Automic VaultAutomic Vault

brew

使用 Homebrew, dnf, Nix, pacman, scoop, winget 安装 nuget

查看 nuget 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

代理安全

代理安全回答

nuget manages .NET packages and registry publishing.

凭据访问

Reads NuGet API keys, package source credentials, and config files.

远程变更

Can push packages and change package-source state.

发布/制品风险

Can publish .NET packages and symbols.

推荐控制

Gate push, delete, source credential, and API-key commands.

代理使用指南

Allow restore/list; require approval for package publication and credential changes.

安装

其他安装命令

macOS

Homebrew已验证 · 100%
brew install nuget

local Homebrew formula metadata

Windows

Scoop已验证 · 92%
scoop install main/nuget

Scoop official bucket manifest trees · bucket/nuget.json · 来源: api.github.com

Windows Package Manager已验证 · 92%
winget install --id Microsoft.NuGet -e

Windows Package Manager source index · Microsoft.NuGet · 来源: cdn.winget.microsoft.com

概览

软件包摘要

Package manager for Microsoft development platform including .NET

命令和别名

  • nuget

历史

项目历史与用法

NuGet is the canonical package manager for the Microsoft .NET ecosystem: a client toolchain, package format, public gallery, and set of repository conventions for creating, publishing, restoring, and consuming .NET libraries.

项目历史

The project began in 2010 as NuPack in the ASP.NET / Microsoft web tooling orbit. Phil Haack's October 6, 2010 announcement described it as an open source, developer-focused package manager for simplifying third-party library use in .NET applications, and said the Outercurve Foundation had accepted the project into the ASP.NET Open Source Gallery.

The NuPack name was quickly changed. Haack's October 21, 2010 post opened public voting on replacement names, and his October 29, 2010 follow-up announced NuGet as the winner. That rename is part of NuGet lore because it tied the package manager's identity to community input before the project settled into the .NET platform.

采用历史

NuGet solved a very visible .NET pain point: finding libraries, adding assembly references, putting files in predictable project locations, applying config transforms, and updating dependencies. A November 2011 MSDN Magazine article presented NuGet as the rescue path from manual library download and reference management, and noted that ASP.NET MVC 3 already included it.

NuGet's adoption is structural rather than just CLI popularity. Microsoft Learn describes NuGet packages as .nupkg zip files carrying compiled code, related files, and manifest metadata; package authors publish them to public or private hosts, while consumers add them to projects and call the package functionality from application code. NuGet.org is the central public repository for that workflow.

Homebrew packages the standalone `nuget` command for macOS/Linux users outside Visual Studio. The Homebrew formula showed stable version 7.6.0 and 26,865 installs over the 365-day analytics window visible on July 1, 2026.

使用方式

Package nerds use NuGet in three overlapping ways: `nuget.exe` for pack/push/restore workflows, Visual Studio's package manager UI and console for project work, and modern SDK/MSBuild restore paths for repeatable CI. The important artifact is the `.nupkg`, whose ID, semantic version, dependencies, target framework assets, metadata, and source repository fields become part of the .NET dependency graph.

Practical usage is not only installing public packages. Organizations run private NuGet feeds for internal libraries, mirror/cache packages for build reproducibility, pin or float versions through project files and lock files, and publish prerelease packages from CI before promoting stable versions to nuget.org or an internal feed.

为什么软件包爱好者会关心

NuGet is infrastructure for the .NET supply chain. It defines the default package unit, public distribution hub, and restore semantics for a large share of .NET application builds, which makes it comparable in ecosystem role to npm for JavaScript or PyPI/pip for Python.

时间线

  • 2010-10-06: NuPack/NuGet announced as an open source .NET package manager accepted by the Outercurve Foundation into the ASP.NET Open Source Gallery.
  • 2010-10-21: NuPack rename vote opened.
  • 2010-10-29: NuGet announced as the selected name.
  • 2011-11: MSDN Magazine documented NuGet's package-install, update, and PowerShell-console workflows for Visual Studio users.

Related projects

  • NuGet Gallery
  • NuGet.Client
  • NuGet/Home
  • .NET SDK restore
  • MSBuild

安全态势

风险级别:orange

infrastructure mutation or orchestration signal.

风险分类器

orange 风险 · 中 置信度 · infrastructure

原因

  • infrastructure mutation or orchestration signal

信号

  • text:package manager

安装行为

  • formula 元数据中未记录 Homebrew post-install 钩子。
  • Homebrew bottle 元数据适用于 1 个平台目标。
  • 安装时包含 1 个运行时依赖。

建议审查

在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.nuget/NuGet/NuGet.Config~/.config/NuGet/NuGet.Config

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
~/.nuget/NuGet/NuGet.Config~/.config/NuGet/NuGet.Config

可执行文件

已安装的可执行文件

命令类型暴露范围备注
nugetcli全局可执行文件

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-07-26
管理器版本7.6.0
管理器更新时间2026-05-14
本地数据OK
上游not checked
检测到的最新版本未检测到

https://www.nuget.org/

安装元数据

软件包元数据

软件包键brew:nuget
版本7.6.0
软件包管理器Homebrew
软件包管理器页面https://formulae.brew.sh/formula/nuget
主页https://www.nuget.org/
仓库https://github.com/NuGet/NuGet.Client
上游文档https://learn.microsoft.com/en-us/nuget
许可证MIT
源码归档https://dist.nuget.org/win-x86-commandline/v7.6.0/nuget.exe
最后更新2026-05-14T02:59:39Z
Pulseupdated
依赖mono
Bottle可用 (于 all)
Homebrew post-install未定义
服务未声明

注册表事实

源数据库详情

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namenuget
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

源数据库匹配

其他软件包管理器记录

匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。

Nix95%

nuget

nix profile install nixpkgs#nuget
  • normalized package name match
  • 匹配方式:Nuget
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/nu/nuget/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
dnf95%

nuget 2.8.7-24.fc44

Package manager for .Net/Mono development platform

http://nuget.org/

sudo dnf install nuget
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: i686
  • Source Package: nuget
  • 2 依赖
  • 2 提供
  • normalized package name match
  • 匹配方式:Nuget
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: nuget from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
dnf95%

nuget-devel 2.8.7-24.fc44

Development files for nuget

http://nuget.org/

sudo dnf install nuget-devel
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: i686
  • Source Package: nuget
  • 2 依赖
  • 2 提供
  • normalized package name match
  • 匹配方式:Nuget
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: nuget-devel from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
pacman95%

nuget 6.11.1-1

Package manager for .NET.

https://www.nuget.org

sudo pacman -S nuget
  • License: APACHE
  • Architecture: any
  • 2 依赖
  • normalized package name match
  • 匹配方式:Nuget
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: nuget from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
Scoop95%

main/nuget

scoop install main/nuget
  • normalized package name match
  • 匹配方式:Nuget
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/nuget.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
winget95%

Microsoft.NuGet

winget install --id Microsoft.NuGet -e
  • normalized package name match
  • 匹配方式:Nuget
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: Microsoft.NuGet from https://cdn.winget.microsoft.com/cache/source.msix

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated agent safety answer
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment