pkg.sopackage field notes

brew / rank 1419

Install step with Homebrew

Crypto and x509 Swiss-Army-Knife. Version 0.30.6 via Homebrew; verified 2026-07-26.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install step

provider-native install command

overview

Package summary

Crypto and x509 Swiss-Army-Knife

Commands and aliases

  • step
  • step-ca

history

Project history and usage

step is Smallstep's command-line tool for certificates, cryptography, and PKI workflows. In package-manager culture it is a classic security operator binary: one install gives developers and sysadmins commands for X.509, JWT, OAuth/OIDC-adjacent tasks, local PKI, and interaction with step-ca.

Project history

The smallstep/cli GitHub repository was created in July 2018. Smallstep's official writing says step and step-ca were first released in 2018, and the README describes step as an easy-to-use CLI for building, operating, and automating PKI systems and workflows, as well as a client for the step-ca online certificate authority.

Adoption history

Smallstep positions step-cli as the command-line interface for its open-source certificate toolchain, and its docs show use across standalone crypto operations and online CA workflows. Smallstep also states that step and step-ca became the most popular open-source certificate management toolchain; treated neutrally, this indicates broad visibility in DevOps, homelab, Kubernetes, ACME, and internal-TLS communities.

How it is used

Common usage includes creating and inspecting certificates, bootstrapping trust for a CA, checking CA health, issuing and renewing certificates through step-ca, formatting keys, and managing contexts. Official docs document `$STEPPATH/config/defaults.json` for defaults such as CA URL, fingerprint, and root certificate path, and `$(step path)/config/ca.json` for step-ca configuration.

Why package nerds care

Package nerds care because step packages a large amount of certificate plumbing into one Go binary, avoiding language-specific setup and reducing the friction of PKI automation. Its broad package-manager footprint in the input facts, including Homebrew, Linux distributions, MacPorts, Nix, and WinGet, makes it a useful example of a security CLI that crossed from vendor toolchain into general-purpose system packaging.

Timeline

  • 2018: step and step-ca first released, according to Smallstep.
  • 2018: Public smallstep/cli GitHub repository created.
  • 2020: v0.14.2 release added initial Windows support and step ssh subcommands.
  • 2026: GitHub releases continued through the v0.30 release line.

Related projects

  • step is closely paired with step-ca, the Smallstep certificate authority server, and shares ecosystem context with ACME clients, Kubernetes cert-manager workflows, SSH certificate tooling, and internal TLS automation.

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
$STEPPATH/config/defaults.json$(step path)/config/ca.json

executables

Installed executables

CommandKindExposureNote
stepexecutableindexed executableDiscovered from the local executable index.
step-caexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version0.30.6
manager updated2026-07-26
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:step
Version0.30.6
Package managerHomebrew
Homepagehttps://smallstep.com
Repositoryhttps://github.com/smallstep/cli
Last updated2026-07-26T04:03:46+02:00
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation