pkg.soopen package index

brew / Rang 2704

ko mit Homebrew, apk, MacPorts, Nix, pacman, scoop installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für ko in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install ko

local Homebrew formula metadata

MacPortsverifiziert · 94%
sudo port install ko

MacPorts ports tree · devel/ko/Portfile · Quelle: api.github.com

Windows

Scoopverifiziert · 92%
scoop install main/ko

Scoop official bucket manifest trees · bucket/ko.json · Quelle: api.github.com

Überblick

Paketzusammenfassung

Build and deploy Go applications on Kubernetes

Befehle und Aliase

  • ko

Verlauf

Projektgeschichte und Nutzung

ko is a Go-focused container image builder for developers who want OCI images without writing Dockerfiles or running Docker locally. Its Homebrew package is a small CLI, but it sits at the intersection of Go modules, Kubernetes manifests, registries, SBOMs, and supply-chain tooling.

Projektgeschichte

The project grew out of Google experience building Docker and Kubernetes support for Bazel. Its README describes ko as a simple, fast container image builder that effectively runs `go build` locally, then packages the resulting binary into an image without requiring Docker.

By 2022, the project had moved into the ko-build GitHub organization and the ko.build documentation domain. A 2022-08-19 migration issue laid out the repository move from google/ko to github.com/ko-build, the ko.build vanity import path, image-name changes, and a Slack channel rename. On 2022-10-11, Google announced that it had submitted ko for CNCF Sandbox consideration.

Adoptionsgeschichte

ko's adoption followed the rise of Go-based cloud-native services that can ship as mostly static binaries. The Google Open Source announcement described growing use by open source and enterprise teams and integration into third-party CI/CD tools.

Package-manager adoption is useful because ko is often installed in developer shells, GitHub Actions, release jobs, and Kubernetes workflows. Its companion setup-ko action made it easy to bootstrap the CLI in CI, while Homebrew, MacPorts, Nix, Arch, Alpine, and Scoop packaging made it available outside a single vendor ecosystem.

Wie es verwendet wird

The common workflow is `ko build` or `ko resolve`: build Go packages into images, push them to a registry, and optionally rewrite Kubernetes YAML with the produced image references. The docs emphasize no Docker daemon requirement, multi-platform images, SBOM generation, Kubernetes integration, build cache support, and registry authentication through ko login or surrounding CI credentials.

It is particularly attractive for Go services with few operating-system package dependencies. That constraint is part of the tool's appeal: it turns the boring case of a static Go binary into a very short path from source to signed or traceable container artifact.

Warum Paket-Nerds sich dafür interessieren

ko is the package-index shorthand for a whole cloud-native philosophy: build the thing the language already knows how to build, then wrap it as an OCI image with minimal ceremony. It competes less with Docker itself than with Dockerfile boilerplate, bespoke CI shell scripts, and build-system plugins.

For maintainers, it is also a clean example of a single-purpose CLI whose value comes from integration points: Go, registries, Kubernetes, SBOMs, GitHub Actions, and module import paths.

Zeitleiste

  • 2022-02-17: ko v0.10.0 was published; ko docs note that before v0.10 the command was called `ko publish`.
  • 2022-08-19: The project opened a migration issue for moving from google/ko to github.com/ko-build and ko.build.
  • 2022-08-24: ko v0.12.0 was published during the repository/domain migration period.
  • 2022-10-11: Google announced that ko had been submitted for CNCF Sandbox consideration.

Related projects

  • ko is related to go-containerregistry, setup-ko, Skaffold's ko builder integration, Docker/BuildKit workflows, Kubernetes deployment tooling, and Bazel container rules that influenced the original design.

Sicherheitslage

Risikostufe: orange

infrastructure mutation or orchestration signal.

Risikoklassifikator

orange Risiko · mittel Konfidenz · infrastructure

Warum

  • infrastructure mutation or orchestration signal

Signale

  • text:kubernetes

Installationsverhalten

  • Es wurden keine Homebrew-Bottle-Metadaten erfasst.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
.ko.yaml

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
koExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-08-03
Manager-Version0.19.1
Manager aktualisiert2026-07-27
lokale Datenunbekannt
Upstreamnicht verfügbar
neueste erkannte Versionnicht erkannt
  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:ko
Version0.19.1
PaketmanagerHomebrew
Homepagehttps://ko.build
Repositoryhttps://github.com/ko-build/ko
Zuletzt aktualisiert2026-07-27T21:58:40+02:00
Pulseupdated
Bottlenicht erfasst
Dienstkeiner deklariert

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

ko

nix profile install nixpkgs#ko
  • normalized package name match
  • Abgeglichen nach: Ko
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ko/ko/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

ko 0.17.1-r16

Build containers from Go projects

https://ko.build/

sudo apk add ko
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: ko
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Ko
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: ko from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

ko-bash-completion 0.17.1-r16

Bash completions for ko

https://ko.build/

sudo apk add ko-bash-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: ko
  • normalized package name match
  • Abgeglichen nach: Ko
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: ko-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

ko-fish-completion 0.17.1-r16

Fish completions for ko

https://ko.build/

sudo apk add ko-fish-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: ko
  • normalized package name match
  • Abgeglichen nach: Ko
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: ko-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

ko-zsh-completion 0.17.1-r16

Zsh completions for ko

https://ko.build/

sudo apk add ko-zsh-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: ko
  • normalized package name match
  • Abgeglichen nach: Ko
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: ko-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
pacman95%

ko 0.19.1-1

Build and deploy Go container images

https://github.com/ko-build/ko

sudo pacman -S ko
  • License: Apache-2.0
  • Architecture: x86_64
  • 1 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Ko
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: ko from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

ko

sudo port install ko
  • normalized package name match
  • Abgeglichen nach: Ko
MacPorts ports tree · api.github.com · MacPorts ports tree: devel/ko/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Scoop95%

main/ko

scoop install main/ko
  • normalized package name match
  • Abgeglichen nach: Ko
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/ko.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Combined YAML source

View the package source record on GitHub.

combined/ko.yml

Verwendete Quellen

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation