{"name":"btcli","full_name":"btcli","tap":"homebrew/core","oldnames":[],"aliases":[],"versioned_formulae":[],"desc":"Bittensor command-line tool","license":"MIT","homepage":"https://docs.learnbittensor.org/btcli","versions":{"stable":"9.23.2","head":null,"bottle":true},"urls":{"stable":{"url":"https://files.pythonhosted.org/packages/58/5f/fd9ede99e419ec618d5b6e6136b62a94840bd45be3af8bb0ded5f45cfbb4/bittensor_cli-9.23.2.tar.gz","tag":null,"revision":null,"using":null,"checksum":"0770e70cd756328093f32556561faa548a8ea357ddc5726918b9422068d2a25d"}},"patches":[],"revision":0,"version_scheme":0,"compatibility_version":null,"autobump":true,"no_autobump_message":null,"skip_livecheck":false,"bottle":{"stable":{"rebuild":0,"root_url":"https://ghcr.io/v2/homebrew/core","files":{"arm64_golden_gate":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/btcli/blobs/sha256:f6f3c7f916915220750ebad0dee09a29eaa371f9f09b038eb7d56951f4cb9a86","sha256":"f6f3c7f916915220750ebad0dee09a29eaa371f9f09b038eb7d56951f4cb9a86"},"arm64_tahoe":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/btcli/blobs/sha256:cd66ced85caa927fc232ba3a42fd3207823b194a89d7cc467941b41e8c242040","sha256":"cd66ced85caa927fc232ba3a42fd3207823b194a89d7cc467941b41e8c242040"},"arm64_sequoia":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/btcli/blobs/sha256:27f15b2b825b3b2fa9439421752904b283d6ce1bb7c77bf300a5f3706a3740e9","sha256":"27f15b2b825b3b2fa9439421752904b283d6ce1bb7c77bf300a5f3706a3740e9"},"arm64_sonoma":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/btcli/blobs/sha256:e36967d257272c1354b845eaf51254cc924a679c960101086ecf4a10cb1d9de9","sha256":"e36967d257272c1354b845eaf51254cc924a679c960101086ecf4a10cb1d9de9"},"sonoma":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/btcli/blobs/sha256:610ad3d89f8c20fcd311ac6a602d34ab3001f4061d8b82d148d965dbbde01b35","sha256":"610ad3d89f8c20fcd311ac6a602d34ab3001f4061d8b82d148d965dbbde01b35"},"arm64_linux":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/btcli/blobs/sha256:2103af4d0efd7fef4a1eabf429a2018a683d840eaa0db906516ef5dda07769e6","sha256":"2103af4d0efd7fef4a1eabf429a2018a683d840eaa0db906516ef5dda07769e6"},"x86_64_linux":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/btcli/blobs/sha256:ce5a5e1273092385254bbdd077740282045952647236287c01676028af77d6e8","sha256":"ce5a5e1273092385254bbdd077740282045952647236287c01676028af77d6e8"}}}},"pour_bottle_only_if":null,"keg_only":false,"keg_only_reason":null,"options":[],"build_dependencies":["rust"],"dependencies":["certifi","libyaml","numpy","openssl@3","python@3.14","xxhash"],"test_dependencies":[],"recommended_dependencies":[],"optional_dependencies":[],"uses_from_macos":[],"uses_from_macos_bounds":[],"requirements":[],"conflicts_with":["bittensor","btpd"],"conflicts_with_reasons":["both install `btcli` binaries","both install `btcli` binaries"],"link_overwrite":[],"caveats":null,"installed":[],"linked_keg":null,"pinned":false,"outdated":false,"deprecated":true,"deprecation_date":"2026-07-19","deprecation_reason":"repo_removed","deprecation_replacement_formula":"bittensor","deprecation_replacement_cask":null,"deprecate_args":{"date":"2026-07-19","because":"repo_removed","replacement_formula":"bittensor","replacement_cask":null},"disabled":false,"disable_date":"2027-01-19","disable_reason":null,"disable_replacement_formula":null,"disable_replacement_cask":null,"disable_args":{"date":"2027-01-19","because":"repo_removed","replacement_formula":"bittensor","replacement_cask":null},"post_install_steps":[],"post_install_defined":false,"service":null,"tap_git_head":"b1562d9578eee517d056092007bf9074798729db","ruby_source_path":"Formula/b/btcli.rb","ruby_source_checksum":{"sha256":"4fb74b841b9068a87096f0b97be35685fd036b7ecc384bb02d81e6467c5a3280"},"variations":{},"executables":["btcli"],"vulnerabilities":{"open":[{"id":"BREW-btcli-CVE-2026-59881","upstream":["GHSA-mq44-7p77-q5h7","CVE-2026-59881","PYSEC-2026-3547"],"summary":"AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate"},{"id":"BREW-btcli-CVE-2026-67322","upstream":["GHSA-rwj8-pgh3-r573","CVE-2026-67322","PYSEC-2026-3842"],"summary":"GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL","severity":"high"},{"id":"BREW-btcli-CVE-2026-69097","upstream":["GHSA-3rp5-jjmw-4wv2","CVE-2026-69097"],"summary":"GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)","severity":"high"},{"id":"BREW-btcli-CVE-2026-69243","upstream":["GHSA-mfx4-hv73-q22v","CVE-2026-69243","PYSEC-2026-3546"],"summary":"AIOHTTP: HTTP request smuggling via WebSocket upgrade"},{"id":"BREW-btcli-CVE-2026-69244","upstream":["GHSA-cq5v-8q36-5273","CVE-2026-69244","PYSEC-2026-3545"],"summary":"AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)"},{"id":"BREW-btcli-CVE-2026-73619","upstream":["GHSA-539m-9xh6-q6rr","CVE-2026-73619","PYSEC-2026-3948"],"summary":"GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()","severity":"medium"},{"id":"BREW-btcli-CVE-2026-73620","upstream":["GHSA-3f7w-8rr8-f37f","CVE-2026-73620","PYSEC-2026-3949"],"summary":"GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read","severity":"high"},{"id":"BREW-btcli-CVE-2026-73621","upstream":["GHSA-p538-c434-8v24","CVE-2026-73621","PYSEC-2026-3950"],"summary":"GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count","severity":"medium"},{"id":"BREW-btcli-CVE-2026-73622","upstream":["GHSA-94p4-4cq8-9g67","CVE-2026-73622","PYSEC-2026-3951"],"summary":"GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)","severity":"high"},{"id":"BREW-btcli-CVE-2026-73623","upstream":["GHSA-6p8h-3wgx-97gf","CVE-2026-73623","PYSEC-2026-3952"],"summary":"GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks","severity":"high"},{"id":"BREW-btcli-CVE-2026-73624","upstream":["GHSA-fjr4-x663-mwxc","CVE-2026-73624"],"summary":"GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)","severity":"high"},{"id":"BREW-btcli-CVE-2026-73625","upstream":["GHSA-r9mr-m37c-5fr3","CVE-2026-73625","PYSEC-2026-3953"],"summary":"GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution","severity":"high"},{"id":"BREW-btcli-CVE-2026-76217","upstream":["GHSA-hh9p-6wh2-4mfc","CVE-2026-76217","PYSEC-2026-3841"],"summary":"GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()","severity":"medium"},{"id":"BREW-btcli-CVE-2026-76218","upstream":["GHSA-9rj7-rf2p-w77r","CVE-2026-76218","PYSEC-2026-3840"],"summary":"GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks","severity":"high"},{"id":"BREW-btcli-CVE-2026-76219","upstream":["GHSA-4gmw-gg2m-w46p","CVE-2026-76219","PYSEC-2026-3838"],"summary":"GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite","severity":"high"},{"id":"BREW-btcli-CVE-2026-76220","upstream":["GHSA-wvpp-8hx9-p66j","CVE-2026-76220","PYSEC-2026-3843"],"summary":"GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution","severity":"high"},{"id":"BREW-btcli-CVE-2026-76221","upstream":["GHSA-jm78-9fvv-mhgr","CVE-2026-76221","PYSEC-2026-3783"],"summary":"GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)","severity":"high"},{"id":"BREW-btcli-CVE-2026-76222","upstream":["GHSA-hmq2-w58f-27jc","CVE-2026-76222","PYSEC-2026-3784"],"summary":"GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython","severity":"high"},{"id":"BREW-btcli-CVE-2026-78675","upstream":["PYSEC-2026-3785","CVE-2026-78675","GHSA-7833-fr7j-v32q"],"summary":"GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)","severity":"high"},{"id":"BREW-btcli-CVE-2026-78676","upstream":["PYSEC-2026-3786","CVE-2026-78676","GHSA-284h-m62q-gf8w"],"summary":"GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE","severity":"critical"},{"id":"BREW-btcli-CVE-2026-78677","upstream":["PYSEC-2026-3787","CVE-2026-78677","GHSA-8mcc-hrx5-hvxc"],"summary":"GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination","severity":"high"},{"id":"BREW-btcli-CVE-2026-78678","upstream":["PYSEC-2026-3788","CVE-2026-78678","GHSA-5xxx-qhh7-9287"],"summary":"GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()","severity":"medium"},{"id":"BREW-btcli-CVE-2026-78679","upstream":["GHSA-3wxw-xv34-2frg","CVE-2026-78679","PYSEC-2026-3837"],"summary":"GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)","severity":"medium"}],"patched":[],"fixed_count":82},"analytics":{"install":{"30d":{"btcli":4},"90d":{"btcli":176,"btcli --HEAD":1},"365d":{"btcli":1226,"btcli --HEAD":1}},"install_on_request":{"30d":{"btcli":4},"90d":{"btcli":176,"btcli --HEAD":1},"365d":{"btcli":1226,"btcli --HEAD":1}},"build_error":{"30d":{"btcli":0}}},
"generated_date":"2026-09-17"}
