macOS
brew install aubelocal Homebrew formula metadata
brew
Fast Node.js package manager. Version 1.32.0 via Homebrew; verified 2026-07-22. Also installable with nix: nix profile install nixpkgs#aube.
install
brew install aubelocal Homebrew formula metadata
nix profile install nixpkgs#aubenixpkgs package indexes · pkgs/by-name/au/aube/package.nix · source: api.github.com
winget install --id endev.aube -eWindows Package Manager source index · endev.aube · source: cdn.winget.microsoft.com
overview
Fast Node.js package manager
history
aube is a 2026 Node.js package manager focused on automatic installs before scripts, pnpm-compatible configuration and lockfile workflows, and stricter supply-chain defaults. Its history is short, but unusually dense: the public beta, v1.0 release train, and rapid follow-up releases all happened within months.
The GitHub repository was created in April 2026. The first public release was v1.0.0-beta.1 on April 18, 2026, and subsequent release titles show a rapid march through npm distribution, Linux portability, lockfile compatibility, lifecycle-script handling, warm-install performance, security gates, and pnpm parity.
The official README explains the central design: aube installs automatically when a script or binary is run, drops into existing projects using existing lockfiles, and emphasizes security defaults such as lifecycle-script approval, transitive dependency controls, and a 24-hour cooling window for brand-new releases.
Because aube is very new, adoption history is better described as packaging and compatibility positioning than long-term ecosystem penetration. The batch input shows Homebrew, Nix, and WinGet packaging, while the README also documents installation through mise, npm, npx, and Homebrew from the jdx tap.
The project deliberately targets migration paths instead of a clean-room ecosystem. Its README and docs say it reads and writes pnpm, npm, Yarn, Bun, and aube lockfiles in place, reads pnpm-compatible `.npmrc`, and can use existing `pnpm-workspace.yaml` files as migration inputs. That gives package nerds an obvious reason to watch it even before it has years of production history.
Day-to-day aube usage centers on running the command the developer actually wanted: `aubr test`, `aube test`, `aube exec vitest`, or `aubx cowsay hi`. If dependencies are missing or stale, aube installs first; if they are fresh, it skips straight to the script or binary.
Configuration is intentionally spread across familiar Node package-manager surfaces: `.npmrc`, user aube config, workspace YAML, `package.json`, environment variables, and CLI flags. The docs state that user config defaults to `~/.config/aube/config.toml` or `$XDG_CONFIG_HOME/aube/config.toml`, while registry tokens and npm-compatible auth live in `.npmrc` or a configured auth file.
aube is significant less because it has a long legacy and more because it is a snapshot of 2026 package-manager concerns: lockfile interoperability, global content-addressable stores, supply-chain gating, lifecycle-script isolation, runtime management, package-manager shims, and package-manager version pinning.
For Homebrew-style metadata, aube is also a reminder that JavaScript package managers are not only JavaScript packages. The official install paths include native release binaries, mise, npm installer scripts, and Homebrew, and the command set exposes multicall shims (`aube`, `aubr`, `aubx`) that all need to land correctly in a user's PATH.
security posture
No matching local secret-handling manifest was found for aube. Nucleus package metadata is still published here so future coverage has a stable package URL.
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
~/.config/aube/config.toml$XDG_CONFIG_HOME/aube/config.toml<cwd>/.npmrc<cwd>/.config/aube/config.toml<project>/aube-workspace.yaml<project>/pnpm-workspace.yaml<project>/package.jsonCredential-bearing paths to review before unattended agent runs.
<project>/.npmrc~/.npmrcpath configured by npmrc-auth-file / npmrcAuthFileexecutables
| Command | Kind | Exposure | Note |
|---|---|---|---|
aube | cli | global executable | |
aubr | cli | global executable | |
aubx | cli | global executable |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | brew:aube |
|---|---|
| Version | 1.32.0 |
| Package manager | Homebrew |
| Package manager page | https://formulae.brew.sh/formula/aube |
| Homepage | https://aube.en.dev |
| Repository | https://github.com/jdx/aube |
| Upstream docs | https://aube.jdx.dev/ |
| License | MIT |
| Source archive | https://github.com/jdx/aube/archive/refs/tags/v1.32.0.tar.gz |
| Last updated | 2026-07-22T03:29:38Z |
| Pulse | updated |
| Build dependencies | cmake, pkgconf, rust, usage |
| Bottle | available (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | not defined |
| Service | none declared |
registry facts
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | aube |
| Version Scheme | 0 |
| Revision | 0 |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
aube
nix profile install nixpkgs#aubeendev.aube
winget install --id endev.aube -esource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.