pkg.soopen package index

brew / 順位 7565

vuls を Homebrew, Nix, apt でインストール

vuls のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install vuls

local Homebrew formula metadata

Linux

Nix確認済み · 92%
nix profile install nixpkgs#vuls

nixpkgs package indexes · pkgs/by-name/vu/vuls/package.nix · ソース: api.github.com

Ubuntu apt確認済み · 92%
sudo apt install vuls

Ubuntu 24.04 LTS package indexes · vuls · ソース: archive.ubuntu.com

概要

パッケージ概要

Agentless Vulnerability Scanner for Linux/FreeBSD

コマンドとエイリアス

  • future-vuls
  • snmp2cpe
  • trivy-to-vuls
  • vuls
  • vuls-scanner

履歴

プロジェクトの歴史と使われ方

Vuls is an agentless vulnerability scanner written in Go for Linux, FreeBSD, and later broader targets such as containers, application libraries, WordPress, network devices, Windows, and macOS. Its core idea is to inventory installed software and match it against vulnerability intelligence without requiring a resident scanner agent on every host.

プロジェクトの歴史

The GitHub repository was created under Future Architect in March 2016, and the README credits kotakanbe as the creator. The project grew from a concrete operations problem: administrators often cannot simply enable automatic updates on production servers, yet manually tracking NVD, OVAL, vendor trackers, and package advisories across many machines is error-prone.

Vuls developed as a Go-based scanner with multiple scan modes. Its documentation describes remote scans over SSH, local scans for hosts that should not be reached centrally, and server mode where target hosts collect software information and send it to a Vuls server over HTTP.

Over time Vuls expanded from OS package vulnerability checks into a larger security-data workflow. The README lists data sources and integrations including NVD, JVN, vendor OVAL feeds, distribution security trackers, Microsoft CVRF, exploit and PoC data, CISA Known Exploited Vulnerabilities, MITRE ATT&CK and CAPEC data, application dependency data, and WordPress scanning.

採用の歴史

Vuls is one of the more visible open-source host vulnerability scanners from the Go security tooling wave of the mid-2010s. By July 2026, GitHub repository metadata showed about 12.2k stars and more than 1.2k forks, indicating durable use well beyond a single-company internal tool.

The project also accumulated companion commands and data tools. Current release assets include `vuls`, `vuls-scanner`, `future-vuls`, `snmp2cpe`, and `trivy-to-vuls`, showing how the project adapted to adjacent scanners, CPE mapping, and hosted-service workflows.

使われ方

A common Vuls workflow is to create a `config.toml`, fetch or serve vulnerability dictionaries, scan target machines, and then generate reports for humans or automation. Remote mode uses SSH from a central machine; local and server modes reduce the need for inbound access to target hosts.

Vuls does not update vulnerable packages itself. Its value is detection, prioritization, and reporting: it tells operators which servers and software are affected, adds severity and exploit context when available, and can send notifications through channels such as email or Slack.

パッケージ好きにとっての重要性

Vuls matters to package and security nerds because it turns package inventories, CVE identifiers, OVAL feeds, vendor advisories, CPE naming, and exploit metadata into a repeatable command-line workflow. It is especially relevant for people who care about the gap between distro package versions and upstream vulnerability identifiers.

タイムライン

  • 2016: future-architect/vuls was created on GitHub on March 27, 2016.
  • 2017: FreeBSD ports carried Vuls as an agentless vulnerability scanner with SSH, TUI, notification, and multi-distribution support.
  • 2020: v0.14.0 was published on December 23, 2020, among the older releases still visible through the GitHub releases API page inspected for this run.
  • 2026: v0.39.3 was published on June 9, 2026, with signed release artifacts for multiple Vuls-related commands.

Related projects

  • Vuls is related to go-cve-dictionary, goval-dictionary, go-cpe-dictionary, gost, go-exploitdb, vulsctl, VulsRepo, Trivy, OWASP Dependency-Check, NVD, JVN, OVAL, and distribution security trackers.

セキュリティ状態

リスクレベル: red

escape, surveillance, or offensive capability signal.

リスク分類器

リスク red · 信頼度 中 · escape-surveillance-offensive

理由

  • escape, surveillance, or offensive capability signal

信号

  • text:vulnerability scanner

インストール挙動

  • Homebrew bottle メタデータは記録されていません。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
config.toml

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
future-vuls実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。
snmp2cpe実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。
trivy-to-vuls実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。
vuls実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。
vuls-scanner実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-08-03
マネージャ版0.40.1
マネージャ更新日2026-07-30
ローカルデータ不明
上流利用不可
検出された最新未検出
  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:vuls
バージョン0.40.1
パッケージマネージャHomebrew
ホームページhttps://vuls.io/
リポジトリhttps://github.com/future-architect/vuls
最終更新2026-07-30T03:56:20Z
Pulseupdated
Bottle未記録
サービス宣言なし

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

vuls

nix profile install nixpkgs#vuls
  • normalized package name match
  • 一致条件: Vuls
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/vu/vuls/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Ubuntu apt95%

vuls 0.6.1-5

Vulnerability scanner for Linux/FreeBSD, agentless, written in Go

https://github.com/future-architect/vuls

sudo apt install vuls
  • Section: universe/devel
  • Architecture: amd64
  • 2 依存関係
  • normalized package name match
  • 一致条件: Vuls
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: vuls from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation