pkg.sopackage field notes

brew / rang 2701

Installer ko avec Homebrew

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de ko pour les workflows d'agents IA.

installation

Commandes d'installation supplémentaires

macOS

Homebrewvérifié · 100%
brew install ko

provider-native install command

aperçu

Résumé du paquet

Build and deploy Go applications on Kubernetes

Commandes et alias

  • ko

historique

Historique du projet et usages

ko is a Go-focused container image builder for developers who want OCI images without writing Dockerfiles or running Docker locally. Its Homebrew package is a small CLI, but it sits at the intersection of Go modules, Kubernetes manifests, registries, SBOMs, and supply-chain tooling.

Historique du projet

The project grew out of Google experience building Docker and Kubernetes support for Bazel. Its README describes ko as a simple, fast container image builder that effectively runs `go build` locally, then packages the resulting binary into an image without requiring Docker.

By 2022, the project had moved into the ko-build GitHub organization and the ko.build documentation domain. A 2022-08-19 migration issue laid out the repository move from google/ko to github.com/ko-build, the ko.build vanity import path, image-name changes, and a Slack channel rename. On 2022-10-11, Google announced that it had submitted ko for CNCF Sandbox consideration.

Historique d'adoption

ko's adoption followed the rise of Go-based cloud-native services that can ship as mostly static binaries. The Google Open Source announcement described growing use by open source and enterprise teams and integration into third-party CI/CD tools.

Package-manager adoption is useful because ko is often installed in developer shells, GitHub Actions, release jobs, and Kubernetes workflows. Its companion setup-ko action made it easy to bootstrap the CLI in CI, while Homebrew, MacPorts, Nix, Arch, Alpine, and Scoop packaging made it available outside a single vendor ecosystem.

Modes d'utilisation

The common workflow is `ko build` or `ko resolve`: build Go packages into images, push them to a registry, and optionally rewrite Kubernetes YAML with the produced image references. The docs emphasize no Docker daemon requirement, multi-platform images, SBOM generation, Kubernetes integration, build cache support, and registry authentication through ko login or surrounding CI credentials.

It is particularly attractive for Go services with few operating-system package dependencies. That constraint is part of the tool's appeal: it turns the boring case of a static Go binary into a very short path from source to signed or traceable container artifact.

Pourquoi les passionnés de paquets s'y intéressent

ko is the package-index shorthand for a whole cloud-native philosophy: build the thing the language already knows how to build, then wrap it as an OCI image with minimal ceremony. It competes less with Docker itself than with Dockerfile boilerplate, bespoke CI shell scripts, and build-system plugins.

For maintainers, it is also a clean example of a single-purpose CLI whose value comes from integration points: Go, registries, Kubernetes, SBOMs, GitHub Actions, and module import paths.

Chronologie

  • 2022-02-17: ko v0.10.0 was published; ko docs note that before v0.10 the command was called `ko publish`.
  • 2022-08-19: The project opened a migration issue for moving from google/ko to github.com/ko-build and ko.build.
  • 2022-08-24: ko v0.12.0 was published during the repository/domain migration period.
  • 2022-10-11: Google announced that ko had been submitted for CNCF Sandbox consideration.

Related projects

  • ko is related to go-containerregistry, setup-ko, Skaffold's ko builder integration, Docker/BuildKit workflows, Kubernetes deployment tooling, and Bazel container rules that influenced the original design.

posture de sécurité

Niveau de risque : orange

infrastructure mutation or orchestration signal.

Classificateur de risque

risque orange · confiance moyen · infrastructure

Pourquoi

  • infrastructure mutation or orchestration signal

Signaux

  • text:kubernetes

Comportement d'installation

  • Aucune métadonnée de bottle Homebrew n’a été enregistrée.

Revue recommandée

Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
.ko.yaml

exécutables

Exécutables installés

CommandeTypeExpositionNote
koexécutableexécutable indexéDécouvert depuis l'index local des exécutables.

fraîcheur

Version et fraîcheur

Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.

page générée2026-08-03
version du gestionnaire0.19.1
gestionnaire mis à jour2026-07-27
données localesinconnu
amontnon disponible
dernière version détectéenon détecté
  • OKAucun avertissement de fraîcheur n'a été généré.

métadonnées d'installation

Métadonnées du paquet

Clé du paquetbrew:ko
Version0.19.1
Gestionnaire de paquetsHomebrew
Page d'accueilhttps://ko.build
Dépôthttps://github.com/ko-build/ko
Dernière mise à jour2026-07-27T21:58:40+02:00
Pulseupdated
Bouteillenon enregistré
Serviceaucun déclaré

piste source

Généré depuis les données du dépôt

Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.

Combined YAML source

View the package source record on GitHub.

combined/ko.yml

Sources utilisées

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation