macOS
brew install frizbeelocal Homebrew formula metadata
安装
brew install frizbeelocal Homebrew formula metadata
sudo zypper install frizbeeopenSUSE Tumbleweed package metadata · frizbee · 来源: download.opensuse.org
winget install --id stacklok.frizbee -eWindows Package Manager source index · stacklok.frizbee · 来源: cdn.winget.microsoft.com
概览
Throw a tag at and it comes back with a checksum
历史
Frizbee is a Stacklok command-line tool and Go library for resolving mutable tags to checksums. Its README describes it as a tool that can take a GitHub Actions reference or container image tag and return a checksum or digest suitable for more reproducible supply-chain references.
Frizbee is maintained in the `stacklok/frizbee` GitHub repository and is written in Go. Official release metadata gathered during research showed a young 0.x project, with v0.0.x and v0.1.x releases from 2024 onward and v0.1.10 published in 2026.
The README documents installation through Go, Homebrew, and winget, and presents Frizbee as both a CLI and a library. It also points to a Frizbee GitHub Action, placing the project in the GitHub Actions and container-image hardening workflow rather than general-purpose checksum utilities.
For GitHub Actions, users can point `frizbee actions` at workflow files or a single action reference to generate replacements and optionally run in dry-run or CI-failing modes. For container images, users can point `frizbee image` at YAML, Dockerfile paths, or a single image tag to get a digest-pinned reference.
The library API exposes replacers for GitHub Actions and container images, with functions for parsing strings, paths, files, and filesystem abstractions.
Frizbee is package-nerd significant as a small supply-chain utility focused on a common packaging and CI problem: tags are convenient but mutable, while checksums and digests are auditable. It sits near Dependabot-style maintenance, GitHub Actions pinning, container digest pinning, and policy enforcement in CI.
Its value as a packaged CLI is that it can be dropped into local workflows or CI jobs without a larger platform, while the library form lets other tools reuse the tag-to-checksum logic.
安全态势
narrow executable package without higher-risk signals.
绿色 风险 · 低 置信度 · appliance
在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。
可执行文件
| 命令 | 类型 | 暴露范围 | 备注 |
|---|---|---|---|
frizbee | cli | 全局可执行文件 |
新鲜度
这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。
https://github.com/stacklok/frizbee
安装元数据
| 软件包键 | brew:frizbee |
|---|---|
| 版本 | 0.1.10 |
| 软件包管理器 | Homebrew |
| 软件包管理器页面 | https://formulae.brew.sh/formula/frizbee |
| 主页 | https://github.com/stacklok/frizbee |
| 仓库 | https://github.com/stacklok/frizbee |
| 许可证 | Apache-2.0 |
| 源码归档 | https://github.com/stacklok/frizbee/archive/refs/tags/v0.1.10.tar.gz |
| 最后更新 | 2026-07-26T11:37:58+02:00 |
| Pulse | updated |
| 构建依赖 | go |
| Bottle | 可用 (于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | 未定义 |
| 服务 | 未声明 |
注册表事实
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | frizbee |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
源数据库匹配
匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。
frizbee 0.1.10-1.5
Throw a tag at and it comes back with a checksum
https://github.com/stacklok/frizbee
sudo zypper install frizbeefrizbee-bash-completion 0.1.10-1.5
Bash Completion for frizbee
https://github.com/stacklok/frizbee
sudo zypper install frizbee-bash-completionfrizbee-fish-completion 0.1.10-1.5
Fish Completion for frizbee
https://github.com/stacklok/frizbee
sudo zypper install frizbee-fish-completionfrizbee-zsh-completion 0.1.10-1.5
Zsh Completion for frizbee
https://github.com/stacklok/frizbee
sudo zypper install frizbee-zsh-completionstacklok.frizbee
winget install --id stacklok.frizbee -e来源线索
此页面由 av-web 从 scripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。
View the package source record on GitHub.