# 使用 Homebrew, Nix 安装 witness

查看 witness 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:witness
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install witness
```

  证据: local Homebrew formula metadata

### Linux

- Nix (92%):

```sh
nix profile install nixpkgs#witness
```

  证据: nixpkgs package indexes: pkgs/by-name/wi/witness/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

## 软件包事实

- **软件包键:** brew:witness
- **软件包管理器:** Homebrew
- **软件包管理器页面:** <https://formulae.brew.sh/formula/witness>
- **版本:** 0.12.0
- **来源摘要:** Automates, normalizes, and verifies software artifact provenance
- **主页:** <https://witness.dev>
- **仓库:** <https://github.com/in-toto/witness>
- **上游文档:** <https://witness.dev>
- **许可证:** Apache-2.0
- **源码归档:** <https://github.com/in-toto/witness/archive/refs/tags/v0.12.0.tar.gz>
- **最后更新:** 2026-08-02T12:51:38+01:00
- **已生成:** 2026-08-04T22:13:35+00:00

## 可执行文件

- witness (cli)
- witness (别名)

## 构建依赖

- go

## 安装行为

- post-install 钩子: 未定义
- Bottle: 可用 于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## 版本和新鲜度

- 页面生成时间: 2026-08-04
- 管理器版本: 0.12.0
- 管理器更新时间: 2026-08-02
- 本地数据: OK
- 上游仓库: https://github.com/in-toto/witness
- 检测到的最新版本: v0.12.0 (当前)
## 项目历史与用法

Witness is an in-toto supply-chain security CLI for producing and verifying attestations about software artifacts and build steps. The project describes itself as a pluggable framework that automates, normalizes, and verifies software artifact provenance, combining attestation generation with a policy engine.

### 项目历史

Witness originated at TestifySec and was later donated to the CNCF in-toto ecosystem. TestifySec's open-source statement dates the formal donation of Witness and Archivista to January 2024, after ratification by the in-toto steering committee, giving the project community governance under the same ecosystem as the in-toto specification.

### 采用历史

Witness sits inside the broader in-toto adoption story. CNCF records in-toto as accepted on August 14, 2019, moved to Incubating on March 10, 2022, and Graduated on February 10, 2025. That matters for Witness because it implements the in-toto specification in a CLI intended for real pipelines, and its README points users to CNCF Slack channels and open community meetings rather than a vendor-only support path.

The project is also tied to adjacent supply-chain standards and systems. The Witness README lists support for in-toto enhancement work, OPA Rego policy, Sigstore and SPIFFE/SPIRE signing paths, timestamp authorities, and Archivista storage, reflecting the post-SolarWinds era movement toward verifiable build provenance, signed attestations, and policy-driven release gates.

### 使用方式

A typical Witness workflow runs a command under `witness run` during a build or release step, collects attestations from configured attestors, signs them, and later verifies the resulting collection against a signed policy. The goal is to answer who performed a supply-chain step, what materials and products were involved, and whether the step satisfied policy before an artifact is trusted or deployed.

### 为什么软件包爱好者会关心

For package and release engineers, Witness is significant because it turns provenance from a document attached at the end of a release into machine-verifiable metadata emitted by each lifecycle step. It is part of the same tooling vocabulary as SLSA provenance, Sigstore signing, OPA/Rego policy, and SBOM/attestation storage, making it a package-nerd tool for proving how an artifact came to exist.

### 时间线

- 2021-12-03: the current GitHub repository was created.
- 2024-01: TestifySec donated Witness and Archivista as in-toto subprojects.
- 2025-02-10: in-toto reached CNCF Graduated maturity, strengthening the ecosystem context around Witness.

### 来源

- <https://api.github.com/repos/in-toto/witness>
- <https://github.com/in-toto/witness>
- <https://witness.dev/>
- <https://www.cncf.io/projects/in-toto/>
- <https://www.testifysec.com/opensource/>


## 安全说明

narrow executable package without higher-risk signals.

- **Geiger 风险:** 绿色 / 低
- narrow executable package without higher-risk signals

## 源数据库详情

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** witness
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable

## 其他软件包管理器记录

- Nix - witness: normalized package name match | nixpkgs package indexes: pkgs/by-name/wi/witness/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1


## 相关链接

- [Terminal utility packages](https://pkg.so/zh-hans/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Networking and protocol packages](https://pkg.so/zh-hans/networking-protocol-tools/) - Matched network, protocol, or remote-service metadata.
- [Security and crypto packages](https://pkg.so/zh-hans/security-crypto-tools/) - Matched security, identity, cryptography, password, signing, or certificate metadata.
- [Homebrew utility packages](https://pkg.so/zh-hans/brew-utility-packages/) - Matched Homebrew package provider.
- [go](https://pkg.so/zh-hans/brew/go/) - Build dependency declared by Homebrew.
- [slsa-verifier](https://pkg.so/zh-hans/brew/slsa-verifier/) - Shares pkgdb curated category or tags: cli, provenance, security, supply-chain-security.
- [cosign](https://pkg.so/zh-hans/brew/cosign/) - Shares pkgdb curated category or tags: cli, security, supply-chain-security.
- [zizmor](https://pkg.so/zh-hans/brew/zizmor/) - Shares pkgdb curated category or tags: cli, security, supply-chain-security.
- [chainloop-cli](https://pkg.so/zh-hans/brew/chainloop-cli/) - Shares pkgdb curated category or tags: attestation, cli, security.
- [malcontent](https://pkg.so/zh-hans/brew/malcontent/) - Shares pkgdb curated category or tags: cli, security, supply-chain-security.
- [safety](https://pkg.so/zh-hans/brew/safety/) - Shares pkgdb curated category or tags: cli, security, supply-chain-security.
- [sigstore](https://pkg.so/zh-hans/brew/sigstore/) - Shares pkgdb curated category or tags: cli, security, supply-chain-security.
- [vet](https://pkg.so/zh-hans/brew/vet/) - Shares pkgdb curated category or tags: cli, security, supply-chain-security.
- [minder](https://pkg.so/zh-hans/brew/minder/) - Security-sensitive metadata or terminology overlaps. Shared terms: artifact, attestation, chain, cli, security.

## Combined YAML source

View the package source record on GitHub. [combined/witness.yml](https://github.com/mxcl/pkgdb/blob/main/combined/witness.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- package-page enrichment
- curated package history
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
