# buf を Homebrew, apk, MacPorts, Nix, pacman, scoop, winget でインストール

buf のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

## インストール

```sh
sudo av install brew:buf
```

## エージェント安全性の回答

buf manages protobuf linting, generation, and registry workflows.

- **認証情報アクセス:** Reads registry tokens, environment variables, and project schema files.
- **リモート変更:** Can push modules and interact with remote schema registries.
- **公開/成果物リスク:** Can publish schema modules and generated artifacts.
- **推奨コントロール:** Gate push, registry login, and token-backed commands.
- **エージェント利用ガイダンス:** Allow lint/generate; require approval for registry writes and token use.

追加のインストールコマンド:

### macOS

- Homebrew (100%):

```sh
brew install buf
```

  証拠: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install buf
```

  証拠: MacPorts ports tree: devel/buf/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- apk (92%):

```sh
sudo apk add buf
```

  証拠: Alpine Linux edge package indexes: buf from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz

- Nix (92%):

```sh
nix profile install nixpkgs#buf
```

  証拠: nixpkgs package indexes: pkgs/by-name/bu/buf/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- pacman (92%):

```sh
sudo pacman -S buf
```

  証拠: Arch Linux sync databases: buf from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

### Windows

- Scoop (92%):

```sh
scoop install main/buf
```

  証拠: Scoop official bucket manifest trees: bucket/buf.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

- winget (92%):

```sh
winget install --id bufbuild.buf -e
```

  証拠: Windows Package Manager source index: bufbuild.buf from https://cdn.winget.microsoft.com/cache/source.msix

## パッケージ情報

- **パッケージキー:** brew:buf
- **パッケージマネージャ:** Homebrew
- **バージョン:** 1.72.0
- **ソース概要:** New way of working with Protocol Buffers
- **ホームページ:** <https://buf.build>
- **リポジトリ:** <https://github.com/bufbuild/buf>
- **最終更新:** 2026-07-26T10:56:35+02:00
- **生成日時:** 2026-08-03T19:37:03+00:00

## 実行可能ファイル

- buf (エイリアス)
- protoc-gen-buf-breaking (エイリアス)
- protoc-gen-buf-lint (エイリアス)

## インストール挙動

- Bottle: 利用不可

## バージョンと鮮度

- ページ生成日: 2026-08-03
- マネージャ版: 1.72.0
## プロジェクトの歴史と使われ方

Buf is a modern Protocol Buffers toolchain centered on the `buf` CLI, replacing many direct `protoc` workflows with module-aware builds, linting, breaking-change detection, formatting, code generation, dependency management, API calls, and access to the Buf Schema Registry.

### プロジェクトの歴史

Buf was created by Buf Technologies as a developer-tooling layer for Protobuf projects. Its public repository presents it as a modern toolchain for Protobuf rather than a replacement for the schema language itself: it keeps the plugin model familiar to `protoc` users while adding workspace configuration, deterministic checks, and registry-aware workflows.

The project grew beyond a formatter or wrapper into a broader ecosystem: the CLI, Buf Schema Registry, remote plugins, generated SDKs, ConnectRPC, Protobuf-ES, and Protovalidate are all positioned by Buf as related pieces of schema-driven API infrastructure.

### 採用の歴史

Buf adoption followed the pain points of larger Protobuf users: teams wanted one repeatable command for compiling, linting, compatibility checks, and generation instead of per-repository shell scripts around `protoc -I` paths. The CLI is distributed through Homebrew, npm, Docker, Windows installers, binary downloads, tarballs, source builds, and other package managers listed in the input.

Registry features widened its role from local CLI tooling to organization-level schema governance. The Buf Schema Registry stores modules, renders documentation, resolves dependencies, hosts remote plugins, produces generated SDKs, and can enforce schema checks for teams that publish APIs there.

### 使われ方

Typical CLI use starts with `buf config init`, then `buf build`, `buf format -w`, `buf lint`, `buf breaking --against ...`, and `buf generate`. Projects commonly check in `buf.yaml`, `buf.gen.yaml`, and `buf.lock` so CI and developer laptops run the same Protobuf workflow.

Core CLI features work without a Buf Schema Registry account, while signing in adds private module dependency resolution, remote plugins, generated SDKs, hosted documentation, and server-side checks.

### パッケージ好きにとっての重要性

Buf matters to package-tooling people because it treats `.proto` files as versioned modules instead of loose source files copied between repos. It brings package-lock and registry patterns familiar from language ecosystems into Protobuf schema distribution.

It is also a notable example of a package manager formula that installs not only the main `buf` binary but companion protoc plugins, making Homebrew a convenient entry point for Protobuf linting and compatibility checks.

### タイムライン

- 2020: Early public Buf releases established the CLI around Protobuf build, lint, breaking-change, and generation workflows.
- 2021: Buf reached a stable v1 line and documented a no-breaking-changes-within-major-version CLI policy.
- 2020s: The project expanded around the Buf Schema Registry, remote plugins, generated SDKs, ConnectRPC, Protobuf-ES, and Protovalidate.

### Related projects

- `protoc` is the historical compiler that Buf augments for day-to-day Protobuf workflows.
- The Buf Schema Registry is the hosted registry used for modules, documentation, remote plugins, generated SDKs, and schema checks.
- ConnectRPC, Protobuf-ES, and Protovalidate are related Buf ecosystem projects named by the official README.

### ソース

- <https://buf.build/docs/bsr>
- <https://buf.build/docs/cli>
- <https://github.com/bufbuild/buf>
- source_facts.package-manager


## セキュリティノート

narrow executable package without higher-risk signals.

- **Geiger リスク:** グリーン / 低
- narrow executable package without higher-risk signals


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Credential files

- Unix: ~/.netrc
## 他のパッケージマネージャ記録

- Nix - buf: normalized package name match | nixpkgs package indexes: pkgs/by-name/bu/buf/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- apk - buf - 1.59.0-r7: normalized package name match | Alpine Linux edge package indexes: buf from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | CLI to work with Protocol Buffers | https://buf.build/
- apk - buf-bash-completion - 1.59.0-r7: normalized package name match | Alpine Linux edge package indexes: buf-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Bash completions for buf | https://buf.build/
- apk - buf-fish-completion - 1.59.0-r7: normalized package name match | Alpine Linux edge package indexes: buf-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Fish completions for buf | https://buf.build/
- apk - buf-protoc-plugins - 1.59.0-r7: normalized package name match | Alpine Linux edge package indexes: buf-protoc-plugins from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | CLI to work with Protocol Buffers (protoc plugins) | https://buf.build/
- apk - buf-zsh-completion - 1.59.0-r7: normalized package name match | Alpine Linux edge package indexes: buf-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Zsh completions for buf | https://buf.build/
- pacman - buf - 1.72.0-1: normalized package name match | Arch Linux sync databases: buf from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz | A tool for working with Protocol Buffers | https://buf.build
- MacPorts - buf: normalized package name match | MacPorts ports tree: devel/buf/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
- Scoop - main/buf: normalized package name match | Scoop official bucket manifest trees: bucket/buf.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
- winget - bufbuild.buf: normalized package name match | Windows Package Manager source index: bufbuild.buf from https://cdn.winget.microsoft.com/cache/source.msix


## Combined YAML source

View the package source record on GitHub. [combined/buf.yml](https://github.com/mxcl/pkgdb/blob/main/combined/buf.yml)


## ソース

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
- curated agent safety answer
