# Install buf with Homebrew, apk, MacPorts, Nix, pacman, scoop, winget

New way of working with Protocol Buffers. Version 1.72.0 via Homebrew; verified 2026-07-26. Also installable with nix: nix profile install nixpkgs#buf.

## Install

```sh
sudo av install brew:buf
```

## Agent safety answer

buf manages protobuf linting, generation, and registry workflows.

- **Credential access:** Reads registry tokens, environment variables, and project schema files.
- **Remote mutation:** Can push modules and interact with remote schema registries.
- **Publish/artifact risk:** Can publish schema modules and generated artifacts.
- **Recommended control:** Gate push, registry login, and token-backed commands.
- **Agent-use guidance:** Allow lint/generate; require approval for registry writes and token use.

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install buf
```

  Evidence: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install buf
```

  Evidence: MacPorts ports tree: devel/buf/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- apk (92%):

```sh
sudo apk add buf
```

  Evidence: Alpine Linux edge package indexes: buf from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz

- Nix (92%):

```sh
nix profile install nixpkgs#buf
```

  Evidence: nixpkgs package indexes: pkgs/by-name/bu/buf/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- pacman (92%):

```sh
sudo pacman -S buf
```

  Evidence: Arch Linux sync databases: buf from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

### Windows

- Scoop (92%):

```sh
scoop install main/buf
```

  Evidence: Scoop official bucket manifest trees: bucket/buf.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

- winget (92%):

```sh
winget install --id bufbuild.buf -e
```

  Evidence: Windows Package Manager source index: bufbuild.buf from https://cdn.winget.microsoft.com/cache/source.msix

## Package facts

- **Package key:** brew:buf
- **Package manager:** Homebrew
- **Version:** 1.72.0
- **Source summary:** New way of working with Protocol Buffers
- **Homepage:** <https://buf.build>
- **Repository:** <https://github.com/bufbuild/buf>
- **Last updated:** 2026-07-26T10:56:35+02:00
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- buf (alias)
- protoc-gen-buf-breaking (alias)
- protoc-gen-buf-lint (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 1.72.0
## Project history and usage

Buf is a modern Protocol Buffers toolchain centered on the `buf` CLI, replacing many direct `protoc` workflows with module-aware builds, linting, breaking-change detection, formatting, code generation, dependency management, API calls, and access to the Buf Schema Registry.

### Project history

Buf was created by Buf Technologies as a developer-tooling layer for Protobuf projects. Its public repository presents it as a modern toolchain for Protobuf rather than a replacement for the schema language itself: it keeps the plugin model familiar to `protoc` users while adding workspace configuration, deterministic checks, and registry-aware workflows.

The project grew beyond a formatter or wrapper into a broader ecosystem: the CLI, Buf Schema Registry, remote plugins, generated SDKs, ConnectRPC, Protobuf-ES, and Protovalidate are all positioned by Buf as related pieces of schema-driven API infrastructure.

### Adoption history

Buf adoption followed the pain points of larger Protobuf users: teams wanted one repeatable command for compiling, linting, compatibility checks, and generation instead of per-repository shell scripts around `protoc -I` paths. The CLI is distributed through Homebrew, npm, Docker, Windows installers, binary downloads, tarballs, source builds, and other package managers listed in the input.

Registry features widened its role from local CLI tooling to organization-level schema governance. The Buf Schema Registry stores modules, renders documentation, resolves dependencies, hosts remote plugins, produces generated SDKs, and can enforce schema checks for teams that publish APIs there.

### How it is used

Typical CLI use starts with `buf config init`, then `buf build`, `buf format -w`, `buf lint`, `buf breaking --against ...`, and `buf generate`. Projects commonly check in `buf.yaml`, `buf.gen.yaml`, and `buf.lock` so CI and developer laptops run the same Protobuf workflow.

Core CLI features work without a Buf Schema Registry account, while signing in adds private module dependency resolution, remote plugins, generated SDKs, hosted documentation, and server-side checks.

### Why package nerds care

Buf matters to package-tooling people because it treats `.proto` files as versioned modules instead of loose source files copied between repos. It brings package-lock and registry patterns familiar from language ecosystems into Protobuf schema distribution.

It is also a notable example of a package manager formula that installs not only the main `buf` binary but companion protoc plugins, making Homebrew a convenient entry point for Protobuf linting and compatibility checks.

### Timeline

- 2020: Early public Buf releases established the CLI around Protobuf build, lint, breaking-change, and generation workflows.
- 2021: Buf reached a stable v1 line and documented a no-breaking-changes-within-major-version CLI policy.
- 2020s: The project expanded around the Buf Schema Registry, remote plugins, generated SDKs, ConnectRPC, Protobuf-ES, and Protovalidate.

### Related projects

- `protoc` is the historical compiler that Buf augments for day-to-day Protobuf workflows.
- The Buf Schema Registry is the hosted registry used for modules, documentation, remote plugins, generated SDKs, and schema checks.
- ConnectRPC, Protobuf-ES, and Protovalidate are related Buf ecosystem projects named by the official README.

### Sources

- <https://buf.build/docs/bsr>
- <https://buf.build/docs/cli>
- <https://github.com/bufbuild/buf>
- source_facts.package-manager


## Security Notes

narrow executable package without higher-risk signals.

- **Geiger risk:** green / low
- narrow executable package without higher-risk signals


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Credential files

- Unix: ~/.netrc
## Other Package-Manager Records

- Nix - buf: normalized package name match | nixpkgs package indexes: pkgs/by-name/bu/buf/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- apk - buf - 1.59.0-r7: normalized package name match | Alpine Linux edge package indexes: buf from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | CLI to work with Protocol Buffers | https://buf.build/
- apk - buf-bash-completion - 1.59.0-r7: normalized package name match | Alpine Linux edge package indexes: buf-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Bash completions for buf | https://buf.build/
- apk - buf-fish-completion - 1.59.0-r7: normalized package name match | Alpine Linux edge package indexes: buf-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Fish completions for buf | https://buf.build/
- apk - buf-protoc-plugins - 1.59.0-r7: normalized package name match | Alpine Linux edge package indexes: buf-protoc-plugins from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | CLI to work with Protocol Buffers (protoc plugins) | https://buf.build/
- apk - buf-zsh-completion - 1.59.0-r7: normalized package name match | Alpine Linux edge package indexes: buf-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Zsh completions for buf | https://buf.build/
- pacman - buf - 1.72.0-1: normalized package name match | Arch Linux sync databases: buf from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz | A tool for working with Protocol Buffers | https://buf.build
- MacPorts - buf: normalized package name match | MacPorts ports tree: devel/buf/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
- Scoop - main/buf: normalized package name match | Scoop official bucket manifest trees: bucket/buf.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
- winget - bufbuild.buf: normalized package name match | Windows Package Manager source index: bufbuild.buf from https://cdn.winget.microsoft.com/cache/source.msix


## Combined YAML source

View the package source record on GitHub. [combined/buf.yml](https://github.com/mxcl/pkgdb/blob/main/combined/buf.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
- curated agent safety answer
