pkg.soopen package index

brew / rank 7457

Install flawz with Homebrew, apk, MacPorts, Nix, pacman

Terminal UI for browsing security vulnerabilities (CVEs). Version 0.4.1 via Homebrew; verified 2026-06-14. Also installable with nix: nix profile install nixpkgs#flawz.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install flawz

local Homebrew formula metadata

MacPortsverified · 94%
sudo port install flawz

MacPorts ports tree · security/flawz/Portfile · source: api.github.com

overview

Package summary

Terminal UI for browsing security vulnerabilities (CVEs)

Commands and aliases

  • flawz

history

Project history and usage

flawz is a Rust terminal user interface for browsing CVE security vulnerability data. It packages NVD-backed vulnerability search into a local CLI/TUI workflow with SQLite storage, theming, offline use, and optional NVD API-key acceleration.

Project history

The upstream GitHub repository was created in 2024. The README presents flawz as a terminal UI for browsing security vulnerabilities, using NIST's NVD as the default vulnerability database and offering search, listing, theming, and details views in the terminal.

The release stream began with v0.1.0 in May 2024 and reached v0.4.1 in June 2026, according to the official GitHub releases API.

Adoption history

The official README documents installation through Cargo, Arch Linux official repositories, Alpine Edge, Homebrew, Nixpkgs unstable, NetBSD pkgsrc, binary releases, and source builds. That unusually broad package-manager list for a young Rust TUI reflects quick adoption by distribution packagers interested in CVE tooling.

How it is used

flawz syncs NVD feeds into a SQLite database, accepts year ranges and recent or modified feeds, and can start directly on a query such as an xz CVE search. Users can pass an NVD API key with `--api-key` or `NVD_API_KEY` for higher NVD rate limits, choose themes, and use offline mode against cached data.

Why package nerds care

flawz is package-nerd relevant because it combines several current CLI trends in one small package: Rust distribution through crates.io and native package managers, terminal UI ergonomics, local SQLite caching, and security metadata browsing tied to the NVD feed ecosystem.

Timeline

  • 2024: GitHub repository created.
  • 2024: v0.1.0 released on May 18.
  • 2024: v0.3.0 released on November 3.
  • 2026: v0.4.0 and v0.4.1 released on June 13.

Related projects

  • NVD and NIST provide the default vulnerability database used by flawz.
  • crates.io, docs.rs, Cargo, Arch Linux, Alpine, Homebrew, Nixpkgs, NetBSD pkgsrc, and SQLite are part of the documented packaging and runtime context.

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
flawzexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version0.4.1
manager updated2026-06-14
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:flawz
Version0.4.1
Package managerHomebrew
Homepagehttps://github.com/orhun/flawz
Repositoryhttps://github.com/orhun/flawz
Last updated2026-06-14T05:08:26Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

flawz

nix profile install nixpkgs#flawz
  • normalized package name match
  • Matched by: Flawz
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/fl/flawz/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

flawz 0.4.1-r0

A Terminal UI for browsing CVEs

https://github.com/orhun/flawz

sudo apk add flawz
  • License: MIT OR Apache-2.0
  • Architecture: x86_64
  • Source Package: flawz
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Flawz
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: flawz from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

flawz-bash-completion 0.4.1-r0

Bash completions for flawz

https://github.com/orhun/flawz

sudo apk add flawz-bash-completion
  • License: MIT OR Apache-2.0
  • Architecture: x86_64
  • Source Package: flawz
  • normalized package name match
  • Matched by: Flawz
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: flawz-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

flawz-doc 0.4.1-r0

A Terminal UI for browsing CVEs (documentation)

https://github.com/orhun/flawz

sudo apk add flawz-doc
  • License: MIT OR Apache-2.0
  • Architecture: x86_64
  • Source Package: flawz
  • normalized package name match
  • Matched by: Flawz
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: flawz-doc from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

flawz-fish-completion 0.4.1-r0

Fish completions for flawz

https://github.com/orhun/flawz

sudo apk add flawz-fish-completion
  • License: MIT OR Apache-2.0
  • Architecture: x86_64
  • Source Package: flawz
  • normalized package name match
  • Matched by: Flawz
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: flawz-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

flawz-zsh-completion 0.4.1-r0

Zsh completions for flawz

https://github.com/orhun/flawz

sudo apk add flawz-zsh-completion
  • License: MIT OR Apache-2.0
  • Architecture: x86_64
  • Source Package: flawz
  • normalized package name match
  • Matched by: Flawz
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: flawz-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
pacman95%

flawz 0.4.1-1

A Terminal UI for browsing security vulnerabilities (CVEs)

https://github.com/orhun/flawz

sudo pacman -S flawz
  • License: MIT AND Apache-2.0
  • Architecture: x86_64
  • 4 dependencies
  • normalized package name match
  • Matched by: Flawz
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: flawz from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

flawz

sudo port install flawz
  • normalized package name match
  • Matched by: Flawz
MacPorts ports tree · api.github.com · MacPorts ports tree: security/flawz/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation