Automic VaultAutomic Vault

brew

Install aube with Homebrew, Nix, winget

Fast Node.js package manager. Version 1.32.0 via Homebrew; verified 2026-07-22. Also installable with nix: nix profile install nixpkgs#aube.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install aube

local Homebrew formula metadata

Linux

Nixverified · 92%
nix profile install nixpkgs#aube

nixpkgs package indexes · pkgs/by-name/au/aube/package.nix · source: api.github.com

Windows

Windows Package Managerverified · 92%
winget install --id endev.aube -e

Windows Package Manager source index · endev.aube · source: cdn.winget.microsoft.com

overview

Package summary

Fast Node.js package manager

Commands and aliases

  • aube
  • aubr
  • aubx

history

Project history and usage

aube is a 2026 Node.js package manager focused on automatic installs before scripts, pnpm-compatible configuration and lockfile workflows, and stricter supply-chain defaults. Its history is short, but unusually dense: the public beta, v1.0 release train, and rapid follow-up releases all happened within months.

Project history

The GitHub repository was created in April 2026. The first public release was v1.0.0-beta.1 on April 18, 2026, and subsequent release titles show a rapid march through npm distribution, Linux portability, lockfile compatibility, lifecycle-script handling, warm-install performance, security gates, and pnpm parity.

The official README explains the central design: aube installs automatically when a script or binary is run, drops into existing projects using existing lockfiles, and emphasizes security defaults such as lifecycle-script approval, transitive dependency controls, and a 24-hour cooling window for brand-new releases.

Adoption history

Because aube is very new, adoption history is better described as packaging and compatibility positioning than long-term ecosystem penetration. The batch input shows Homebrew, Nix, and WinGet packaging, while the README also documents installation through mise, npm, npx, and Homebrew from the jdx tap.

The project deliberately targets migration paths instead of a clean-room ecosystem. Its README and docs say it reads and writes pnpm, npm, Yarn, Bun, and aube lockfiles in place, reads pnpm-compatible `.npmrc`, and can use existing `pnpm-workspace.yaml` files as migration inputs. That gives package nerds an obvious reason to watch it even before it has years of production history.

How it is used

Day-to-day aube usage centers on running the command the developer actually wanted: `aubr test`, `aube test`, `aube exec vitest`, or `aubx cowsay hi`. If dependencies are missing or stale, aube installs first; if they are fresh, it skips straight to the script or binary.

Configuration is intentionally spread across familiar Node package-manager surfaces: `.npmrc`, user aube config, workspace YAML, `package.json`, environment variables, and CLI flags. The docs state that user config defaults to `~/.config/aube/config.toml` or `$XDG_CONFIG_HOME/aube/config.toml`, while registry tokens and npm-compatible auth live in `.npmrc` or a configured auth file.

Why package nerds care

aube is significant less because it has a long legacy and more because it is a snapshot of 2026 package-manager concerns: lockfile interoperability, global content-addressable stores, supply-chain gating, lifecycle-script isolation, runtime management, package-manager shims, and package-manager version pinning.

For Homebrew-style metadata, aube is also a reminder that JavaScript package managers are not only JavaScript packages. The official install paths include native release binaries, mise, npm installer scripts, and Homebrew, and the command set exposes multicall shims (`aube`, `aubr`, `aubx`) that all need to land correctly in a user's PATH.

Timeline

  • 2026-04: Repository created and v1.0.0-beta.1 published as the first public release.
  • 2026-04: Early beta releases added npm distribution, Linux portability, lockfile compatibility, and warm-install improvements.
  • 2026-05: v1.13 and later releases emphasized supply-chain gates, OSV checks, lifecycle-script content sniffing, Yarn Berry compatibility, and pnpm parity.
  • 2026-06: v1.18.2 noted the project move to jdx; v1.25.1 refreshed benchmarks.

Related projects

  • pnpm: aube reads pnpm-compatible configuration and existing pnpm workspace files.
  • npm and Yarn: aube reads shared `.npmrc` registry/auth settings and existing lockfiles.
  • Bun: aube compares against Bun in benchmarks and supports Bun lockfiles.
  • mise: the README recommends mise as the primary install and runtime-management path.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for aube. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Build metadata lists 4 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.config/aube/config.toml$XDG_CONFIG_HOME/aube/config.toml<cwd>/.npmrc<cwd>/.config/aube/config.toml<project>/aube-workspace.yaml<project>/pnpm-workspace.yaml<project>/package.json

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
<project>/.npmrc~/.npmrcpath configured by npmrc-auth-file / npmrcAuthFile

executables

Installed executables

CommandKindExposureNote
aubecliglobal executable
aubrcliglobal executable
aubxcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-07-25
manager version1.32.0
manager updated2026-07-22
local dataok
upstreamcurrent
latest detectedv1.32.0

https://github.com/jdx/aube

  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:aube
Version1.32.0
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/aube
Homepagehttps://aube.en.dev
Repositoryhttps://github.com/jdx/aube
Upstream docshttps://aube.jdx.dev/
LicenseMIT
Source archivehttps://github.com/jdx/aube/archive/refs/tags/v1.32.0.tar.gz
Last updated2026-07-22T03:29:38Z
Pulseupdated
Build dependenciescmake, pkgconf, rust, usage
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameaube
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

aube

nix profile install nixpkgs#aube
  • normalized package name match
  • Matched by: Aube
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/au/aube/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
winget95%

endev.aube

winget install --id endev.aube -e
  • normalized package name match
  • Matched by: Aube
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: endev.aube from https://cdn.winget.microsoft.com/cache/source.msix

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment