pkg.sopackage field notes

brew / Rang 282

kubeconform mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für kubeconform in AI-Agent-Workflows.

Agent-Sicherheit

Antwort zur Agent-Sicherheit

kubeconform validates Kubernetes manifests and may read deployment configuration.

Credential-Zugriff

Reads manifest files that may include secret references or generated values.

Änderungen an Remote-Zustand

Validation is local and does not mutate clusters.

Publish-/Artefakt-Risiko

Can validate deployable artifacts before cluster application.

Empfohlene Kontrolle

Gate only when scanning secret-bearing files or feeding apply pipelines.

Hinweise für Agent-Nutzung

Allow local validation; require approval before passing output into deployment commands.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install kubeconform

provider-native install command

Überblick

Paketzusammenfassung

FAST Kubernetes manifests validator, with support for Custom Resources!

Befehle und Aliase

  • kubeconform

Verlauf

Projektgeschichte und Nutzung

Kubeconform is a Kubernetes manifest validator that grew out of the Kubeval lineage: its own documentation says it is inspired by, contains code from, and is designed to stay close to Kubeval while adding higher-throughput validation, configurable schema locations, CRD support, offline validation, and a schema registry fork for recent Kubernetes versions.

Projektgeschichte

The GitHub repository was created on 2020-05-30. The public documentation feed dates the overview, installation, usage, CRD support, JSON Schema conversion, GitHub Action, and Go-module documentation pages to 2021-07-02, which matches the period when the project presented itself as a standalone replacement for common Kubeval workflows.

Kubeconform kept the Unix-style single-binary validator shape that made Kubeval popular in CI, but its distinguishing evolution was schema flexibility: users can validate against Kubernetes versions, local or remote schema locations, and converted CRD schemas rather than only core Kubernetes resources.

Adoptionsgeschichte

Adoption has been strongest in CI/CD and GitOps-adjacent workflows where teams want to fail manifest changes before applying them to a cluster. The tool's package-manager footprint across Homebrew, Linux distributions, Windows package managers, and Nix reflects a cross-platform CLI audience rather than a cluster-installed controller audience.

The repository metadata observed on 2026-07-01 showed more than 3000 GitHub stars, making it one of the better-known third-party Kubernetes manifest validators outside kubectl itself.

Wie es verwendet wird

Typical use is to pass files, directories, or stdin to `kubeconform`, optionally choosing output such as text, JSON, JUnit, or TAP and enabling summary output for CI logs. For custom resources, users point `-schema-location` at local or HTTP(S) JSON schemas, or convert CRDs to JSON Schema with the project-provided conversion tooling.

The package matters in validation pipelines because it gives maintainers a fast, scriptable check for Kubernetes resource structure without needing live cluster access.

Warum Paket-Nerds sich dafür interessieren

For package-manager users, Kubeconform is the kind of small Go CLI that fits neatly into `brew install`, CI images, pre-commit hooks, and reproducible Nix shells. Its significance is not a broad runtime platform but a sharp replacement-class tool for a once-common Kubernetes validation gap.

Zeitleiste

  • 2020-05-30: GitHub repository created.
  • 2021-07-02: Documentation pages published for overview, installation, usage, CRD support, JSON Schema conversion, GitHub Action usage, and Go-module usage.
  • 2024-07-30: Release v0.6.7 published.
  • 2025-05-12: Release v0.7.0 published.
  • 2026-06-04: Release v0.8.0 published.

Related projects

  • Kubeval is the direct predecessor named by the Kubeconform documentation. The kubernetes-json-schema registry is part of the validation ecosystem because Kubeconform uses JSON schemas for Kubernetes resources and supports schema-location overrides for CRDs.

Sicherheitslage

Risikostufe: orange

infrastructure mutation or orchestration signal.

Risikoklassifikator

orange Risiko · mittel Konfidenz · infrastructure

Warum

  • infrastructure mutation or orchestration signal

Signale

  • text:kubernetes

Installationsverhalten

  • Es wurden keine Homebrew-Bottle-Metadaten erfasst.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
kubeconformExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-08-03
Manager-Version0.8.0
Manager aktualisiert2026-07-27
lokale Datenunbekannt
Upstreamnicht verfügbar
neueste erkannte Versionnicht erkannt
  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:kubeconform
Version0.8.0
PaketmanagerHomebrew
Homepagehttps://github.com/yannh/kubeconform
Repositoryhttps://github.com/yannh/kubeconform
Zuletzt aktualisiert2026-07-27T21:58:44+02:00
Pulseupdated
Bottlenicht erfasst
Dienstkeiner deklariert

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • curated agent safety answer
  • curated package history
  • pkgdb category and tag curation