pkg.soopen package index

brew / 順位 2704

ko を Homebrew, apk, MacPorts, Nix, pacman, scoop でインストール

ko のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install ko

local Homebrew formula metadata

MacPorts確認済み · 94%
sudo port install ko

MacPorts ports tree · devel/ko/Portfile · ソース: api.github.com

Windows

Scoop確認済み · 92%
scoop install main/ko

Scoop official bucket manifest trees · bucket/ko.json · ソース: api.github.com

概要

パッケージ概要

Build and deploy Go applications on Kubernetes

コマンドとエイリアス

  • ko

履歴

プロジェクトの歴史と使われ方

ko is a Go-focused container image builder for developers who want OCI images without writing Dockerfiles or running Docker locally. Its Homebrew package is a small CLI, but it sits at the intersection of Go modules, Kubernetes manifests, registries, SBOMs, and supply-chain tooling.

プロジェクトの歴史

The project grew out of Google experience building Docker and Kubernetes support for Bazel. Its README describes ko as a simple, fast container image builder that effectively runs `go build` locally, then packages the resulting binary into an image without requiring Docker.

By 2022, the project had moved into the ko-build GitHub organization and the ko.build documentation domain. A 2022-08-19 migration issue laid out the repository move from google/ko to github.com/ko-build, the ko.build vanity import path, image-name changes, and a Slack channel rename. On 2022-10-11, Google announced that it had submitted ko for CNCF Sandbox consideration.

採用の歴史

ko's adoption followed the rise of Go-based cloud-native services that can ship as mostly static binaries. The Google Open Source announcement described growing use by open source and enterprise teams and integration into third-party CI/CD tools.

Package-manager adoption is useful because ko is often installed in developer shells, GitHub Actions, release jobs, and Kubernetes workflows. Its companion setup-ko action made it easy to bootstrap the CLI in CI, while Homebrew, MacPorts, Nix, Arch, Alpine, and Scoop packaging made it available outside a single vendor ecosystem.

使われ方

The common workflow is `ko build` or `ko resolve`: build Go packages into images, push them to a registry, and optionally rewrite Kubernetes YAML with the produced image references. The docs emphasize no Docker daemon requirement, multi-platform images, SBOM generation, Kubernetes integration, build cache support, and registry authentication through ko login or surrounding CI credentials.

It is particularly attractive for Go services with few operating-system package dependencies. That constraint is part of the tool's appeal: it turns the boring case of a static Go binary into a very short path from source to signed or traceable container artifact.

パッケージ好きにとっての重要性

ko is the package-index shorthand for a whole cloud-native philosophy: build the thing the language already knows how to build, then wrap it as an OCI image with minimal ceremony. It competes less with Docker itself than with Dockerfile boilerplate, bespoke CI shell scripts, and build-system plugins.

For maintainers, it is also a clean example of a single-purpose CLI whose value comes from integration points: Go, registries, Kubernetes, SBOMs, GitHub Actions, and module import paths.

タイムライン

  • 2022-02-17: ko v0.10.0 was published; ko docs note that before v0.10 the command was called `ko publish`.
  • 2022-08-19: The project opened a migration issue for moving from google/ko to github.com/ko-build and ko.build.
  • 2022-08-24: ko v0.12.0 was published during the repository/domain migration period.
  • 2022-10-11: Google announced that ko had been submitted for CNCF Sandbox consideration.

Related projects

  • ko is related to go-containerregistry, setup-ko, Skaffold's ko builder integration, Docker/BuildKit workflows, Kubernetes deployment tooling, and Bazel container rules that influenced the original design.

セキュリティ状態

リスクレベル: orange

infrastructure mutation or orchestration signal.

リスク分類器

リスク orange · 信頼度 中 · infrastructure

理由

  • infrastructure mutation or orchestration signal

信号

  • text:kubernetes

インストール挙動

  • Homebrew bottle メタデータは記録されていません。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
.ko.yaml

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
ko実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-08-03
マネージャ版0.19.1
マネージャ更新日2026-07-27
ローカルデータ不明
上流利用不可
検出された最新未検出
  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:ko
バージョン0.19.1
パッケージマネージャHomebrew
ホームページhttps://ko.build
リポジトリhttps://github.com/ko-build/ko
最終更新2026-07-27T21:58:40+02:00
Pulseupdated
Bottle未記録
サービス宣言なし

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

ko

nix profile install nixpkgs#ko
  • normalized package name match
  • 一致条件: Ko
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ko/ko/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

ko 0.17.1-r16

Build containers from Go projects

https://ko.build/

sudo apk add ko
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: ko
  • 1 依存関係
  • 1 提供
  • normalized package name match
  • 一致条件: Ko
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: ko from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

ko-bash-completion 0.17.1-r16

Bash completions for ko

https://ko.build/

sudo apk add ko-bash-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: ko
  • normalized package name match
  • 一致条件: Ko
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: ko-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

ko-fish-completion 0.17.1-r16

Fish completions for ko

https://ko.build/

sudo apk add ko-fish-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: ko
  • normalized package name match
  • 一致条件: Ko
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: ko-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

ko-zsh-completion 0.17.1-r16

Zsh completions for ko

https://ko.build/

sudo apk add ko-zsh-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: ko
  • normalized package name match
  • 一致条件: Ko
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: ko-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
pacman95%

ko 0.19.1-1

Build and deploy Go container images

https://github.com/ko-build/ko

sudo pacman -S ko
  • License: Apache-2.0
  • Architecture: x86_64
  • 1 依存関係
  • normalized package name match
  • 一致条件: Ko
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: ko from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

ko

sudo port install ko
  • normalized package name match
  • 一致条件: Ko
MacPorts ports tree · api.github.com · MacPorts ports tree: devel/ko/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Scoop95%

main/ko

scoop install main/ko
  • normalized package name match
  • 一致条件: Ko
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/ko.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

Combined YAML source

View the package source record on GitHub.

combined/ko.yml

使用ソース

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation