# 使用 Homebrew, zypper, winget 安装 frizbee

查看 frizbee 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:frizbee
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install frizbee
```

  证据: local Homebrew formula metadata

### Linux

- zypper (92%):

```sh
sudo zypper install frizbee
```

  证据: openSUSE Tumbleweed package metadata: frizbee from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

### Windows

- winget (92%):

```sh
winget install --id stacklok.frizbee -e
```

  证据: Windows Package Manager source index: stacklok.frizbee from https://cdn.winget.microsoft.com/cache/source.msix

## 软件包事实

- **软件包键:** brew:frizbee
- **软件包管理器:** Homebrew
- **软件包管理器页面:** <https://formulae.brew.sh/formula/frizbee>
- **版本:** 0.1.10
- **来源摘要:** Throw a tag at and it comes back with a checksum
- **主页:** <https://github.com/stacklok/frizbee>
- **仓库:** <https://github.com/stacklok/frizbee>
- **许可证:** Apache-2.0
- **源码归档:** <https://github.com/stacklok/frizbee/archive/refs/tags/v0.1.10.tar.gz>
- **最后更新:** 2026-07-26T11:37:58+02:00
- **已生成:** 2026-08-04T22:13:35+00:00

## 可执行文件

- frizbee (cli)
- frizbee (别名)

## 构建依赖

- go

## 安装行为

- post-install 钩子: 未定义
- Bottle: 可用 于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## 版本和新鲜度

- 页面生成时间: 2026-08-04
- 管理器版本: 0.1.10
- 管理器更新时间: 2026-07-26
- 本地数据: OK
- 上游仓库: https://github.com/stacklok/frizbee
- 检测到的最新版本: v0.1.10 (当前)
## 项目历史与用法

Frizbee is a Stacklok command-line tool and Go library for resolving mutable tags to checksums. Its README describes it as a tool that can take a GitHub Actions reference or container image tag and return a checksum or digest suitable for more reproducible supply-chain references.

### 项目历史

Frizbee is maintained in the `stacklok/frizbee` GitHub repository and is written in Go. Official release metadata gathered during research showed a young 0.x project, with v0.0.x and v0.1.x releases from 2024 onward and v0.1.10 published in 2026.

### 采用历史

The README documents installation through Go, Homebrew, and winget, and presents Frizbee as both a CLI and a library. It also points to a Frizbee GitHub Action, placing the project in the GitHub Actions and container-image hardening workflow rather than general-purpose checksum utilities.

### 使用方式

For GitHub Actions, users can point `frizbee actions` at workflow files or a single action reference to generate replacements and optionally run in dry-run or CI-failing modes. For container images, users can point `frizbee image` at YAML, Dockerfile paths, or a single image tag to get a digest-pinned reference.

The library API exposes replacers for GitHub Actions and container images, with functions for parsing strings, paths, files, and filesystem abstractions.

### 为什么软件包爱好者会关心

Frizbee is package-nerd significant as a small supply-chain utility focused on a common packaging and CI problem: tags are convenient but mutable, while checksums and digests are auditable. It sits near Dependabot-style maintenance, GitHub Actions pinning, container digest pinning, and policy enforcement in CI.

Its value as a packaged CLI is that it can be dropped into local workflows or CI jobs without a larger platform, while the library form lets other tools reuse the tag-to-checksum logic.

### 时间线

- 2024: Official releases include early v0.0.x and v0.1.x Frizbee builds.
- 2024: The README documents installation via Go, Homebrew, and winget and usage for GitHub Actions and container images.
- 2026: Official releases include Frizbee v0.1.10.

### Related projects

- Related surfaces include GitHub Actions, the Frizbee GitHub Action, container registries, image digest pinning, and Stacklok supply-chain tooling.
- The CLI's work overlaps with CI policy, tag pinning, reproducible builds, and tools that rewrite workflow or manifest files to less mutable references.

### 来源

- <https://github.com/marketplace/actions/frizbee-action>
- <https://github.com/stacklok/frizbee/releases>
- <https://raw.githubusercontent.com/stacklok/frizbee/main/README.md>


## 安全说明

narrow executable package without higher-risk signals.

- **Geiger 风险:** 绿色 / 低
- narrow executable package without higher-risk signals

## 源数据库详情

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** frizbee
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable

## 其他软件包管理器记录

- zypper - frizbee - 0.1.10-1.5: normalized package name match | openSUSE Tumbleweed package metadata: frizbee from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Throw a tag at and it comes back with a checksum | https://github.com/stacklok/frizbee
- zypper - frizbee-bash-completion - 0.1.10-1.5: normalized package name match | openSUSE Tumbleweed package metadata: frizbee-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Bash Completion for frizbee | https://github.com/stacklok/frizbee
- zypper - frizbee-fish-completion - 0.1.10-1.5: normalized package name match | openSUSE Tumbleweed package metadata: frizbee-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Fish Completion for frizbee | https://github.com/stacklok/frizbee
- zypper - frizbee-zsh-completion - 0.1.10-1.5: normalized package name match | openSUSE Tumbleweed package metadata: frizbee-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Zsh Completion for frizbee | https://github.com/stacklok/frizbee
- winget - stacklok.frizbee: normalized package name match | Windows Package Manager source index: stacklok.frizbee from https://cdn.winget.microsoft.com/cache/source.msix


## 相关链接

- [Source-control packages](https://pkg.so/zh-hans/source-control-tools/) - Belongs to a source-control command family.
- [Terminal utility packages](https://pkg.so/zh-hans/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Networking and protocol packages](https://pkg.so/zh-hans/networking-protocol-tools/) - Matched network, protocol, or remote-service metadata.
- [Security and crypto packages](https://pkg.so/zh-hans/security-crypto-tools/) - Matched security, identity, cryptography, password, signing, or certificate metadata.
- [go](https://pkg.so/zh-hans/brew/go/) - Build dependency declared by Homebrew.
- [zizmor](https://pkg.so/zh-hans/brew/zizmor/) - Shares pkgdb curated category or tags: cli, github-actions, security.
- [osv-scanner](https://pkg.so/zh-hans/brew/osv-scanner/) - Shares pkgdb curated category or tags: cli, security, supply-chain.
- [md5sha1sum](https://pkg.so/zh-hans/brew/md5sha1sum/) - Shares pkgdb curated category or tags: checksums, cli, security.
- [md5deep](https://pkg.so/zh-hans/brew/md5deep/) - Shares pkgdb curated category or tags: checksums, cli, security.
- [npq](https://pkg.so/zh-hans/brew/npq/) - Shares pkgdb curated category or tags: cli, security, supply-chain.
- [pip-audit](https://pkg.so/zh-hans/brew/pip-audit/) - Shares pkgdb curated category or tags: cli, security, supply-chain.
- [scorecard](https://pkg.so/zh-hans/brew/scorecard/) - Shares pkgdb curated category or tags: cli, security, supply-chain.
- [ghalint](https://pkg.so/zh-hans/brew/ghalint/) - Shares pkgdb curated category or tags: cli, github-actions, security.
- [ratchet](https://pkg.so/zh-hans/brew/ratchet/) - Security-sensitive metadata or terminology overlaps. Shared terms: chain, cli, pinning, security, supply.

## Combined YAML source

View the package source record on GitHub. [combined/frizbee.yml](https://github.com/mxcl/pkgdb/blob/main/combined/frizbee.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- package-page enrichment
- curated package history
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
