pkg.soopen package index

brew / Rang 5720

poutine mit Homebrew, Nix installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für poutine in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install poutine

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#poutine

nixpkgs package indexes · pkgs/by-name/po/poutine/package.nix · Quelle: api.github.com

Überblick

Paketzusammenfassung

Security scanner that detects vulnerabilities in build pipelines

Befehle und Aliase

  • poutine

Verlauf

Projektgeschichte und Nutzung

poutine is an open-source CLI security scanner for CI/CD definitions and software build pipelines.

Projektgeschichte

BoostSecurity.io created poutine to find security weaknesses and misconfigurations in build pipelines. Its name alludes both to the Montréal dish and the French use of “poutine” for something messy, reflecting the complexity of modern software-supply chains.

Adoptionsgeschichte

The project supports scanning GitHub Actions, GitLab CI/CD, Azure DevOps, and Tekton Pipelines as Code. It is distributed as a standalone binary, Homebrew formula, container image, and GitHub Action.

Wie es verwendet wird

Users run poutine against a local checkout, a remote repository, or all repositories in an organization. Repository and organization scans accept SCM access tokens through command options or variables such as GH_TOKEN and GL_TOKEN.

Configuration is auto-discovered from .poutine.yml or .github/poutine.yml, with the root file taking precedence. The separate ~/.poutine/config.yaml file stores the anonymous identifier used by the optional version check; it is not a credentials file.

Warum Paket-Nerds sich dafür interessieren

poutine represents the newer generation of policy-aware supply-chain tools packaged as ordinary developer CLIs. Its support for SARIF, organization-wide scans, and custom Rego rules makes it useful both locally and in automated security pipelines.

Zeitleiste

  • Public project era: Released by BoostSecurity.io as an Apache-2.0-licensed build-pipeline scanner.
  • Later development: Added multiple CI platforms, SARIF output, custom Rego rules, acknowledgement filters, and MCP integration.

Related projects

  • boostsecurityio/poutine-action packages the scanner for GitHub Actions.
  • Custom checks use Rego, the policy language associated with Open Policy Agent.

Sicherheitslage

Risikostufe: grün

narrow executable package without higher-risk signals.

Risikoklassifikator

grün Risiko · niedrig Konfidenz · appliance

Warum

  • narrow executable package without higher-risk signals

Signale

  • metadata:no-higher-risk-signals

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
.poutine.yml.github/poutine.yml~/.poutine/config.yaml

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
poutinecliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-09-19
Manager-Version1.1.6
Manager aktualisiert2026-09-13
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv1.1.6

https://github.com/boostsecurityio/poutine

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:poutine
Version1.1.6
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/poutine
Homepagehttps://boostsecurityio.github.io/poutine/
Repositoryhttps://github.com/boostsecurityio/poutine
Upstream-Dokumentationhttps://boostsecurityio.github.io/poutine/
LizenzApache-2.0
Quellarchivhttps://github.com/boostsecurityio/poutine/archive/refs/tags/v1.1.6.tar.gz
Zuletzt aktualisiert2026-09-13T12:01:57Z
Pulseupdated
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namepoutine
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

poutine

nix profile install nixpkgs#poutine
  • normalized package name match
  • Abgeglichen nach: Poutine
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/po/poutine/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation