pkg.sopackage field notes

brew / 順位 9167

bomber を Homebrew でインストール

bomber のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install bomber

provider-native install command

概要

パッケージ概要

Scans Software Bill of Materials for security vulnerabilities

コマンドとエイリアス

  • bomber

履歴

プロジェクトの歴史と使われ方

bomber is a DevSecOps command-line scanner for Software Bill of Materials files. It reads CycloneDX, SPDX, and Syft SBOMs and checks listed components against vulnerability providers.

プロジェクトの歴史

The Git repository begins in July 2022, with the first tagged public release following in August 2022. The README describes the project as a response to a practical SBOM question: after receiving a vendor SBOM for closed-source software, users need a fast way to identify component vulnerabilities and license risk.

The project evolved through v0.3 and v0.4 releases in 2022 and 2023, then v0.5 in 2024. Its README labels the project beta while documenting a broad feature set around providers, output formats, ignore lists, severity filtering, data enrichment, and CI-friendly stdin scanning.

採用の歴史

bomber belongs to the post-SBOM-surge security tooling ecosystem. The input package metadata lists Homebrew plus Linux distribution packages, MacPorts, Pacman, Ubuntu, and zypper, reflecting adoption as a portable security CLI rather than a library embedded in applications.

使われ方

Typical use is `bomber scan` against one SBOM file or a directory of SBOMs. The README documents OSV as the default no-credential provider, with optional GitHub Advisory Database, Sonatype OSS Index, and Snyk providers, plus stdout, HTML, JSON, and Markdown output modes.

パッケージ好きにとっての重要性

bomber is package-nerd relevant because it treats package metadata itself as the object of security analysis. It sits downstream of SBOM generators such as Syft and normalizes vulnerability lookup across package ecosystems and advisory providers.

タイムライン

  • 2022-07-08: Initial repository commit.
  • 2022-08-22: v0.1.0 tag and initial public version.
  • 2022-09-19: v0.3.0 tag appears during rapid early development.
  • 2023-12-13: v0.4.8 tag appears.
  • 2024-08-15: v0.5.0 tag appears.
  • 2024-09-23: v0.5.1 tag appears.

Related projects

  • CycloneDX, SPDX, and Syft are documented input SBOM formats.
  • OSV, GitHub Advisory Database, Sonatype OSS Index, and Snyk are documented vulnerability providers.
  • Syft is a common companion tool because it can generate an SBOM and pipe it directly into bomber.

セキュリティ状態

リスクレベル: グリーン

narrow executable package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

インストール挙動

  • Homebrew bottle メタデータは記録されていません。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
bomber実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-08-03
マネージャ版0.5.1
マネージャ更新日2026-07-25
ローカルデータ不明
上流利用不可
検出された最新未検出
  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:bomber
バージョン0.5.1
パッケージマネージャHomebrew
ホームページhttps://devops-kung-fu.github.io/bomber/
リポジトリhttps://github.com/devops-kung-fu/bomber
最終更新2026-07-25T14:19:44-04:00
Pulseupdated
Bottle未記録
サービス宣言なし

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • curated package history
  • pkgdb category and tag curation