Automic VaultAutomic Vault

brew

melange mit Homebrew, apk, Nix, pacman, zypper installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für melange in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install melange

local Homebrew formula metadata

Linux

Alpine Linux apkverifiziert · 92%
sudo apk add melange

Alpine Linux edge package indexes · melange · Quelle: dl-cdn.alpinelinux.org

Nixverifiziert · 92%
nix profile install nixpkgs#melange

nixpkgs package indexes · pkgs/by-name/me/melange/package.nix · Quelle: api.github.com

Arch Linux pacmanverifiziert · 92%
sudo pacman -S melange

Arch Linux sync databases · melange · Quelle: geo.mirror.pkgbuild.com

openSUSE zypperverifiziert · 92%
sudo zypper install melange

openSUSE Tumbleweed package metadata · melange · Quelle: download.opensuse.org

Überblick

Paketzusammenfassung

Build APKs from source code

Befehle und Aliase

  • melange

Verlauf

Projektgeschichte und Nutzung

melange is Chainguard's declarative build tool for producing APK packages from source. The README describes it as a pipeline-oriented APK builder commonly used for packages that feed container images built with apko, especially in the Wolfi and Alpine Linux ecosystems.

Projektgeschichte

The project was created for supply-chain-aware package production, where software is built into APK artifacts with controlled pipelines and provenance rather than copied directly into images. The README frames this as part of secure software factories: build and capture software artifacts into packages so images can be assembled from auditable components.

The v0.1.0 release appeared in June 2022. Since then melange has become a core piece of the Chainguard/Wolfi packaging stack, with release automation, multi-architecture support, QEMU-based emulation, pipeline libraries, package signing, and documentation for build files, pipelines, testing, and updates.

Adoptionsgeschichte

melange's adoption is strongly tied to Wolfi, Chainguard Images, and apko-based image construction. The upstream README says the majority of its APKs are built for the Wolfi or Alpine Linux ecosystems, and the supplied package facts list Homebrew, Alpine, Nix, pacman, and openSUSE packaging.

For teams building minimal container images, melange provides a package-native alternative to ad hoc Dockerfile build steps. That makes it relevant in reproducible-build and SBOM-heavy workflows where APKs are easier to scan, sign, attest, and reuse.

Wie es verwendet wird

A melange build file declares package metadata, build environment contents, pipeline steps, subpackages, and tests. The README shows melange build examples/gnu-hello.yaml and a containerized invocation with cgr.dev/chainguard/melange.

The tool writes architecture-specific APK outputs under a packages directory. It can generate signing keys with melange keygen and accepts --signing-key during builds.

Warum Paket-Nerds sich dafür interessieren

melange is package-nerd catnip because it brings distro-style package recipes into cloud-native image builds. It is small in concept but high leverage: YAML recipes, APK outputs, signing, pipelines, and apko integration let maintainers replace one-off container build scripts with reusable package metadata.

Zeitleiste

  • 2022-06-02: Release v0.1.0 published.
  • 2022 onward: melange used with apko, Wolfi, and Alpine-oriented APK production.
  • 2026-06-29: Release v0.55.0 published with ongoing pipeline improvements.

Related projects

  • apko: Chainguard's tool for building OCI images from APK packages.
  • Wolfi: the APK-based Linux distribution ecosystem frequently built with melange.
  • Alpine Linux: the APK package ecosystem whose package format melange targets.

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für melange wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
melange.yamlmelange.yml

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
melangecliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version0.56.3
Manager aktualisiert2026-07-17
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv0.56.3

https://github.com/chainguard-dev/melange

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:melange
Version0.56.3
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/melange
Homepagehttps://github.com/chainguard-dev/melange
Repositoryhttps://github.com/chainguard-dev/melange
Upstream-Dokumentationhttps://github.com/chainguard-dev/melange
LizenzApache-2.0
Quellarchivhttps://github.com/chainguard-dev/melange/archive/refs/tags/v0.56.3.tar.gz
Zuletzt aktualisiert2026-07-17T15:38:35Z
Pulseupdated
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namemelange
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

melange

nix profile install nixpkgs#melange
  • normalized package name match
  • Abgeglichen nach: Melange
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/me/melange/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

melange 0.52.1-r0

Build apk packages using declarative pipelines

https://github.com/chainguard-dev/melange

sudo apk add melange
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: melange
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Melange
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: melange from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

melange-bash-completion 0.52.1-r0

Bash completions for melange

https://github.com/chainguard-dev/melange

sudo apk add melange-bash-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: melange
  • normalized package name match
  • Abgeglichen nach: Melange
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: melange-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

melange-fish-completion 0.52.1-r0

Fish completions for melange

https://github.com/chainguard-dev/melange

sudo apk add melange-fish-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: melange
  • normalized package name match
  • Abgeglichen nach: Melange
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: melange-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

melange-zsh-completion 0.52.1-r0

Zsh completions for melange

https://github.com/chainguard-dev/melange

sudo apk add melange-zsh-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: melange
  • normalized package name match
  • Abgeglichen nach: Melange
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: melange-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
pacman95%

melange 0.52.0-1

Build APKs from source code

https://github.com/chainguard-dev/melange

sudo pacman -S melange
  • License: Apache-2.0
  • Architecture: x86_64
  • 4 Abhängigkeiten
  • 1 optionale Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Melange
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: melange from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
zypper95%

melange 0.52.1-1.1

Build APKs from source code

https://github.com/chainguard-dev/melange

sudo zypper install melange
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: melange
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Melange
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: melange from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
zypper95%

melange-bash-completion 0.52.1-1.1

Bash Completion for melange

https://github.com/chainguard-dev/melange

sudo zypper install melange-bash-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: melange
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Melange
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: melange-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
zypper95%

melange-fish-completion 0.52.1-1.1

Fish Completion for melange

https://github.com/chainguard-dev/melange

sudo zypper install melange-fish-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: melange
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Melange
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: melange-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
zypper95%

melange-zsh-completion 0.52.1-1.1

Zsh Completion for melange

https://github.com/chainguard-dev/melange

sudo zypper install melange-zsh-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: melange
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Melange
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: melange-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment