# noir を Homebrew でインストール

noir のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

## インストール

```sh
sudo av install brew:noir
```

追加のインストールコマンド:

### macOS

- Homebrew (100%):

```sh
brew install noir
```

  証拠: local Homebrew formula metadata

## パッケージ情報

- **パッケージキー:** brew:noir
- **パッケージマネージャ:** Homebrew
- **バージョン:** 1.2.1
- **ソース概要:** Attack surface detector that identifies endpoints by static analysis
- **ホームページ:** <https://owasp.org/www-project-noir/>
- **リポジトリ:** <https://github.com/owasp-noir/noir>
- **最終更新:** 2026-07-21T14:22:21Z
- **生成日時:** 2026-08-03T19:37:03+00:00

## 実行可能ファイル

- noir (エイリアス)

## インストール挙動

- Bottle: 利用不可

## バージョンと鮮度

- ページ生成日: 2026-08-03
- マネージャ版: 1.2.1
## プロジェクトの歴史と使われ方

OWASP Noir is a Crystal-based SAST tool that reads source code and extracts application endpoints: paths, methods, parameters, headers, cookies, and source-file locations. It is aimed at attack-surface inventory, shadow API discovery, and feeding DAST or AI-assisted review pipelines with a focused route list.

### プロジェクトの歴史

The Noir README gives a clear project timeline: it started as Hahwul's personal project in August 2023, moved to the `noir-cr` GitHub organization in November 2023, joined OWASP in June 2024, and released v1.0.0 in May 2026. The same README says OWASP membership included renaming the GitHub organization from `noir-cr` to `owasp-noir` and moving to co-leadership with `ksg97031`.

The project scope widened from a WhiteBox testing aid into an inventory consumed by human reviewers, AI auditors, and DAST tools. The README describes support for 50+ frameworks, LLM fallback for unsupported routing patterns, output formats including JSON, YAML, OpenAPI, SARIF, cURL, Postman, and HTML, and direct handoffs to ZAP, Burp Suite, and Caido.

### 採用の歴史

By 2026-07-01, GitHub metadata reported 1345 stars and 140 forks for `owasp-noir/noir`. Homebrew's formula API reported stable version 1.1.0 and 755 installs over 365 days. Those are early-project numbers, but the OWASP project page and the 1.0.0 release milestone show the tool crossing from personal/security-community project into a packaged security tool.

Noir's adoption is tied to a practical gap in API security testing: crawlers and DAST tools miss routes hidden in server code, deprecated handlers, or framework-specific routing conventions. Noir extracts the code-side route inventory so scanners and reviewers start from a better endpoint map.

### 使われ方

The minimal usage is `noir -b <source_dir>`. Security teams use the output to review attacker-reachable handlers, generate OpenAPI or SARIF artifacts, feed ZAP/Burp/Caido, and provide compact context to LLM-based SAST agents. CI usage is supported through a GitHub Action, SARIF output, and exit codes.

The package-nerd detail is that Noir is source-inventory glue. It is not a replacement for DAST or a general-purpose code scanner; it turns static framework knowledge into endpoint artifacts that downstream tools already understand.

### パッケージ好きにとっての重要性

Noir is still young enough that its history should stay close to maintainer-provided timelines. The useful enrichment is the OWASP transition, stable 1.x release, supported-output ecosystem, and the exact niche: static endpoint extraction for attack-surface mapping.

### タイムライン

- 2023-08: Noir started as Hahwul's personal project, according to the project README.
- 2023-11: The repository moved to the `noir-cr` GitHub organization.
- 2024-06: Noir joined OWASP and the organization was renamed to `owasp-noir`.
- 2026-05-24: GitHub releases list v1.0.0.
- 2026-06-15: GitHub releases list v1.1.0.
- 2026-07-01: Homebrew formula API reported stable version 1.1.0.

### Related projects

- OWASP ZAP
- Burp Suite
- Caido
- SARIF
- OpenAPI

### ソース

- <https://api.github.com/repos/owasp-noir/noir>
- <https://formulae.brew.sh/api/formula/noir.json>
- <https://github.com/owasp-noir/noir>
- <https://github.com/owasp-noir/noir/releases>
- <https://owasp-noir.github.io/noir/>
- <https://owasp.org/www-project-noir/>
- <https://raw.githubusercontent.com/owasp-noir/noir/main/README.md>


## セキュリティノート

narrow executable package without higher-risk signals.

- **Geiger リスク:** グリーン / 低
- narrow executable package without higher-risk signals


## Combined YAML source

View the package source record on GitHub. [combined/noir.yml](https://github.com/mxcl/pkgdb/blob/main/combined/noir.yml)


## ソース

- pkg.so package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
- cross-ecosystem install command graph
