chef/omnibus
52.7
Adequate · 20 September 2026
16.2k
lines of production code
Ruby
primary language
1
measurement over time
What this system is
Omnibus is a Ruby-based command-line tool for building, packaging, and publishing software artifacts across multiple operating systems. It manages the entire build lifecycle by fetching source code, compiling dependencies, and generating native packages such as RPM, DEB, MSI, DMG, and APPX. The system supports publishing these packages to various destinations, including AWS S3 and Artifactory, while providing extensible infrastructure for versioning, caching, and CI metadata integration.
Features
Add APPX packager for Windows Store packages
Omnibus now supports building APPX packages for Windows via a new \Packager::APPX\ class. This packager generates the required \AppxManifest.xml\ and uses the \makeappx.exe\ tool to create the package archive. It supports optional code signing via a provided \signing\_identity\ and allows users to include custom assets from their project's resources directory.
lib/omnibus/packagers · high confidence
Added AppX package manifest template
A new ERB template for the AppX package manifest (AppxManifest.xml.erb) has been added to the resources/appx directory. This file defines the core structure for Windows AppX packages, including identity, properties, prerequisites (minimum OS version 6.3), and resource settings, using variables for name, version, publisher, and friendly name.
resources/appx · high confidence
Adds Makeself packaging resources and default installation script
The \resources/makeself\ directory now includes the Makeself v2.1.5 shell scripts (\makeself.sh\ and \makeself-header.sh\) used to generate self-extracting archives, along with a new \makeselfinst.erb\ template. This template defines the default installation behavior for the generated archives, which involves extracting files to a specified directory and executing an optional \postinst\ script if present.
resources/makeself · high confidence
Enable Chef Expeditor for automated builds, versioning, and PR verification
This change introduces Chef Expeditor configuration to automate the release lifecycle. Upon merging a pull request to the release branch, the system automatically bumps the patch version, updates the changelog, builds the gem, and publishes it to Rubygems when the project is promoted. It also adds a new CI pipeline that verifies pull requests by running linting and specs against Ruby 3.1, utilizing a custom script to cache bundler dependencies in S3 for faster execution.
.expeditor · high confidence
Initial project scaffolding and configuration files
The repository is initialized with essential configuration and documentation files, including a \.gitignore\ for common development artifacts, \.rspec\ for test runner settings, and \.rubocop.yml\ enforcing Ruby 2.6+ style guidelines. A \Rakefile\ is added to manage unit, functional, and acceptance tests via RSpec and Cucumber, alongside ChefStyle linting. The project also includes \README.md\ with usage instructions, \CHANGELOG.md\ tracking version history, \LICENSE\ (Apache 2.0), \CODE\_OF\_CONDUCT.md\, \MAINTAINERS.md\, \RELEASE\_NOTES.md\, and a \VERSION\ file set to 9.1.6.
(repo-wide) · high confidence
Introduce BuildVersion DSL and BuildSystemMetadata for build versioning
Omnibus now provides a dedicated DSL for constructing build versions, allowing projects to define version sources (such as Git or specific software dependencies) and output formats (like SemVer) directly in the project configuration. This change also introduces a BuildSystemMetadata class that integrates with CI environments like Buildkite to inject build metadata. These additions shift version string generation from implicit defaults to explicit, configurable project-level definitions.
lib/omnibus · high confidence
Introduce new compressor architecture with DMG, TGZ, and Null implementations
Omnibus now includes a new compressor framework located in lib/omnibus/compressors, providing distinct implementations for macOS DMG packaging, generic TGZ tarballs, and a Null compressor for no-op scenarios. The DMG compressor handles the full lifecycle of creating, attaching, and verifying disk images with configurable window bounds and asset positioning, while the TGZ compressor allows users to specify compression levels (1-9) for generating optimized tar.gz archives. This change establishes the structural foundation for how packages are compressed post-packaging, replacing previous ad-hoc logic with a standardized, extensible compressor interface.
lib/omnibus/compressors · high confidence
New Artifactory publisher and refactored S3 publisher
Omnibus now includes a new Artifactory publisher that uploads packages and their metadata files to an Artifactory repository, automatically creating build records with version and VCS information. The existing S3 publisher has been refactored to support AWS IAM role authentication and profile-based credentials, allowing for more flexible access control when publishing to S3 buckets.
lib/omnibus/publishers · high confidence
New Buildkite build metadata integration
Omnibus now automatically captures and includes build environment metadata from Buildkite CI jobs in the generated build manifest. This new capability reads specific environment variables (such as AWS AMI ID, hostname, Docker usage, and Docker image details) to provide richer context about the build infrastructure, enhancing traceability for builds executed on Buildkite.
lib · high confidence
Solaris IPS package generation templates added
New ERB templates for generating Solaris IPS (Image Packaging System) manifests and applying document transformations have been added. The manifest template defines package metadata including FMRI, description, summary, architecture variant, and classification. The transformation template applies specific edits to directory paths, dependency FMRI patterns for shell and system packages, and debug dependency file/path settings for Ruby, Make, and Perl environments.
resources/ips · high confidence
Behavioural changes
2 commits (0 fixes) modifying lib/omnibus/assets
A change to existing behaviour in lib/omnibus/assets — 2 commits, 2 files.
lib/omnibus/assets · medium confidence · unverified
AIX BFF packaging now includes generated config and template scripts
The BFF packager for AIX now automatically generates a post-install configuration script (config.erb) and a standardized package definition template (gen.template.erb). This ensures that every AIX package includes a config script regardless of whether the project provided one, and standardizes the fileset structure and file listing within the generated BFF package.
resources/bff · high confidence
Add Debian package control file templates
Added ERB templates for the Debian control file, conffiles, and md5sums, enabling the packager to generate these metadata files with support for package iteration, dependencies, conflicts, and file checksums.
resources/deb · high confidence
Configurable unsafe redirects and consistent Tempfile usage for URI opens
The \open\_uri\ extension now allows users to opt into insecure HTTP↔HTTPS redirects via the \allow\_unsafe\_redirects\ option, while still permitting safe HTTP→HTTPS upgrades by default. Additionally, \Kernel\#open\ is forced to always return a \Tempfile\ instead of a \StringIO\, ensuring consistent file handling regardless of download size.
_lib/omnibus/core\extensions · high confidence
Customized DMG layout via AppleScript
The DMG creation process now uses a new AppleScript template to customize the visual appearance of the disk image. This script configures the Finder window to use icon view, hides the toolbar and status bar, sets specific window bounds and icon sizes, and positions the installer package on the desktop background.
resources/dmg · high confidence
Introduce new Omnibus CLI entry point with clean shutdown and UTF-8 support
The bin/omnibus script now serves as the primary entry point for the CLI, ensuring clean termination by trapping INT signals and enforcing UTF-8 encoding globally to prevent issues with certificate chains on platforms lacking a UTF-8 locale. It also configures the load path to include the lib directory and enables stdout synchronization for reliable output.
bin · high confidence
RPM packaging logic and signing overhaul
The RPM generation process has been updated to use SHA256 file digest algorithms instead of MD5, disable build-id link creation, and exclude directories owned by the filesystem package via a new \filesystem\_list\ resource. RPM signing now utilizes a dedicated Ruby script (\signing.erb\) that handles passphrase prompts for both older and newer \rpmsign\ versions, and the spec template now maps \replaces\ dependencies to the \Obsoletes\ tag.
resources/rpm · high confidence
Redesigned Windows installer with bundled runtime and fast extraction
The Windows installer has been restructured to use a WiX bundle that automatically installs the Visual C++ 2012 Redistributable before launching the main application MSI. The installer now supports faster file extraction via a custom FastUnzip action powered by 7-Zip, and includes a new white-themed UI with a bundled license agreement. Additionally, the upgrade logic has been adjusted to enforce major upgrades, ensuring that newer versions replace existing installations.
resources/msi · high confidence
Refactored CLI into subcommands with new cache and changelog capabilities
The CLI has been restructured to use Thor subcommands, introducing \omnibus cache\ (with \existing\, \list\, \missing\, \fetch\, and \populate\ actions for managing S3 package caches) and \omnibus changelog generate\ (which creates release notes by comparing manifests and supports skipping components or bumping versions). The \omnibus publish\ command now uses subcommands (\s3\ and \artifactory\) and exposes platform mapping and region options, while deprecating the \--version-manifest\ flag in favor of metadata files. A new base command class standardizes configuration loading, logging, and help handling.
lib/omnibus/cli · high confidence
Refactored fetchers into separate files with new PathFetcher and enhanced Git/Net capabilities
The fetcher implementations have been extracted from a monolithic file into individual files (FileFetcher, GitFetcher, NetFetcher, NullFetcher, PathFetcher) to improve maintainability. A new PathFetcher has been added to allow sourcing software from local directories, supporting configurable file syncing options. The GitFetcher now supports cloning submodules (via the \:submodules\ option) and forcibly removes non-empty project directories before cloning to prevent conflicts. The NetFetcher has been enhanced to support S3 caching, authenticated HTTP URLs (via \:authorization\), cookies, configurable unsafe redirects, and a broader range of archive formats including .7z, .zip, .tar.xz, and .tar.lzma.
lib/omnibus/fetchers · high confidence
Restrict macOS package installation to the system volume
The macOS installer package generated by this tool now enforces installation exclusively on the local system volume. This is achieved by updating the distribution XML template to set \enable\_anywhere\ and \enable\_currentUserHome\ to false, while enabling \enable\_localSystem\. Users installing these packages will no longer have the option to install to the current user's home directory or arbitrary locations; the software will be installed to the standard system location.
resources/pkg · high confidence
Simplified Debian package lifecycle scripts
The generated Debian package scripts (postinst, postrm, preinst, prerm) have been replaced with minimal, POSIX-compliant shell scripts. These scripts now provide basic user feedback during installation and removal phases (e.g., printing confirmation messages) and include simple error-handling utilities, ensuring compatibility with older Unix environments while removing any previous complex logic.
_lib/omnibus/generator\_files/package\scripts · high confidence
Updated default project and software generator templates
The generator templates for new projects have been updated to produce valid, ready-to-use configurations. The project template now uses \default\_root\ for the install directory and includes sensible default exclude patterns for \.git\ and bundler git directories. A new \preparation\ software template has been added to handle build directory setup, and the \zlib\ software template has been updated to use the \workers\ DSL method for parallel builds instead of hardcoded job counts.
_lib/omnibus/generator\files/config · high confidence
Updated project generator templates for modern Chef and Test Kitchen configurations
The files generated by the Omnibus project generator have been updated to use Chef Zero as the default provisioner in .kitchen.yml, switch the Berkshelf source to Chef Supermarket, and include integration group dependencies for apt, freebsd, and yum-epel cookbooks. The generated Gemfile now places Berkshelf and Test Kitchen in a development group, and the omnibus.rb template includes new configuration options for Windows architecture defaults, S3 IAM role ARN support, and fetcher read timeouts. Additionally, a new .kitchen.local.yml template allows for easy driver customization, and the README has been updated to reflect the 'omnibus manifest' command and current platform support.
_lib/omnibus/generator\files · high confidence
Test coverage
Add Aruba-based integration testing infrastructure; Add step definitions for omnibus project generation and platform mappings; Added feature tests for Omnibus CLI commands; Added functional tests for Builder, FileSyncer, Licensing, and Templating; Added functional tests for file, git, net, and path fetchers; Added test support helpers for environment, file operations, and Git; Added unit tests for Artifactory and S3 publishers; Added unit tests for BuildVersion, Builder, Buildkite, and ChangeLog components; Added unit tests for all packager implementations; Added unit tests for compressor implementations; Establishes centralized RSpec test configuration and helpers.
Dependencies
Omnibus gemspec modernization and dependency updates
The omnibus gemspec has been modernized to require Ruby 3.0 or later and updated with current production dependencies, including aws-sdk-s3 (\~\> 1.116.0), chef-utils (\>= 15.4), chef-cleanroom (\~\> 1.0), ohai (\>= 18.2.6, \< 19), and license\_scout (\~\> 1.4.0). Development dependencies have also been refreshed, specifying chefstyle 2.2.2, fauxhai-ng (\>= 7.5), and aruba (\~\> 2.0). The Gemfile now delegates to the gemspec and organizes documentation and debugging gems into specific groups, while the legacy Gemfile.lock has been removed.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 53.
Lenses
- Code Health 95
- Architecture 98
- Maturity 60
- Readiness 50
- Security 90
- Accessibility 40
Changes since last survey
- 300 commits — 270 feature/other, 30 fixes
By area
- (root) — 128 commits
- (repo) — 81 commits
- lib/omnibus — 69 commits
- spec/unit — 8 commits
- .expeditor/verify.pipeline.yml — 4 commits
- .expeditor/config.yml — 2 commits
- resources/rpm — 2 commits
- .github/CODEOWNERS — 1 commit
- .github/PULL_REQUEST_TEMPLATE.md — 1 commit
- .github/dependabot.yml — 1 commit
- docs/Overview.md — 1 commit
- resources/msi — 1 commit
- spec/support — 1 commit
Notable commits
- fix: Chefstyle fixes
- fix: Fix Ruby 3.1 deprecation warning with ERB.new (#1108)
- fix: Fix and add specs
- fix: Fix mac_x-10 failure for chef-workstation
- fix: Fix misc breakages and extract solaris-specific method
- fix: Fix omnibus healthcheck spinning on chef-server builds
- fix: Fix pathing for go on windows
- fix: Fix rpath in LDFLAGS for FreeBSD
- fix: Fixed bad constant reference (#1112)
- fix: Fixes for omnibus for ruby-3.0
- fix: INFC-268 fix solaris build
- fix: Merge pull request #1024 from chef/jgarud/fix-arguments-pattern-ruby3
- fix: Merge pull request #1041 from chef/fix-mac10-failure-for-chef-workstation
- fix: Merge pull request #1042 from chef/jsnapp/revert-whitelist-libbrotlidec
- fix: Merge pull request #1054 from vkarve-chef/vkarve/fix-typo-arg
- fix: Merge pull request #1097 from chef/fix-pr-template
- fix: Merge pull request #1154 from chef/CHEF-14201-fix-bundler-install
- fix: Merge pull request #1155 from chef/poorndm/revert-train-core-changes
- fix: Revert "DF - updating copyright to PTC's based"
- fix: Revert "Fix mac_x-10 failure for chef-workstation"
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
chef/omnibus was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e55f9bc189d721ddbe34d6e5cc188147c328936b — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.