Automic VaultAutomic Vault

brew

Installer melange avec Homebrew, apk, Nix, pacman, zypper

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de melange pour les workflows d'agents IA.

installation

Commandes d'installation supplémentaires

macOS

Homebrewvérifié · 100%
brew install melange

local Homebrew formula metadata

Linux

Alpine Linux apkvérifié · 92%
sudo apk add melange

Alpine Linux edge package indexes · melange · Source: dl-cdn.alpinelinux.org

Nixvérifié · 92%
nix profile install nixpkgs#melange

nixpkgs package indexes · pkgs/by-name/me/melange/package.nix · Source: api.github.com

Arch Linux pacmanvérifié · 92%
sudo pacman -S melange

Arch Linux sync databases · melange · Source: geo.mirror.pkgbuild.com

openSUSE zyppervérifié · 92%
sudo zypper install melange

openSUSE Tumbleweed package metadata · melange · Source: download.opensuse.org

aperçu

Résumé du paquet

Build APKs from source code

Commandes et alias

  • melange

historique

Historique du projet et usages

melange is Chainguard's declarative build tool for producing APK packages from source. The README describes it as a pipeline-oriented APK builder commonly used for packages that feed container images built with apko, especially in the Wolfi and Alpine Linux ecosystems.

Historique du projet

The project was created for supply-chain-aware package production, where software is built into APK artifacts with controlled pipelines and provenance rather than copied directly into images. The README frames this as part of secure software factories: build and capture software artifacts into packages so images can be assembled from auditable components.

The v0.1.0 release appeared in June 2022. Since then melange has become a core piece of the Chainguard/Wolfi packaging stack, with release automation, multi-architecture support, QEMU-based emulation, pipeline libraries, package signing, and documentation for build files, pipelines, testing, and updates.

Historique d'adoption

melange's adoption is strongly tied to Wolfi, Chainguard Images, and apko-based image construction. The upstream README says the majority of its APKs are built for the Wolfi or Alpine Linux ecosystems, and the supplied package facts list Homebrew, Alpine, Nix, pacman, and openSUSE packaging.

For teams building minimal container images, melange provides a package-native alternative to ad hoc Dockerfile build steps. That makes it relevant in reproducible-build and SBOM-heavy workflows where APKs are easier to scan, sign, attest, and reuse.

Modes d'utilisation

A melange build file declares package metadata, build environment contents, pipeline steps, subpackages, and tests. The README shows melange build examples/gnu-hello.yaml and a containerized invocation with cgr.dev/chainguard/melange.

The tool writes architecture-specific APK outputs under a packages directory. It can generate signing keys with melange keygen and accepts --signing-key during builds.

Pourquoi les passionnés de paquets s'y intéressent

melange is package-nerd catnip because it brings distro-style package recipes into cloud-native image builds. It is small in concept but high leverage: YAML recipes, APK outputs, signing, pipelines, and apko integration let maintainers replace one-off container build scripts with reusable package metadata.

Chronologie

  • 2022-06-02: Release v0.1.0 published.
  • 2022 onward: melange used with apko, Wolfi, and Alpine-oriented APK production.
  • 2026-06-29: Release v0.55.0 published with ongoing pipeline improvements.

Related projects

  • apko: Chainguard's tool for building OCI images from APK packages.
  • Wolfi: the APK-based Linux distribution ecosystem frequently built with melange.
  • Alpine Linux: the APK package ecosystem whose package format melange targets.

posture de sécurité

Aucune couverture d'outil protégé trouvée pour le moment

Aucun manifest local de gestion des secrets correspondant n'a été trouvé pour melange. Les métadonnées de paquet Nucleus restent publiées ici afin que la couverture future dispose d'une URL stable.

Comportement d'installation

  • Aucun hook post-install Homebrew n’est enregistré dans les métadonnées de formule.
  • Les métadonnées de bottle Homebrew sont disponibles pour 6 plateformes.
  • Les métadonnées de compilation listent 1 dépendances de compilation.

Revue recommandée

Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
melange.yamlmelange.yml

exécutables

Exécutables installés

CommandeTypeExpositionNote
melangecliexécutable global

fraîcheur

Version et fraîcheur

Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.

page générée2026-07-25
version du gestionnaire0.56.3
gestionnaire mis à jour2026-07-17
données localesOK
amontà jour
dernière version détectéev0.56.3

https://github.com/chainguard-dev/melange

  • OKAucun avertissement de fraîcheur n'a été généré.

métadonnées d'installation

Métadonnées du paquet

Clé du paquetbrew:melange
Version0.56.3
Gestionnaire de paquetsHomebrew
Page du gestionnaire de paquetshttps://formulae.brew.sh/formula/melange
Page d'accueilhttps://github.com/chainguard-dev/melange
Dépôthttps://github.com/chainguard-dev/melange
Docs amonthttps://github.com/chainguard-dev/melange
LicenceApache-2.0
Archive sourcehttps://github.com/chainguard-dev/melange/archive/refs/tags/v0.56.3.tar.gz
Dernière mise à jour2026-07-17T15:38:35Z
Pulseupdated
Dépendances de compilationgo
Bouteilledisponible (sur arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
post-install Homebrewnon défini
Serviceaucun déclaré

faits du registre

Détails de la base source

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namemelange
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

correspondances dans les bases sources

Autres enregistrements de gestionnaires de paquets

Les correspondances proviennent d’index externes de gestionnaires de paquets et restent séparées des liens de paquets Automic Vault locaux.

Nix95%

melange

nix profile install nixpkgs#melange
  • normalized package name match
  • Correspondance par : Melange
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/me/melange/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

melange 0.52.1-r0

Build apk packages using declarative pipelines

https://github.com/chainguard-dev/melange

sudo apk add melange
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: melange
  • 1 Dépendances
  • 1 fournit
  • normalized package name match
  • Correspondance par : Melange
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: melange from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

melange-bash-completion 0.52.1-r0

Bash completions for melange

https://github.com/chainguard-dev/melange

sudo apk add melange-bash-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: melange
  • normalized package name match
  • Correspondance par : Melange
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: melange-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

melange-fish-completion 0.52.1-r0

Fish completions for melange

https://github.com/chainguard-dev/melange

sudo apk add melange-fish-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: melange
  • normalized package name match
  • Correspondance par : Melange
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: melange-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

melange-zsh-completion 0.52.1-r0

Zsh completions for melange

https://github.com/chainguard-dev/melange

sudo apk add melange-zsh-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: melange
  • normalized package name match
  • Correspondance par : Melange
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: melange-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
pacman95%

melange 0.52.0-1

Build APKs from source code

https://github.com/chainguard-dev/melange

sudo pacman -S melange
  • License: Apache-2.0
  • Architecture: x86_64
  • 4 Dépendances
  • 1 dépendances optionnelles
  • normalized package name match
  • Correspondance par : Melange
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: melange from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
zypper95%

melange 0.52.1-1.1

Build APKs from source code

https://github.com/chainguard-dev/melange

sudo zypper install melange
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: melange
  • 1 Dépendances
  • 1 fournit
  • normalized package name match
  • Correspondance par : Melange
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: melange from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
zypper95%

melange-bash-completion 0.52.1-1.1

Bash Completion for melange

https://github.com/chainguard-dev/melange

sudo zypper install melange-bash-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: melange
  • 1 Dépendances
  • 1 fournit
  • normalized package name match
  • Correspondance par : Melange
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: melange-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
zypper95%

melange-fish-completion 0.52.1-1.1

Fish Completion for melange

https://github.com/chainguard-dev/melange

sudo zypper install melange-fish-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: melange
  • 1 Dépendances
  • 1 fournit
  • normalized package name match
  • Correspondance par : Melange
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: melange-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
zypper95%

melange-zsh-completion 0.52.1-1.1

Zsh Completion for melange

https://github.com/chainguard-dev/melange

sudo zypper install melange-zsh-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: melange
  • 1 Dépendances
  • 1 fournit
  • normalized package name match
  • Correspondance par : Melange
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: melange-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst

piste source

Généré depuis les données du dépôt

Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.

Sources utilisées

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment