pkg.sopackage field notes

brew / Rang 7472

flawz mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für flawz in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install flawz

provider-native install command

Überblick

Paketzusammenfassung

Terminal UI for browsing security vulnerabilities (CVEs)

Befehle und Aliase

  • flawz

Verlauf

Projektgeschichte und Nutzung

flawz is a Rust terminal user interface for browsing CVE security vulnerability data. It packages NVD-backed vulnerability search into a local CLI/TUI workflow with SQLite storage, theming, offline use, and optional NVD API-key acceleration.

Projektgeschichte

The upstream GitHub repository was created in 2024. The README presents flawz as a terminal UI for browsing security vulnerabilities, using NIST's NVD as the default vulnerability database and offering search, listing, theming, and details views in the terminal.

The release stream began with v0.1.0 in May 2024 and reached v0.4.1 in June 2026, according to the official GitHub releases API.

Adoptionsgeschichte

The official README documents installation through Cargo, Arch Linux official repositories, Alpine Edge, Homebrew, Nixpkgs unstable, NetBSD pkgsrc, binary releases, and source builds. That unusually broad package-manager list for a young Rust TUI reflects quick adoption by distribution packagers interested in CVE tooling.

Wie es verwendet wird

flawz syncs NVD feeds into a SQLite database, accepts year ranges and recent or modified feeds, and can start directly on a query such as an xz CVE search. Users can pass an NVD API key with `--api-key` or `NVD_API_KEY` for higher NVD rate limits, choose themes, and use offline mode against cached data.

Warum Paket-Nerds sich dafür interessieren

flawz is package-nerd relevant because it combines several current CLI trends in one small package: Rust distribution through crates.io and native package managers, terminal UI ergonomics, local SQLite caching, and security metadata browsing tied to the NVD feed ecosystem.

Zeitleiste

  • 2024: GitHub repository created.
  • 2024: v0.1.0 released on May 18.
  • 2024: v0.3.0 released on November 3.
  • 2026: v0.4.0 and v0.4.1 released on June 13.

Related projects

  • NVD and NIST provide the default vulnerability database used by flawz.
  • crates.io, docs.rs, Cargo, Arch Linux, Alpine, Homebrew, Nixpkgs, NetBSD pkgsrc, and SQLite are part of the documented packaging and runtime context.

Sicherheitslage

Risikostufe: grün

narrow executable package without higher-risk signals.

Risikoklassifikator

grün Risiko · niedrig Konfidenz · appliance

Warum

  • narrow executable package without higher-risk signals

Signale

  • metadata:no-higher-risk-signals

Installationsverhalten

  • Es wurden keine Homebrew-Bottle-Metadaten erfasst.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
flawzExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-08-03
Manager-Version0.4.1
Manager aktualisiert2026-06-14
lokale Datenunbekannt
Upstreamnicht verfügbar
neueste erkannte Versionnicht erkannt
  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:flawz
Version0.4.1
PaketmanagerHomebrew
Homepagehttps://github.com/orhun/flawz
Repositoryhttps://github.com/orhun/flawz
Zuletzt aktualisiert2026-06-14T05:08:26Z
Pulseupdated
Bottlenicht erfasst
Dienstkeiner deklariert

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • curated package history
  • pkgdb category and tag curation