pkg.sopackage field notes

brew / Rang 6213

xxh mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für xxh in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install xxh

provider-native install command

Überblick

Paketzusammenfassung

Bring your favorite shell wherever you go through the ssh

Befehle und Aliase

  • xxh
  • xxh.bash
  • xxh.xsh
  • xxh.zsh

Verlauf

Projektgeschichte und Nutzung

xxh is a remote-shell portability tool for people who want their own shell, aliases, plugins, and terminal habits when connecting through SSH. Its niche is not replacing OpenSSH transport; it wraps the SSH workflow so a prepared, removable userland can be uploaded to a remote Linux host without root access or permanent system installation.

Projektgeschichte

The project grew out of a common dotfile and remote-login annoyance: a heavily customized local shell disappears when a user logs in to an unfamiliar server. The README frames xxh around that problem and around the goal of bringing shells such as xonsh, zsh, fish, bash, and osquery to remote hosts.

The design evolved around small, forkable shell and plugin packages. Instead of copying a user's private dotfiles wholesale, xxh encourages reusable shell entrypoints and prerun plugins, so a remote environment can be assembled locally, uploaded, used, and removed by deleting the remote .xxh directory.

Adoptionsgeschichte

xxh adoption has been strongest in the remote-development and shell-customization niche rather than in base operating systems. Its README lists Python package installation, pipx, conda-forge, Homebrew, MacPorts, portable Linux archives, and AppImage as distribution paths, reflecting a tool aimed at users who move between many hosts and package ecosystems.

The surrounding plugin repositories are part of the adoption story: zsh and fish integrations, Oh My Zsh and Oh My Fish support, Powerlevel10k, starship, vim, zoxide, Docker, Python, and dotfiles plugins show the project being used as a portable terminal-environment framework rather than a single binary.

Wie es verwendet wird

In practice, users invoke xxh where they would normally invoke ssh, preserving ordinary SSH arguments while adding xxh-specific options with plus-prefixed flags. Common workflows include selecting a shell for a host, preinstalling plugins, forcing a remote reinstall, choosing the remote home/hermetic level, or using seamless mode from the local shell.

The package is useful when a developer has access to many Linux hosts but cannot install packages globally, wants a familiar shell on ephemeral machines, or needs a repeatable remote command environment without leaving long-lived files behind.

Warum Paket-Nerds sich dafür interessieren

xxh is package-nerd interesting because it packages a personal environment rather than just a program. It sits at the intersection of SSH, dotfiles, shell frameworks, portable binaries, and plugin packaging, making explicit the messy work many developers otherwise solve with ad hoc scp, curl, and bootstrap scripts.

Its plus-option convention and forkable package model also show a pragmatic packaging lesson: when a wrapper must pass through the native tool's flags, namespacing the wrapper's own options keeps the command line usable.

Zeitleiste

  • 2019: Public discussion and package pages show xxh being promoted as a way to bring zsh, Oh My Zsh, and other shells through SSH without root access on the host.
  • 2020: Homebrew, MacPorts, conda-forge, pip, pipx, AppImage, and portable Linux archive installation paths are documented in the project README.
  • 2020s: The shell and plugin ecosystem grows around xonsh, zsh, fish, bash, osquery, prerun plugins, and cookiecutter templates for new plugins.

Related projects

  • OpenSSH is the underlying transport and user-facing model that xxh wraps rather than replaces.
  • xonsh, zsh, fish, bash, and osquery are supported shell entrypoints in the xxh ecosystem.
  • Oh My Zsh, Oh My Fish, Powerlevel10k, starship, zoxide, vim, and Docker appear as examples of portable shell and prerun plugin targets.

Sicherheitslage

Risikostufe: yellow

broad file, network, media, or database tool signal. generalized runtime or code generation signal.

Risikoklassifikator

yellow Risiko · mittel Konfidenz · runtime

Warum

  • broad file, network, media, or database tool signal
  • generalized runtime or code generation signal

Signale

  • text:shell
  • text:ssh

Installationsverhalten

  • Es wurden keine Homebrew-Bottle-Metadaten erfasst.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.config/xxh/config.xxhc

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
xxhExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.
xxh.bashExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.
xxh.xshExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.
xxh.zshExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-08-03
Manager-Version0.8.14
Manager aktualisiert
lokale Datenunbekannt
Upstreamnicht verfügbar
neueste erkannte Versionnicht erkannt
  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:xxh
Version0.8.14
PaketmanagerHomebrew
Homepagehttps://github.com/xxh/xxh
Bottlenicht erfasst
Dienstkeiner deklariert

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation