# Install crane with Homebrew

Tool for interacting with remote images and registries. Version 0.21.8 via Homebrew; verified 2026-07-31.

## Install

```sh
sudo av install brew:crane
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install crane
```

  Evidence: provider-native install command

## Package facts

- **Package key:** brew:crane
- **Package manager:** Homebrew
- **Version:** 0.21.8
- **Source summary:** Tool for interacting with remote images and registries
- **Homepage:** <https://github.com/google/go-containerregistry>
- **Repository:** <https://github.com/google/go-containerregistry>
- **Last updated:** 2026-07-31T20:45:46Z
- **Generated:** 2026-08-03T00:40:33+00:00

## Executables

- crane (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 0.21.8
## Project history and usage

crane is the command-line front end in Google's go-containerregistry project for working with remote container images and registries. It sits beside the Go library APIs and exposes common registry operations as shell commands.

### Project history

The go-containerregistry repository was created in 2018 as a Go library and set of CLIs for container registry work. Its README describes the library as largely based on Google's earlier Python containerregistry library and explains that crane, gcrane, and krane are tools built on top of the shared registry primitives.

The crane README documents direct binary releases, Go installation, Homebrew, Arch Linux, GitHub Actions setup, and a container image form of the tool. The project published a v0.1.0 GitHub release in 2020 and was still publishing releases in 2026.

### Adoption history

crane became common packaging material because it is useful without a Docker daemon: scripts can copy, tag, inspect, authenticate to, and move images directly against registries. Official installation instructions explicitly cover Homebrew, Arch Linux, release tarballs, Go install, and containerized usage.

### How it is used

Package users reach for crane for registry automation: pulling and pushing images, copying between registries, tagging images in CI, listing tags, and authenticating to registries. The go-containerregistry README maps examples such as crane pull, crane push, and crane cp to library-level remote and tarball operations.

### Why package nerds care

For package maintainers, crane is a small, single-purpose registry CLI with signed release artifacts and documented SLSA provenance verification. That makes it attractive in build pipelines where installing a full container engine would be unnecessary overhead.

### Timeline

- 2018: google/go-containerregistry repository created.
- 2020: v0.1.0 release published.
- 2026: v0.21.7 release published.

### Related projects

- go-containerregistry also includes gcrane, a GCR-oriented variant, and krane, a Kubernetes-workload-identity-aware drop-in replacement. The README notes that ko originally lived in the repository before moving to its own project.

### Sources

- <https://github.com/google/go-containerregistry>
- <https://github.com/google/go-containerregistry/tree/main/cmd/crane#readme>
- <https://github.com/google/go-containerregistry/releases/tag/v0.1.0>
- <https://github.com/google/go-containerregistry/releases/tag/v0.21.7>


## Security Notes

No matching local secret-handling manifest was found for crane. Nucleus package metadata is still published here so future coverage has a stable package URL.



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Credential files

- Unix: ~/.docker/config.json, ${DOCKER_CONFIG}/config.json, ${XDG_RUNTIME_DIR}/containers/auth.json
- Windows: %USERPROFILE%\.docker\config.json

## Combined YAML source

View the package source record on GitHub. [combined/crane.yml](https://github.com/automic-vault/db/blob/main/combined/crane.yml)


## Sources

- Nucleus package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
