pkg.soopen package index

brew / Rang 7761

legitify mit Homebrew, Nix installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für legitify in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install legitify

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#legitify

nixpkgs package indexes · pkgs/by-name/le/legitify/package.nix · Quelle: api.github.com

Überblick

Paketzusammenfassung

Tool to detect/remediate misconfig and security risks of GitHub/GitLab assets

Befehle und Aliase

  • legitify

Verlauf

Projektgeschichte und Nutzung

Legitify is Legit Security's open-source CLI for finding and helping remediate security, compliance, and misconfiguration risks across GitHub and GitLab assets.

Projektgeschichte

Legit Security announced Legitify on 2022-10-05 as an open-source GitHub configuration scanner for security, DevOps, and developer teams. The repository and project site later described the scope as source-code-management posture across GitHub and GitLab assets, with built-in policies and remediation-oriented output.

Adoptionsgeschichte

The project was packaged as a standalone CLI, GitHub Action, Homebrew formula, Nix package, and GitHub CLI extension. That mix made it fit both one-off audits from a workstation and scheduled checks in CI for organizations managing many repositories, members, teams, runners, branch protections, and tokens.

Wie es verwendet wird

Typical usage is to authenticate to GitHub or GitLab, run `legitify analyze`, and review policy findings against repositories, organizations, runners, webhooks, actions, branch protection, and other SCM resources. Its Homebrew packaging matters because security teams can hand developers a familiar install path instead of a vendor-only SaaS workflow.

Warum Paket-Nerds sich dafür interessieren

Legitify is a package-nerd example of application-security posture management ideas escaping into a plain CLI. It packages policy checks and remediation hints as a tool that can live in local shells, CI jobs, and GitHub Actions, adjacent to linters and secret scanners.

Zeitleiste

  • 2022-07-26: The GitHub issue tracker showed early public project activity.
  • 2022-10-05: Legit Security published the introductory Legitify announcement.
  • 2023-01-19: Public issues tracked expansion into third-party application policies.
  • 2023-02-06: Public issues tracked auto-remediation work.

Related projects

  • Related projects include the `gh-legitify` GitHub CLI extension, the Legitify GitHub Action, OpenSSF Scorecard, GitHub Advanced Security configuration checks, GitLab security scanners, and policy-as-code tools used for SCM governance.

Sicherheitslage

Risikostufe: blue

broad file, network, media, or database tool signal.

Risikoklassifikator

blue Risiko · mittel Konfidenz · tool

Warum

  • broad file, network, media, or database tool signal

Signale

  • text:media

Installationsverhalten

  • Es wurden keine Homebrew-Bottle-Metadaten erfasst.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
legitifyExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-08-03
Manager-Version1.0.11
Manager aktualisiert2026-07-26
lokale Datenunbekannt
Upstreamnicht verfügbar
neueste erkannte Versionnicht erkannt
  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:legitify
Version1.0.11
PaketmanagerHomebrew
Homepagehttps://legitify.dev/
Repositoryhttps://github.com/Legit-Labs/legitify
Zuletzt aktualisiert2026-07-26T13:41:01+02:00
Pulseupdated
Bottlenicht erfasst
Dienstkeiner deklariert

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

legitify

nix profile install nixpkgs#legitify
  • normalized package name match
  • Abgeglichen nach: Legitify
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/le/legitify/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation