# 使用 Homebrew, MacPorts, Nix, zypper, scoop, winget 安装 kubescape

查看 kubescape 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:kubescape
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install kubescape
```

  证据: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install kubescape
```

  证据: MacPorts ports tree: sysutils/kubescape/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- Nix (92%):

```sh
nix profile install nixpkgs#kubescape
```

  证据: nixpkgs package indexes: pkgs/by-name/ku/kubescape/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- zypper (92%):

```sh
sudo zypper install kubescape
```

  证据: openSUSE Tumbleweed package metadata: kubescape from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

### Windows

- Scoop (92%):

```sh
scoop install main/kubescape
```

  证据: Scoop official bucket manifest trees: bucket/kubescape.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

- winget (92%):

```sh
winget install --id kubescape.kubescape -e
```

  证据: Windows Package Manager source index: kubescape.kubescape from https://cdn.winget.microsoft.com/cache/source.msix

## 软件包事实

- **软件包键:** brew:kubescape
- **软件包管理器:** Homebrew
- **版本:** 4.0.11
- **来源摘要:** Kubernetes testing according to Hardening Guidance by NSA and CISA
- **主页:** <https://kubescape.io>
- **仓库:** <https://github.com/kubescape/kubescape>
- **最后更新:** 2026-07-27T21:58:46+02:00
- **已生成:** 2026-08-03T19:37:03+00:00

## 可执行文件

- kubescape (别名)

## 安装行为

- Bottle: 不可用

## 版本和新鲜度

- 页面生成时间: 2026-08-03
- 管理器版本: 4.0.11
## 项目历史与用法

Kubescape is an open source Kubernetes security and compliance platform, created by ARMO and hosted as a CNCF project. The CLI scans clusters, Kubernetes YAML, Helm charts, repositories, container registries, and images for misconfigurations, vulnerabilities, and risk.

### 项目历史

Kubescape began as a Kubernetes-focused security scanner and expanded into a broader platform covering posture management, hardening, runtime security, image vulnerability scanning, admission control, and remediation workflows. Its repository describes coverage from development through runtime, including NSA-CISA, MITRE ATT&CK, and CIS benchmark-oriented checks.

The CNCF project page records Kubescape's acceptance into CNCF on December 13, 2022 and its move to Incubating maturity on January 13, 2025.

### 采用历史

Kubescape's packaging shows adoption across developer and CI workflows: official docs list Homebrew installation, the project maintains a GitHub Action, and the README lists package-manager paths for Homebrew, Krew, Arch, Ubuntu, Nix, Chocolatey, and Scoop.

### 使用方式

The CLI is commonly used to scan a running Kubernetes cluster, scan local manifest directories, scan container images, list controls and frameworks, and integrate security checks into pull-request or CI pipelines.

### 为什么软件包爱好者会关心

Kubescape matters to package maintainers because it sits at the intersection of Kubernetes CLI tooling, security scanning databases, and policy frameworks. It is also an example of a CNCF security project with both a standalone CLI and in-cluster components.

### 时间线

- 2022: Kubescape was accepted to CNCF on December 13.
- 2025: Kubescape moved to CNCF Incubating maturity on January 13.

### Related projects

- Related projects and integrations include Kubernetes, Helm, Krew, Grype, Copacetic, Inspektor Gadget, GitHub Actions, and CNCF security/compliance tooling.

### 来源

- <https://github.com/kubescape/kubescape>
- <https://github.com/marketplace/actions/kubescape>
- <https://kubescape.io/docs>
- <https://kubescape.io/docs/install-cli/>
- <https://www.cncf.io/projects/kubescape/>


## 安全说明

infrastructure mutation or orchestration signal.

- **Geiger 风险:** orange / 中
- infrastructure mutation or orchestration signal

## 其他软件包管理器记录

- Nix - kubescape: normalized package name match | nixpkgs package indexes: pkgs/by-name/ku/kubescape/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- zypper - kubescape - 4.0.11-1.2: normalized package name match | openSUSE Tumbleweed package metadata: kubescape from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Tool providing a multi-cloud K8s single pane of glass | https://github.com/armosec/kubescape
- MacPorts - kubescape: normalized package name match | MacPorts ports tree: sysutils/kubescape/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
- Scoop - main/kubescape: normalized package name match | Scoop official bucket manifest trees: bucket/kubescape.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
- winget - kubescape.kubescape: normalized package name match | Windows Package Manager source index: kubescape.kubescape from https://cdn.winget.microsoft.com/cache/source.msix


## Combined YAML source

View the package source record on GitHub. [combined/kubescape.yml](https://github.com/mxcl/pkgdb/blob/main/combined/kubescape.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
