Automic VaultAutomic Vault

brew

使用 Homebrew, chocolatey 安装 graalvm

查看 graalvm 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

安装

其他安装命令

macOS

Homebrew已验证 · 100%
brew install graalvm

local Homebrew formula metadata

概览

软件包摘要

JDK distribution with Graal compiler and Native Image

命令和别名

  • native-image
  • native-image-configure

历史

项目历史与用法

GraalVM is Oracle Labs' high-performance JDK and language-runtime project built around the Graal compiler, the Truffle language implementation framework, and Native Image ahead-of-time compilation. In package-manager terms it is a JDK distribution with extra runtime and native-compilation tooling, so installing it is closer to selecting a Java toolchain than installing a single application.

The Homebrew package is significant because it gives macOS and Unix-like developers a normal package-manager route to `native-image` and the GraalVM JDK. That matters for build scripts, CI jobs, Java microservices, and framework ecosystems that test against or produce GraalVM Native Image binaries.

项目历史

Oracle Labs describes GraalVM as a runtime for Java and JVM languages, JavaScript, Python, WebAssembly, and other languages that can run standalone or embedded in OpenJDK, Oracle JDK, Oracle Database, and MySQL. The project grew from Oracle Labs compiler and VM research led around the Graal dynamic compiler and the Truffle self-optimizing runtime system.

GraalVM's public pre-production line used 1.0 release candidates in 2018. Those releases show the package becoming more than a compiler experiment: artifacts moved toward the `org.graalvm` coordinates, Native Image pieces were published to Maven Central, and the distribution carried language runtimes, SDK APIs, tools, and the Substrate VM implementation behind Native Image.

The source repository `oracle/graal` brings together the compiler, SDK, SubstrateVM, Truffle, language runtimes and related tools. That monorepo shape is part of the project's identity: GraalVM is not only a JDK build, but also a platform for language implementers and ahead-of-time compilation research.

采用历史

GraalVM adoption in the Java ecosystem has been tied to two overlapping use cases: using the Graal compiler as an optimizing JIT, and using Native Image to build standalone executables with fast startup and lower resource use. The latter became especially visible in cloud-native Java, where container startup time and memory footprint are package-level concerns.

Oracle's 2023 licensing change made Oracle GraalVM for JDK 17, JDK 20, and following releases available under the GraalVM Free Terms and Conditions, including commercial production use subject to the license terms. That reduced a practical adoption barrier for teams that needed Oracle-provided builds rather than only community builds.

Oracle later described a shift in Java-runtime strategy: GraalVM technologies were aligned with the Java release cadence after years of research, the Graal JIT informed Oracle JDK work, and Native Image work informed OpenJDK Project Leyden. For package users, that means GraalVM sits at the intersection of a shipping JDK distribution and upstream Java platform experiments.

使用方式

Developers use GraalVM as a Java Development Kit in IDEs and build tools, then opt into Native Image through the `native-image` command or build plugins. The Native Image docs describe compiling Java code ahead of time into a native executable that includes only reachable application, library, runtime, and statically linked JDK code for a target operating system and architecture.

Typical command-line and package-manager usage revolves around setting `JAVA_HOME`, ensuring a local C toolchain is available, and running Maven or Gradle Native Image plugins. The Homebrew package exposes the JDK and tools such as `native-image` and `native-image-configure`, making it convenient for repeatable local builds.

The package also has a metadata angle: Native Image needs reachability metadata for dynamic Java features such as reflection, resources, and service loading. The curated path `META-INF/native-image/<groupId>/<artifactId>/reachability-metadata.json` reflects that package-ecosystem convention.

为什么软件包爱好者会关心

GraalVM is package-nerd bait because it blurs boundaries between compiler, JDK, language runtime, and build artifact. Installing it can change Java bytecode execution, native executable generation, container image size, startup behavior, and dependency metadata requirements.

Its release and licensing history also affects distribution policy. Packagers need to distinguish GraalVM Community Edition licensing from Oracle GraalVM licensing, match builds to JDK baselines, and expose tooling in a way that works with `JAVA_HOME`, Gradle, Maven, CI runners, and architecture-specific native toolchains.

For Homebrew users, `brew install graalvm` is a practical way to obtain a specialized Java toolchain while keeping the installation visible to scripts and package-manager audits.

时间线

  • 2018: GraalVM 1.0 release candidates documented polyglot runtimes, Maven artifacts, Native Image work, and SDK/API changes.
  • 2018-10: GraalVM 1.0-RC8 documented Native Image Maven integration and Maven Central publication of Substrate VM components.
  • 2019: GraalVM moved from the 1.0 release-candidate era into production-oriented release lines.
  • 2022: Oracle Labs announced alignment of GraalVM technology development with Java release cadence.
  • 2023: Oracle announced the GraalVM Free Terms and Conditions for Oracle GraalVM releases beginning with JDK 17 and JDK 20.
  • 2026: GraalVM release-calendar documentation describes monthly feature releases from the 25.1 line with quarterly CPU updates.

Related projects

  • OpenJDK is the Java platform baseline that GraalVM builds on and tracks.
  • Truffle is the language implementation framework used by GraalVM language runtimes.
  • SubstrateVM is the Native Image implementation area in the Graal repository.
  • GraalJS, GraalPy, GraalWasm, Espresso, Sulong, Native Build Tools, and the GraalVM reachability metadata repository are adjacent GraalVM ecosystem projects.
  • Project Leyden is related through ahead-of-time Java work that Oracle says was informed by Native Image.

安全态势

尚未找到受保护工具覆盖

没有找到 graalvm 的匹配本地密钥处理 manifest。Nucleus 软件包元数据仍在此发布,以便未来覆盖拥有稳定的软件包 URL。

安装行为

  • formula 元数据中未记录 Homebrew post-install 钩子。
  • Homebrew bottle 元数据适用于 5 个平台目标。
  • 安装时包含 6 个运行时依赖。
  • 构建元数据列出 5 个构建依赖。

建议审查

在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
META-INF/native-image/<groupId>/<artifactId>/reachability-metadata.json

可执行文件

已安装的可执行文件

命令类型暴露范围备注
native-imagecli全局可执行文件
native-image-configurecli全局可执行文件

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-07-25
管理器版本25.1.3
管理器更新时间2026-07-05
本地数据OK
上游not checked
检测到的最新版本未检测到

https://github.com/oracle/graal

安装元数据

软件包元数据

软件包键brew:graalvm
版本25.1.3
软件包管理器Homebrew
软件包管理器页面https://formulae.brew.sh/formula/graalvm
主页https://www.graalvm.org/
仓库https://github.com/oracle/graal
上游文档https://www.graalvm.org/latest/docs
许可证GPL-2.0-only WITH Classpath-exception-2.0
源码归档https://github.com/oracle/graal/archive/refs/tags/graal-25.1.3.tar.gz
最后更新2026-07-05T23:51:35Z
Pulseupdated
依赖freetype, giflib, harfbuzz, jpeg-turbo, libpng, little-cms2
构建依赖autoconf, mx, ninja, openjdk@25, pkgconf
Bottle可用 (于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, x86_64_linux)
Homebrew post-install未定义
服务未声明

注册表事实

源数据库详情

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namegraalvm
Version Scheme0
Revision0
Requirements
  • arch
  • xcode
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyyes
URL Keys
  • stable

源数据库匹配

其他软件包管理器记录

匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。

Chocolatey95%

graalvm

choco install graalvm
  • normalized package name match
  • 匹配方式:Graalvm
Chocolatey community package catalog · community.chocolatey.org · Chocolatey community package catalog: graalvm from http://community.chocolatey.org/api/v2/Packages?$filter=IsLatestVersion&$select=Id&$top=1000&$skiptoken='7.756','razer-synapse-3'

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment