Automic VaultAutomic Vault

brew

graalvm を Homebrew, chocolatey でインストール

graalvm のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install graalvm

local Homebrew formula metadata

概要

パッケージ概要

JDK distribution with Graal compiler and Native Image

コマンドとエイリアス

  • native-image
  • native-image-configure

履歴

プロジェクトの歴史と使われ方

GraalVM is Oracle Labs' high-performance JDK and language-runtime project built around the Graal compiler, the Truffle language implementation framework, and Native Image ahead-of-time compilation. In package-manager terms it is a JDK distribution with extra runtime and native-compilation tooling, so installing it is closer to selecting a Java toolchain than installing a single application.

The Homebrew package is significant because it gives macOS and Unix-like developers a normal package-manager route to `native-image` and the GraalVM JDK. That matters for build scripts, CI jobs, Java microservices, and framework ecosystems that test against or produce GraalVM Native Image binaries.

プロジェクトの歴史

Oracle Labs describes GraalVM as a runtime for Java and JVM languages, JavaScript, Python, WebAssembly, and other languages that can run standalone or embedded in OpenJDK, Oracle JDK, Oracle Database, and MySQL. The project grew from Oracle Labs compiler and VM research led around the Graal dynamic compiler and the Truffle self-optimizing runtime system.

GraalVM's public pre-production line used 1.0 release candidates in 2018. Those releases show the package becoming more than a compiler experiment: artifacts moved toward the `org.graalvm` coordinates, Native Image pieces were published to Maven Central, and the distribution carried language runtimes, SDK APIs, tools, and the Substrate VM implementation behind Native Image.

The source repository `oracle/graal` brings together the compiler, SDK, SubstrateVM, Truffle, language runtimes and related tools. That monorepo shape is part of the project's identity: GraalVM is not only a JDK build, but also a platform for language implementers and ahead-of-time compilation research.

採用の歴史

GraalVM adoption in the Java ecosystem has been tied to two overlapping use cases: using the Graal compiler as an optimizing JIT, and using Native Image to build standalone executables with fast startup and lower resource use. The latter became especially visible in cloud-native Java, where container startup time and memory footprint are package-level concerns.

Oracle's 2023 licensing change made Oracle GraalVM for JDK 17, JDK 20, and following releases available under the GraalVM Free Terms and Conditions, including commercial production use subject to the license terms. That reduced a practical adoption barrier for teams that needed Oracle-provided builds rather than only community builds.

Oracle later described a shift in Java-runtime strategy: GraalVM technologies were aligned with the Java release cadence after years of research, the Graal JIT informed Oracle JDK work, and Native Image work informed OpenJDK Project Leyden. For package users, that means GraalVM sits at the intersection of a shipping JDK distribution and upstream Java platform experiments.

使われ方

Developers use GraalVM as a Java Development Kit in IDEs and build tools, then opt into Native Image through the `native-image` command or build plugins. The Native Image docs describe compiling Java code ahead of time into a native executable that includes only reachable application, library, runtime, and statically linked JDK code for a target operating system and architecture.

Typical command-line and package-manager usage revolves around setting `JAVA_HOME`, ensuring a local C toolchain is available, and running Maven or Gradle Native Image plugins. The Homebrew package exposes the JDK and tools such as `native-image` and `native-image-configure`, making it convenient for repeatable local builds.

The package also has a metadata angle: Native Image needs reachability metadata for dynamic Java features such as reflection, resources, and service loading. The curated path `META-INF/native-image/<groupId>/<artifactId>/reachability-metadata.json` reflects that package-ecosystem convention.

パッケージ好きにとっての重要性

GraalVM is package-nerd bait because it blurs boundaries between compiler, JDK, language runtime, and build artifact. Installing it can change Java bytecode execution, native executable generation, container image size, startup behavior, and dependency metadata requirements.

Its release and licensing history also affects distribution policy. Packagers need to distinguish GraalVM Community Edition licensing from Oracle GraalVM licensing, match builds to JDK baselines, and expose tooling in a way that works with `JAVA_HOME`, Gradle, Maven, CI runners, and architecture-specific native toolchains.

For Homebrew users, `brew install graalvm` is a practical way to obtain a specialized Java toolchain while keeping the installation visible to scripts and package-manager audits.

タイムライン

  • 2018: GraalVM 1.0 release candidates documented polyglot runtimes, Maven artifacts, Native Image work, and SDK/API changes.
  • 2018-10: GraalVM 1.0-RC8 documented Native Image Maven integration and Maven Central publication of Substrate VM components.
  • 2019: GraalVM moved from the 1.0 release-candidate era into production-oriented release lines.
  • 2022: Oracle Labs announced alignment of GraalVM technology development with Java release cadence.
  • 2023: Oracle announced the GraalVM Free Terms and Conditions for Oracle GraalVM releases beginning with JDK 17 and JDK 20.
  • 2026: GraalVM release-calendar documentation describes monthly feature releases from the 25.1 line with quarterly CPU updates.

Related projects

  • OpenJDK is the Java platform baseline that GraalVM builds on and tracks.
  • Truffle is the language implementation framework used by GraalVM language runtimes.
  • SubstrateVM is the Native Image implementation area in the Graal repository.
  • GraalJS, GraalPy, GraalWasm, Espresso, Sulong, Native Build Tools, and the GraalVM reachability metadata repository are adjacent GraalVM ecosystem projects.
  • Project Leyden is related through ahead-of-time Java work that Oracle says was informed by Native Image.

セキュリティ状態

保護ツール対応はまだ見つかっていません

graalvm に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 5 個のプラットフォームターゲットで利用できます。
  • 6 件の実行時依存関係とともにインストールされます。
  • ビルドメタデータには 5 件のビルド依存関係があります。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
META-INF/native-image/<groupId>/<artifactId>/reachability-metadata.json

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
native-imagecliグローバル実行可能ファイル
native-image-configurecliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版25.1.3
マネージャ更新日2026-07-05
ローカルデータOK
上流not checked
検出された最新未検出

https://github.com/oracle/graal

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:graalvm
バージョン25.1.3
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/graalvm
ホームページhttps://www.graalvm.org/
リポジトリhttps://github.com/oracle/graal
上流ドキュメントhttps://www.graalvm.org/latest/docs
ライセンスGPL-2.0-only WITH Classpath-exception-2.0
ソースアーカイブhttps://github.com/oracle/graal/archive/refs/tags/graal-25.1.3.tar.gz
最終更新2026-07-05T23:51:35Z
Pulseupdated
依存関係freetype, giflib, harfbuzz, jpeg-turbo, libpng, little-cms2
ビルド依存関係autoconf, mx, ninja, openjdk@25, pkgconf
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namegraalvm
Version Scheme0
Revision0
Requirements
  • arch
  • xcode
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyyes
URL Keys
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Chocolatey95%

graalvm

choco install graalvm
  • normalized package name match
  • 一致条件: Graalvm
Chocolatey community package catalog · community.chocolatey.org · Chocolatey community package catalog: graalvm from http://community.chocolatey.org/api/v2/Packages?$filter=IsLatestVersion&$select=Id&$top=1000&$skiptoken='7.756','razer-synapse-3'

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment