pkg.sopackage field notes

brew / Rang 2895

cpio mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für cpio in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install cpio

provider-native install command

Überblick

Paketzusammenfassung

Copies files into or out of a cpio or tar archive

Befehle und Aliase

  • cpio

Verlauf

Projektgeschichte und Nutzung

GNU cpio is the GNU implementation of the classic copy-in/copy-out archiver. It copies files between directories and archives, including cpio formats and tar formats, and remains a small but important Unix packaging and recovery tool.

Projektgeschichte

GNU cpio's manual is published by the Free Software Foundation and documents the program as a tool for creating and extracting archives or copying directory trees. The manual credits Robert Carleton and Sergey Poznyakoff, and the current GNU source package includes documentation maintained through the 2.15 release.

The GNU package history visible in NEWS shows long-running maintenance around archive-format compatibility, large-file support, security fixes, reproducible archive options, and portability fixes. Version 2.0 added SVR4 cpio formats and traditional/POSIX tar archive support; later releases added sparse handling, GPLv3 licensing, reproducible archive support, and security fixes.

Adoptionsgeschichte

The supplied package facts list GNU cpio across common Unix-like package managers, including Debian, Ubuntu, Fedora/dnf, Alpine/apk, Arch/pacman, openSUSE/zypper, Nix, MacPorts, Homebrew, and a GnuWin32 package. That breadth matches cpio's role as a standard archive utility rather than an application-level tool.

Wie es verwendet wird

GNU cpio has three primary modes: copy-out to create archives from file lists, copy-in to extract archives, and copy-pass to copy directory trees. The manual emphasizes pipelines with find or ls, archive media such as disk files, tapes, and pipes, and compatibility with multiple cpio and tar formats.

Warum Paket-Nerds sich dafür interessieren

Package maintainers care about cpio because it is both a user-facing archive command and an old archive format that still appears in build systems, initramfs tooling, backups, and historical Unix data. GNU cpio's NEWS also matters to distributors because it records CVE fixes, reproducibility options, and large-file behavior changes.

Zeitleiste

  • 1996: GNU FTP archive lists cpio 2.4.2.
  • 2007: Version 2.9 switched GNU cpio to GPLv3.
  • 2015: Version 2.12 added --reproducible archive support.
  • 2019: Version 2.13 fixed CVE-2015-1197, CVE-2016-2037, and CVE-2019-14866.
  • 2024: Version 2.15 fixed copy-in and --no-absolute-filenames behavior.

Related projects

  • GNU tar is related through archive-format compatibility.
  • GNU find is commonly paired with cpio to provide file lists.

Sicherheitslage

Risikostufe: blue

broad file, network, media, or database tool signal.

Risikoklassifikator

blue Risiko · mittel Konfidenz · tool

Warum

  • broad file, network, media, or database tool signal

Signale

  • text:archive

Installationsverhalten

  • Es wurden keine Homebrew-Bottle-Metadaten erfasst.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
cpioExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-08-03
Manager-Version2.15
Manager aktualisiert
lokale Datenunbekannt
Upstreamnicht verfügbar
neueste erkannte Versionnicht erkannt
  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:cpio
Version2.15
PaketmanagerHomebrew
Homepagehttps://www.gnu.org/software/cpio/
Bottlenicht erfasst
Dienstkeiner deklariert

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • curated package history
  • pkgdb category and tag curation