注册表事实
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | kubescape |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
源数据库匹配
匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。
kubescape
nix profile install nixpkgs#kubescapekubescape 4.0.9-1.1
Tool providing a multi-cloud K8s single pane of glass
https://github.com/armosec/kubescape
sudo zypper install kubescapekubescape
sudo port install kubescapemain/kubescape
scoop install main/kubescapekubescape.kubescape
winget install --id kubescape.kubescape -e来源线索
此页面由 av-web 从 scripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。
View the package source record on GitHub.