pkg.sopackage field notes

brew / rank 738

Install certbot with Homebrew

Tool to obtain certs from Let's Encrypt and autoenable HTTPS. Version 5.7.0 via Homebrew; verified 2026-07-16.

agent safety

Agent safety answer

certbot manages TLS certificates and can change web-server certificate state.

Credential access

Reads account keys, private keys, webroot paths, and DNS provider credentials.

Remote mutation

Can request certificates and modify local server config or DNS plugins.

Publish/artifact risk

Can create certificates used by public services.

Recommended control

Gate renew, certonly, private-key reads, and DNS credential use.

Agent-use guidance

Allow certificate status checks; require approval before issuing, renewing, or editing live certs.

install

Additional install commands

macOS

Homebrewverified ยท 100%
brew install certbot

provider-native install command

overview

Package summary

Tool to obtain certs from Let's Encrypt and autoenable HTTPS

Commands and aliases

  • certbot

history

Project history and usage

Certbot is EFF's ACME client for obtaining and renewing HTTPS certificates, most commonly from Let's Encrypt, and optionally configuring web servers such as Apache and nginx.

Project history

The repository was created in 2014 during the early Let's Encrypt client era. In 2016, EFF announced the client would move under the Certbot name to distinguish the client from the Let's Encrypt certificate authority and ISRG organization.

Adoption history

Certbot rode the same adoption wave as Let's Encrypt: EFF's 2016 announcement noted Let's Encrypt had issued its three millionth certificate, and EFF later reported Certbot installed on more than 4 million web servers maintaining certificates for more than 31 million websites.

How it is used

Certbot is intended to run on the server that hosts the site. It obtains certificates, saves them under /etc/letsencrypt/live, renews them on a schedule, and can use plugins for Apache, nginx, webroot, standalone, manual, and DNS-based validation.

Why package nerds care

Certbot is one of the canonical examples of a security CLI becoming distribution infrastructure: it appears in many package managers, replaced the older letsencrypt command name in user documentation, deprecated certbot-auto, and standardized operational files under /etc/letsencrypt.

Timeline

  • 2014: Public certbot/certbot repository created.
  • 2016: EFF announced the Let's Encrypt client rename to Certbot and the new certbot.eff.org site.
  • 2025: Certbot 5.0.0 released, removing older deprecated APIs and Python 3.9 support.
  • 2026: Certbot 5.6.0 released according to the official changelog.

Related projects

  • Let's Encrypt is the default certificate authority commonly used with Certbot.
  • ACME is the protocol Certbot speaks, standardized as RFC 8555.
  • certbot-apache, certbot-nginx, and Certbot DNS plugins provide authenticator and installer integrations.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for certbot. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Credential files

Credential-bearing paths to review before unattended agent runs.

macOS
~/Library/Application Support/letsencrypt
Unix
~/.config/letsencrypt~/.letsencrypt

executables

Installed executables

CommandKindExposureNote
certbotexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version5.7.0
manager updated2026-07-16
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:certbot
Version5.7.0
Package managerHomebrew
Homepagehttps://certbot.eff.org/
Repositoryhttps://github.com/certbot/certbot
Last updated2026-07-16T20:51:03Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated agent safety answer
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation