Skip to content
CAI
Software that uses CAICheck a score

Homebrew/brew

69.9

Adequate · 26 September 2026

135k

lines of production code

Ruby

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the core implementation of Homebrew, a package manager for macOS and Linux that installs, manages, and configures software formulae and casks. It provides a comprehensive command-line interface for dependency resolution, build environment management, and service control, while enforcing code quality through extensive static analysis and linting tools. The codebase also includes infrastructure for automated testing, vulnerability scanning, and API-driven package metadata synchronization.

How it got here

2009–2017 — Linux support and type safety

46 changes.

This period focused on establishing first-class Linux support by introducing OS-specific modules, portable Ruby binaries, and a unified dispatch layer for platform logic. Concurrently, the codebase underwent a major architectural overhaul to enforce strict type safety using Sorbet, standardize development tooling, and restructure core components like environment handling and build shims.

2018–2021 — Sorbet typing and tooling modernization

59 changes.

This period focused on modernizing the Homebrew codebase by introducing Sorbet strict typing across core components like the CLI, cask DSL, and RuboCop infrastructure. It also involved significant refactoring of archive handling, livecheck strategies, and shell completion generation to improve reliability and developer experience.

2022–2026 — Sorbet typing and modularization

79 changes.

This period focused on enforcing strict static type checking across the codebase by migrating DSL and command definitions to autogenerated Sorbet RBI files via Tapioca compilers. It simultaneously restructured monolithic command implementations into modular, strictly-typed subcommand classes and integrated external features like bundle and services into the core repository.

Features

Add Object\#deep\_dup for safe deep copying of objects

Users can now use the new \Object\#deep\_dup\ method to create a deep copy of an object if it is duplicable, or receive the original object if it is not. This utility, implemented in \Library/Homebrew/extend/object/deep\_dup.rb\ and supported by a \duplicable?\ check in \Library/Homebrew/extend/object/duplicable.rb\, provides a safer and more performant alternative to exception-based duplication strategies for arbitrary objects.

Library/Homebrew/extend/object · high confidence

Add Tapioca RBI compilers for Cask DSL, Config, and Caveats

This change introduces new Tapioca compiler files that generate Sorbet RBI type signatures for Cask components. Specifically, it adds compilers for \Cask::DSL\ (generating method signatures for artifact classes and blocks), \Cask::Config\ (generating accessors for configuration keys with specific return types like \Pathname\ or \Boolean\), and \Cask::DSL::Caveats\ (generating method signatures for caveat names). These additions improve static type checking and IDE support for Cask-related code within Homebrew.

Library/Homebrew/sorbet/tapioca/compilers/cask · high confidence

Add Vernier fork guard for profiling

Introduces a new \VernierForkGuard\ utility module that safely manages the Vernier profiling gem during forking operations. This prevents the Vernier autorun collector from interfering with child processes, ensuring accurate profiling data when Homebrew commands are executed in parallel or forked environments.

Library/Homebrew/utils · high confidence

Add atomic file writing capability

Users can now write to files atomically using the new File.atomic\_write method, which ensures that other processes or threads do not see partially written data by writing to a temporary file first and then renaming it to the target location. This method preserves the original file's permissions and ownership where possible, providing a safer way to update configuration or data files without risking corruption.

Library/Homebrew/extend/file · high confidence

Add deep merge and key/value transformation methods to Hash

The \Library/Homebrew/extend/hash\ module now provides new methods for recursively merging and transforming hashes. \deep\_merge\ and \deep\_merge!\ allow merging nested hashes with an optional block to resolve conflicts, while \deep\_transform\_values\ and \deep\_transform\_keys\ (including destructive variants) apply blocks to all values or keys across nested structures. Additionally, \deep\_stringify\_keys\ and \deep\_symbolize\_keys\ are available to convert all keys to strings or symbols respectively. Type signatures (.rbi) are included for Sorbet compatibility.

Library/Homebrew/extend/hash · high confidence

Add macOS 11 pkg-config files for SDK libraries

Added pkg-config (.pc) files for common system libraries (such as bzip2, expat, libcurl, libxml2, sqlite3, and zlib) to the macOS 11 SDK path. This allows formulae that rely on pkg-config to correctly locate and link against these libraries when building against the macOS 11 SDK.

Library/Homebrew/os/mac/pkgconfig/11 · high confidence

Add macOS 13 SDK pkgconfig files for system libraries

Added .pc files for system libraries (bzip2, expat, libcurl, libedit, libexslt, libffi, libxml-2.0, libxslt, ncurses, ncursesw, sqlite3, uuid, zlib) targeting the macOS 13 SDK. This enables formulae to correctly locate and link against these system-provided libraries when building on macOS 13.

Library/Homebrew/os/mac/pkgconfig/13 · high confidence

Add macOS 15 (Sequoia) pkg-config files

Added a new set of pkg-config (.pc) files for the macOS 15 SDK, including definitions for bzip2, expat, libcurl, libedit, libexslt, libffi, libxml-2.0, libxslt, ncurses, sqlite3, uuid, and zlib. These files enable formulae to correctly locate and link against system libraries when building on macOS 15 (Sequoia).

Library/Homebrew/os/mac/pkgconfig/15 · high confidence

Add portable Ruby 4.0.7 for arm64 Linux

This change introduces support for the arm64 Linux platform by adding a new portable Ruby binary configuration (portable-ruby-arm64-linux) alongside existing Darwin and x86\_64 Linux variants. The portable Ruby version is bumped to 4.0.7, ensuring that users on arm64 Linux systems can now utilize the bundled, portable Ruby environment for Homebrew operations, matching the capabilities already available for macOS and x86\_64 Linux.

Library/Homebrew/vendor · high confidence

Add strict-typed IRB helper for debrew debugging

The debrew tool now includes a dedicated IRB helper module (\debrew/irb.rb\) that provides a \start\_within\ method for launching an interactive Ruby session within a specific binding. This helper is configured with Sorbet strict typing and frozen string literals, ensuring consistent debugging behavior and type safety during development workflows.

Library/Homebrew/debrew · high confidence

Added Sorbet RBI annotations for Minitest and Rainbow

New Sorbet RBI annotation files have been added for the Minitest and Rainbow libraries to improve static type checking. The \minitest.rbi\ file defines signatures for assertion and refutation methods within \Minitest::Assertions\, while \rainbow.rbi\ provides type signatures for the \Rainbow\ module, including its color classes and presenter methods. A \.gitattributes\ file was also added to mark these generated RBI files as vendored.

Library/Homebrew/sorbet/rbi/annotations · high confidence

Added Sorbet RBI type signatures for parser gem and upstream workarounds

This change introduces static type definitions to improve type checking coverage in Homebrew. It adds an autogenerated RBI file for the \parser\ gem (version 3.3.8.0), providing type signatures for its AST nodes and processors. Additionally, it creates a new \upstream.rbi\ file containing strict type definitions for \Integer\ and \JSON::Coder\ to address known Sorbet issues pending upstream fixes, replacing previous local workarounds.

Library/Homebrew/sorbet/rbi · high confidence

Added Sublime Text project configuration for Homebrew

A new Sublime Text project file (homebrew.sublime-project) has been added to configure the editor for the Homebrew repository. This setup defines the project root, excludes specific Homebrew internal directories (such as Caskroom, Cellar, and Library/Homebrew paths) to improve performance and relevance, follows symlinks, and sets the tab size to 2 spaces.

.sublime · high confidence

Added deep\_dup and compact\_blank methods to core Ruby classes

The library now includes \deep\_dup\ methods for \Array\, \Hash\, and \Module\, allowing users to create deep copies of complex nested structures where modifications to the copy do not affect the original. Additionally, a \compact\_blank\ method has been added to \Hash\ to remove key-value pairs where the value is blank. These utilities are implemented as extensions to the standard Ruby classes within the Homebrew codebase.

_Library/Homebrew/extend/enumerable, Library/Homebrew/extend/object/deep\dup · high confidence

Added macOS 14 pkgconfig files for system libraries

New pkgconfig definition files have been added to the macOS 14 (Sonoma) SDK directory to support build tools for libraries including bzip2, expat, libcurl, libedit, libexslt, libffi, libxml-2.0, libxslt, ncurses, sqlite3, uuid, and zlib. These files provide the necessary compiler and linker flags for formulae that depend on these system-provided libraries on the new macOS version.

Library/Homebrew/os/mac/pkgconfig/12, Library/Homebrew/os/mac/pkgconfig/14 · high confidence

Added pkg-config files for macOS 26 (Tahoe)

Added a new set of pkg-config definition files for the macOS 26 SDK, enabling build tools to correctly locate and link against system libraries on the upcoming macOS version. The directory now includes definitions for bzip2 (1.0.8), expat (2.7.4), libcurl (8.7.1), libedit (3.0), libexslt (0.8.20), libffi (3.4-rc1), libxml2 (2.9.13), libxslt (1.1.35), ncurses (6.0.20150808), sqlite3 (3.51.0), uuid (1.0), and zlib (1.2.12), all pointing to the MacOSX26.sdk path.

Library/Homebrew/os/mac/pkgconfig/26 · high confidence

Added shims for RuboCop and the Ruby debugger (rdbg)

New executable shims have been added to the Homebrew shims directory to provide consistent access to RuboCop and the Ruby debugger (rdbg). The RuboCop shim delegates execution to the \brew rubocop\ command, ensuring it runs within the Homebrew environment. The rdbg shim sets a specific environment variable and executes the debugger binary using Homebrew's portable Ruby, which supports debugging workflows, including those in VS Code.

Library/Homebrew/shims/gems · high confidence

Audit command now supports --new-formula option

The \brew audit\ command now accepts a \--new-formula\ flag, allowing developers to run audit checks specifically on newly created or uncommitted formulae without requiring them to be committed to a tap first. This enables earlier validation of new packages during the development workflow.

Library/Homebrew/dev-cmd · high confidence

Autogenerated Sorbet RBI DSL signatures added

The \Library/Homebrew/sorbet/rbi/dsl\ directory now contains autogenerated Sorbet RBI files for core DSL classes including Formula, Resource, Bottle, Caveats, Checksum, ExternalPatch, Keg, Livecheck, PATH, PkgVersion, ResourceStageContext, SoftwareSpec, HeadSoftwareSpec, and Tty. These files provide type signatures for dynamic DSL methods (such as \on\_arm\, \on\_macos\, \deprecate!\, \disable!\, and \no\_autobump!\), enabling static type checking and improved IDE support for Homebrew formula and cask definitions.

Library/Homebrew/sorbet/rbi/dsl · high confidence

Comprehensive RuboCop audit framework for Homebrew formulae and casks

The \Library/Homebrew/rubocops\ directory has been restructured into a unified, Sorbet-typed RuboCop plugin that enforces consistent style and correctness across Homebrew formulae and casks. This change introduces a wide range of new and refactored cops that automatically detect and correct issues such as bottle block formatting and ordering, dependency ordering, component precedence, deprecated checksums, unsafe file removal patterns, and improper API usage. It also adds specific checks for cask stanzas, shell command safety, and public API documentation, providing users with immediate, auto-correctable feedback on their formula and cask code during \brew style\ checks.

Library/Homebrew/rubocops · high confidence

Formulae can now be deprecated or disabled with a specific date

The Homebrew core tap maintainers can now schedule the deprecation or disabling of formulae for a future date. This change introduces new DSL methods (\deprecate!\ and \disable!\) that accept a \no\_longer\_meets\_criteria\ reason and a \disable\_date\. When a formula reaches this date, Homebrew will automatically warn users that the formula is deprecated or disabled, providing a smoother transition path for users before the formula is eventually removed from the repository.

Library/Homebrew · high confidence

Initial Sorbet configuration for Homebrew

A new Sorbet type-checking configuration file has been added to the Homebrew codebase. This configuration enables experimental features such as \requires\_ancestor\ and \rspec\ modes, while explicitly ignoring vendor directories, test gems, and the Formula and Casks directories to focus type-checking on core logic.

Library/Homebrew/sorbet · high confidence

Initial VS Code Dev Container configuration for Codespaces

Added a new \.devcontainer\ setup that enables development within GitHub Codespaces using the \ghcr.io/homebrew/brew:main\ image. The configuration pre-installs a curated list of VS Code extensions (including Ruby LSP, Sorbet, and Docker tools) and runs an \onCreateCommand\ script to fix file permissions, install development dependencies (such as \shellcheck\, \gh\, and \bash-completion\), and start the SSH server to support \gh cs ssh\. This change also disables interactive prompts during prebuilds to ensure non-interactive environments do not hang.

.devcontainer · high confidence

Introduce CaskStruct generator for internal API serialization

A new \CaskStructGenerator\ module has been added to the internal API to handle the conversion of raw cask data into structured \CaskStruct\ instances. This change enables the serialization of complex cask attributes, including language variations, macOS and Linux dependencies, URL specs (with deprecated fields filtered out), and artifact stanzas (ignoring the \target\ key). It also ensures that \ruby\_source\_checksum\ is correctly populated and that boolean presence flags are derived from the data, providing a consistent internal representation for cask metadata.

Library/Homebrew/api/cask · high confidence

Introduce FormulaCop base class for formula-specific RuboCop audits

A new \FormulaCop\ base class has been added to the RuboCop extend module to centralize logic for auditing Homebrew formulas. This class provides shared helper methods for detecting dependencies, URLs, caveats, and checksums, allowing specific audit cops to inherit this behavior rather than duplicating code. It also includes Sorbet strict typing and abstracts the entry point for formula class analysis, improving the maintainability and consistency of formula-related style checks.

Library/Homebrew/rubocops/extend · high confidence

Introduce FormulaStructGenerator for API formula data processing

The \Library/Homebrew/api/formula\ area now includes a new \FormulaStructGenerator\ module that transforms raw API formula data into structured \FormulaStruct\ instances. This generator handles the conversion of bottle checksums, dependency lists (stable and head), requirements, service configurations, and license information (including SPDX expression conversion), ensuring that formula metadata consumed via the API is consistently formatted and validated before use.

Library/Homebrew/api/formula · high confidence

Introduce Homebrew vulnerability scanning and advisory matching infrastructure

This change adds a comprehensive vulnerability scanning and advisory-matching system to Homebrew. It introduces a \CachedFeed\ base class for loading and caching upstream JSON feeds, including a new \AdvisoryDatabase\ reader for the Homebrew advisory corpus and a \CPANSec\ loader for Perl security advisories. The system includes an \Identify\ module to derive OSV.dev query keys from formula source URLs and registry packages, and a \Match\ class that performs versionless queries against OSV.dev, Repology, and CPANSA to evaluate affected ranges. It also provides \AdvisoryOverrides\ for reviewed corrections, a \History\ walker for git-based boundary derivation, and an \OsvExport\ module to emit OSV-schema records for the Homebrew ecosystem.

Library/Homebrew/vulns · high confidence

Introduce OS-specific extension layer for Linux support

This change introduces a new \extend/os\ directory structure that acts as a dispatch layer, conditionally requiring OS-specific implementations (macOS or Linux) for core Homebrew components such as bottle specifications, cask installation, environment setup, and diagnostics. For Linux, this enables specific behaviors like using the user's primary group for the Caskroom directory, skipping macOS-only bundle services, and handling Linux-specific cask artifacts (e.g., using \cp --reflink=auto\ for moved artifacts and ignoring extended attributes for relocated ones). This architectural shift allows Homebrew to maintain a unified codebase while applying necessary platform-specific logic, effectively laying the groundwork for first-class Linux support.

Library/Homebrew/extend/os · high confidence

Introduce \`brew alias\` and \`brew unalias\` commands

Users can now create, manage, and edit custom command aliases using the new \brew alias\ and \brew unalias\ commands. This change introduces the \Library/Homebrew/aliases\ module, which handles the creation of shell scripts in the Homebrew aliases directory and symlinks them to \HOMEBREW\_PREFIX/bin\ for immediate availability. The implementation includes logic to prevent conflicts with existing Homebrew commands and reserved names, and supports both simple command shortcuts and custom script aliases.

Library/Homebrew/aliases · high confidence

Introduce \`brew completions\` subcommand for managing shell completions

Homebrew now includes a new \brew completions\ command with \link\, \unlink\, and \state\ subcommands, allowing users to easily enable, disable, and check the status of shell completions for Bash, Zsh, and Fish. This replaces the previous manual installation process, with the completion scripts themselves being automatically generated from ERB templates and cached for performance.

Library/Homebrew/completions · high confidence

Introduce \`brew formula-analytics\` command with Python-based InfluxDB querying

Adds the \brew formula-analytics\ and \generate-analytics-api\ commands, implemented in a new \Library/Homebrew/formula-analytics\ directory. The tooling uses a Python 3.13+ virtual environment (managed via uv) to run \influxdb-query.py\, which executes SQL queries against InfluxDB Cloud Serverless via Arrow Flight (gRPC) and streams results as JSON Lines to the Ruby-based brew command. This replaces the previous PyCall-based approach with a subprocess-based Python script to avoid heavyweight native dependencies, requiring the \HOMEBREW\_INFLUXDB\_TOKEN\ environment variable for authentication.

Library/Homebrew/formula-analytics · high confidence

Introduce dedicated Language modules for Java, Node, Perl, PHP, and Python

Homebrew now provides structured, type-strict helper modules for managing language-specific formulae. The new Language::Java module adds support for detecting and configuring OpenJDK installations via \java\_home\ and \java\_home\_env\. Language::Node introduces secure npm installation workflows, including script ignoring, cache isolation, and shebang rewriting. Language::Perl and Language::PHP add shebang detection and rewriting capabilities. Language::Python consolidates Python-specific logic, including virtualenv support, site-package management, and shebang rewriting, while deprecating several older helper methods.

Library/Homebrew/language · high confidence

Introduce generated Fish shell completions for Homebrew

Homebrew now provides a comprehensive set of Fish shell completions via the new \completions/fish/brew.fish\ file. This file is automatically generated from the command documentation and replaces previous manual or incomplete completion scripts. It supports full command and subcommand completion, expands common aliases (such as \ls\ to \list\), and offers context-aware suggestions for formulae, casks, taps, and installed packages. Users benefit from a consistent and up-to-date command-line experience in the Fish shell without needing to maintain custom completion files.

completions/fish · high confidence

Introduce generated manpages directory

The repository now includes a dedicated \manpages/\ directory containing the generated Homebrew manual pages (such as \brew.1\) and a \README.md\ explaining that these files are produced by the \brew generate-man-completions\ command from \CLI::Parser\ definitions and repository documentation.

manpages · high confidence

Introduce new \`brew livecheck\` command architecture

The \brew livecheck\ command has been completely rewritten with a new internal structure. This change introduces a modular strategy system (defined in \Livecheck::Strategic\ and \Livecheck::Strategy\) that allows for extensible version-checking logic, including support for various HTTP strategies and custom blocks. It adds a new \Livecheck::Options\ class to manage request parameters like headers, cookies, and POST data, and implements \Livecheck::SkipConditions\ to handle logic for skipping deprecated, disabled, or unversioned formulae and casks. The core execution logic is now in \Livecheck\#run\_checks\, which orchestrates the checking process for formulae, casks, and resources.

Library/Homebrew/livecheck · high confidence

Introduce typed API modules and structs for formulae and casks

Homebrew now includes a new set of Sorbet-typed modules and classes in the API layer to handle formula and cask data from the JSON API. This adds \FormulaStruct\ and \CaskStruct\ to represent package metadata, along with dedicated modules (\Homebrew::API::Formula\, \Homebrew::API::Cask\, \Homebrew::API::Internal\, etc.) to fetch, cache, and parse this data. The changes also introduce \PackagesIndex\ for efficient byte-offset lookups into large JSON payloads, \SourceDownload\ and \JSONDownload\ strategies for retrieving source code and API files, and an \Analytics\ module for fetching unsigned analytics data. Additionally, a new \homebrew-1.pem\ public key is added to support signature verification for the API.

Library/Homebrew/api · high confidence

New Cask CI checks for system state and zap stanza coverage

Added new CI helper modules in Library/Homebrew/cask/ci to improve cask installation and cleanup validation. The new check.rb module captures and compares system state (installed apps, kernel extensions, packages, and launch jobs) before and after installation to detect leftover artifacts that should be handled by uninstall directives. The new zap\_check.rb module exercises cask applications and uses brew generate-zap to verify that the existing zap stanza covers all files created during installation, reporting any missing paths.

Library/Homebrew/cask/ci · high confidence

New Homebrew::Services::System::Systemctl module for service management

A new \Homebrew::Services::System::Systemctl\ module has been introduced to handle interactions with the \systemctl\ command. This module provides typed, strict methods for locating the \systemctl\ executable, determining the appropriate scope (system vs. user), and executing commands with various output modes (default, quiet, or read-only). It serves as the concrete implementation for managing systemd services within the Homebrew services system.

Library/Homebrew/services/system · high confidence

New Linux ELF, linker, and runtime library introspection modules

This change introduces a new set of modules under \Library/Homebrew/os/linux\ to provide detailed introspection of Linux binary formats and runtime environments. The new \ELFShim\ module parses ELF headers to identify architecture, file type, and runtime search paths (RPATH/RUNPATH), while \OS::Linux::Ld\ queries the system dynamic linker (\ld.so\) to determine library search directories and configuration. Additionally, \OS::Linux::Glibc\ and \OS::Linux::Kernel\ modules expose system version information, and \OS::Linux::Libstdcxx\ detects the system's libstdc++ version. These components replace ad-hoc checks with a structured, type-safe API for handling Linux-specific binary metadata.

Library/Homebrew/os/linux · high confidence

New RuboCop rules enforce cask style, ordering, and modernization

A comprehensive suite of new RuboCop cops has been added to the cask rubocops library to enforce stricter style and structural rules for Homebrew casks. These new checks include enforcing alphabetical ordering for \font\ stanzas and array elements in \conflicts\with\, \uninstall\, and \zap\ blocks; ensuring consistent ordering of architecture and OS keys in \sha256\ and conditional stanzas; and requiring the use of modern \on\{system}\ blocks instead of legacy \if\ conditionals or deprecated \preflight\/\postflight\ hooks. The linter also now flags redundant nested conditionals, disallows specific legacy patterns in uninstall commands, and enforces proper formatting for \deprecate!\ and \no\_autobump!\ reasons, providing automatic corrections for many of these style issues.

Library/Homebrew/rubocops/cask · high confidence

New Zsh completion system for Homebrew

Homebrew now includes a new Zsh completion script (\_brew) that provides tab-completion for commands, options, formulae, casks, and taps. The completion system is automatically generated from the manpages and includes caching to improve performance, as well as support for user-defined aliases.

completions/zsh · high confidence

New bash completion script for Homebrew

A new bash completion script has been added to automatically generate completions for Homebrew commands, flags, formulae, casks, and services. The script includes logic to handle POSIX mode detection, command caching, and alias resolution, providing a more robust and faster autocomplete experience for users.

completions/bash · high confidence

New cask appcast discovery module

A new \Cask::Appcast\ module has been added to automatically discover appcast URLs for casks by inspecting app bundles for Sparkle \SUFeedURL\ entries and Electron Builder update metadata, enabling more robust livecheck and update detection.

Library/Homebrew/cask · high confidence

New livecheck strategies for Apache, Bitbucket, CPAN, Crate, Electron Builder, GNOME, GNU, Hackage, Git, GitHub, and more

The livecheck system now includes a comprehensive set of new strategies to automatically detect software versions from a wider variety of sources. New strategies have been added for Apache directory listings, Bitbucket downloads/tags, CPAN, Rust crates (via the crates.io API), Electron Builder YAML appcasts, GNOME cache.json, GNU FTP mirrors, Hackage, Git repositories (via \git ls-remote\), GitHub (using both the API for latest releases and recent releases), and others. These strategies allow \brew livecheck\ to automatically identify new versions for formulas and casks hosted on these platforms without requiring manual regex configuration in most cases.

Library/Homebrew/livecheck/strategy · high confidence

New macOS FFI library wrappers for system frameworks

Added a new set of FFI (Foreign Function Interface) wrappers in Library/Homebrew/os/mac/ffi for interacting with macOS system frameworks, including AppKit, CoreFoundation, Foundation, LaunchServices, Security, libproc, dyld, and xattr. These modules provide Ruby bindings for native functions such as retrieving bundle identifiers, managing Core Foundation object lifecycles via release pools, handling file quarantine properties, verifying code signatures, and managing extended attributes. This infrastructure replaces previous shell-out mechanisms (like osascript) for process ancestry and other system calls, enabling more robust and deterministic interaction with macOS APIs.

Library/Homebrew/os/mac/ffi · high confidence

New macOS installer package for Apple Silicon and macOS 15+

Homebrew now provides a native macOS installer package (.pkg) that installs exclusively to /opt/homebrew on Apple Silicon Macs running macOS 15 (Sequoia) or later. The installer enforces a non-root installation user, configures system-wide PATH access via /etc/paths.d, and seeds the API cache for the installing user. It also hardens the installation by disabling Git hooks and cleaning up configuration files, while explicitly refusing to operate on symlinked directories to ensure a secure and stable setup.

package · high confidence

New native package manager extensions for Brew bundle

The bundle system now supports managing packages from several native package managers directly via new extension classes: Cargo (Rust), Go, npm (Node.js), uv (Python), Flatpak, Krew (kubectl plugins), VSCode extensions, and WinGet (Windows/WSL). These extensions allow users to declare and install tools from these ecosystems in their Brewfiles, with support for batch installation, cleanup, and dumping. The implementation introduces a unified \Extension\ base class to standardize how these package types are handled within the bundle framework.

Library/Homebrew/bundle/extensions · high confidence

New shared RuboCop helpers for formula and cask auditing

This change introduces a new \Library/Homebrew/rubocops/shared\ directory containing shared helper modules (\api\_annotation\_helper\, \desc\_helper\, \homepage\_helper\, \install\_steps\_helper\, \no\_autobump\_helper\, \on\_system\_conditionals\_helper\, and \url\_helper\) that standardize and enforce style checks across both formulae and casks. These helpers provide structured validation for public API annotations, description formatting, homepage URL hygiene, install step DSL usage, system conditionals, and URL patterns, ensuring consistent auditing logic and enabling automated corrections for common style violations.

Library/Homebrew/rubocops/shared · high confidence

Architecture

Homebrew Bundle logic migrated into core Homebrew

The \brew bundle\ functionality has been moved from the separate Homebrew/bundle repository into the core Homebrew/brew repository. This change consolidates the bundle implementation (including the DSL, installer, dumper, and package type handlers) directly within the main codebase, ensuring that bundle features are maintained alongside the core tool and eliminating the need for a separate extension repository.

Library/Homebrew/bundle · high confidence

Refactor macOS development tools and Mach-O handling into new modular files

The macOS-specific logic for handling Xcode, Command Line Tools, SDKs, and Mach-O binaries has been reorganized into dedicated files (\xcode.rb\, \sdk.rb\, \mach.rb\, \ffi.rb\). This change introduces a new \MachOShim\ module for inspecting and modifying Mach-O binaries (e.g., rpaths, dylib IDs) and a structured \SDK\ class with locators for both Xcode and CLT SDKs. It also establishes a base FFI module for system library calls. These changes improve code organization and type safety but do not alter the external behavior of Homebrew on macOS.

Library/Homebrew/os/mac · high confidence

Repository structure reorganized and development tooling standardized

The repository has been restructured to use a \Library/\ directory for core code, with a new \bin/brew\ entry point and generated completions/manpages at the root. This change introduces standardized development tooling, including an \.editorconfig\ for consistent formatting, a \.dockerignore\ to optimize Docker builds, and a \Dockerfile\ based on Ubuntu 24.04 for reproducible CI environments. Additionally, an \AGENTS.md\ file has been added to define strict coding, testing, and commit guidelines for contributors and AI assistants, while \.gitignore\ and \.gitattributes\ have been updated to manage vendored gems and generated Sorbet RBI files.

(repo-wide) · high confidence

Behavioural changes

Added Sorbet RBI stubs for FormulaAuditStrict RuboCop cops

Autogenerated Sorbet RBI files have been added for several RuboCop cops within the \FormulaAuditStrict\ namespace (including \GitUrls\, \MakeCheck\, \Requirements\, \RustCheck\, \TestPresent\, and \Text\). These stubs provide type signatures for dynamic methods, enabling Sorbet to type-check the formula audit logic used by Homebrew.

_Library/Homebrew/sorbet/rbi/dsl/rubo\_cop/cop/formula\_audit\strict · high confidence

Added Sorbet RBI type signatures for Cask DSL components

Autogenerated RBI files have been added for \Cask::Cask\, \Cask::Config\, \Cask::DSL\, and \Cask::URL\ to provide static type checking for the Cask DSL. This includes signatures for new or updated DSL methods such as \app\_image\, \deprecate\_args\, \disable\_args\, \no\_autobump!\, \pwsh\_completion\, and \homepage\_browsed\, as well as platform-specific conditional blocks like \on\_linux\ and \on\_system\. The \Cask::Config\ RBI also explicitly types configuration directory methods to return \Pathname\ instead of \String\.

Library/Homebrew/sorbet/rbi/dsl/cask · high confidence

Analytics and Developer commands now use subcommand dispatch

The \brew analytics\ and \brew developer\ commands have been refactored to use a subcommand-based structure. Users can now explicitly manage analytics with \brew analytics on\, \brew analytics off\, and \brew analytics state\, and manage developer mode with \brew developer on\, \brew developer off\, and \brew developer state\. This change introduces dedicated subcommand classes for each action, replacing the previous monolithic command implementations with a modular dispatch system that handles argument parsing and execution for each specific subcommand.

Library/Homebrew/analytics, Library/Homebrew/developer · high confidence

Autogenerated Sorbet RBI files for Cask DSL classes

The Cask DSL type signatures for \Base\, \Caveats\, \Postflight\, \Preflight\, \UninstallPostflight\, and \UninstallPreflight\ are now provided as autogenerated \.rbi\ files. This migration replaces the previous Parlour-based approach with Tapioca compilers, ensuring that dynamic methods (such as \depends\_on\_java\ and \appdir\) are automatically kept in sync with the runtime implementation.

Library/Homebrew/sorbet/rbi/dsl/cask/dsl · high confidence

Bootsnap integration and startup configuration refactoring

Homebrew now uses Bootsnap to cache Ruby compilation, significantly speeding up command execution by prewarming caches for common commands in the background and invalidating them when gems change. This change introduces new startup files (\config.rb\, \ruby\_path.rb\, \bootsnap.rb\) that centralize environment variable handling, define core paths, and manage the Bootsnap lifecycle, while also adding Sorbet type definitions for the new startup module.

Library/Homebrew/startup · high confidence

Bundled sorbet-runtime gem updated to version 0.6.13506

The vendored sorbet-runtime gem has been updated to version 0.6.13506. This update includes new compatibility patches for RSpec, specifically addressing issues with \expect\_any\_instance\_of\ and allowing \sig\ blocks on \let\-defined methods. It also introduces a \T::DefMods\ mixin for method-level DSL keywords (\abstract\, \override\, \final\, \overridable\) and adds a \T::Boolean\ type alias. Additionally, the runtime now provides configuration options to exclude values from type error messages and custom handlers for inline type errors and sig builder errors.

Library/Homebrew/vendor/bundle/ruby/4.0.0/gems/sorbet-runtime-0.6.13506 · high confidence

Cask DSL stanzas rewritten with Sorbet strict typing and expanded dependency support

The cask DSL files (base, caveats, conflicts\_with, container, depends\_on, postflight, preflight, rename, uninstall\_postflight, uninstall\_preflight, and version) have been refactored to use Sorbet \typed: strict\ signatures and modern Ruby patterns. For users, this brings stricter validation of cask definitions (e.g., version characters, container types) and expands the \depends\_on\ stanza to explicitly support Linux (\:linux\) and architecture (\:arch\) constraints alongside macOS requirements. The \conflicts\_with\ stanza now supports merging multiple stanzas, and the \caveats\ system includes new conditional messages for unsigned accessibility and Rosetta 2 requirements, while suppressing Rosetta warnings on Intel Macs.

Library/Homebrew/cask/dsl · high confidence

Cask artifacts restructured with strict typing and new artifact types

The cask artifact system has been refactored to use Sorbet strict typing across all artifact classes, introducing new artifact types such as AppImage, Manpage, and GeneratedCompletion while restructuring the hierarchy with new abstract base classes like AbstractArtifact and AbstractUninstall. This change adds support for Linux casks (AppImage, fonts, binaries), implements a new \command\_wrapper\ stanza for creating shell command wrappers, and introduces \generated\_script\ and \generated\_completions\_from\_executable\ stanzas for dynamic script and completion generation. The uninstall process now features a more robust directive ordering system with support for wildcards in launchctl identifiers and improved handling of privileged operations through a new install steps framework.

Library/Homebrew/cask/artifact · high confidence

Cask description cache store now handles untrusted taps gracefully

The new CaskDescriptionCacheStore for casks no longer aborts when encountering untrusted taps during cache population or updates. Instead, it catches Homebrew::UntrustedTapError (along with other expected exceptions) and simply removes the affected cask from the cache, ensuring that search and description commands remain functional even when some taps are not fully trusted.

_Library/Homebrew/description\_cache\store · high confidence

Configure Tapioca RBI generation and require handling

Tapioca is now configured to generate Ruby Interface (RBI) files with specific exclusions for standard library gems, development dependencies, and the \parser\ gem (to improve typecheck performance). A new \require.rb\ script ensures that gems like \rubocop-rspec\ and \ruby-macho\ are loaded with their correct dependencies before RBI generation, while \prerequire.rb\ sets up SimpleCov for coverage tracking without defaults.

Library/Homebrew/sorbet/tapioca · high confidence

Custom YARD documentation templates for internal and private API visibility

The Homebrew documentation generation now uses custom YARD templates to explicitly distinguish between internal and private APIs. When viewing generated docs, users will see specific warning notes indicating whether a method or class is part of an internal API (usable within Homebrew-owned repositories except in casks/formulae) or a private API (restricted to the Homebrew/brew repository). The templates also enhance the module item summary view to display visibility tags, inheritance status, and deprecation notices more clearly.

Library/Homebrew/yard/templates · high confidence

Default API visibility set to private with documentation warnings

The YARD documentation parser now marks all undocumented APIs as private by default, ensuring that only explicitly documented public interfaces are exposed in generated docs. It also warns users when non-private APIs lack documentation, helping maintain clear public contracts. Additionally, the parser handles \@deprecated\ and \@disabled\ tags to provide migration guidance in the documentation.

Library/Homebrew/yard · high confidence

Download strategies refactored into a strict, modular class hierarchy

The download strategy system has been restructured into a strict, modular class hierarchy with \AbstractDownloadStrategy\ and \AbstractFileDownloadStrategy\ as base classes, and specific strategies (Git, Curl, Subversion, etc.) inheriting from them. This change introduces Sorbet strict typing, standardizes caching and path resolution logic, and improves sandboxing and credential handling for VCS downloads. Users benefit from more reliable downloads, better cache management, and improved security through stricter sandboxing and credential isolation.

_Library/Homebrew/download\strategy · high confidence

Enforce standardized cask stanza ordering

The cask rubocop now enforces a strict, predefined order for DSL stanzas to ensure consistency across Homebrew casks. This change introduces a new constants file defining the canonical sequence, which groups related elements (such as architecture and OS conditionals, versioning, and metadata) and specifies the exact position for artifacts like completions, installers, and uninstall methods. Users writing or maintaining casks will see linting errors if stanzas appear out of this defined order, requiring adjustments to match the new structural requirements.

Library/Homebrew/rubocops/cask/constants · high confidence

Enhanced RuboCop AST node extensions for Cask stanzas

The Cask RuboCop linting tools now include extended AST node methods to better identify and handle specific Cask DSL structures. New matchers detect \on\_system\ blocks, architecture variables, and system variables, allowing the linter to correctly recognize these as valid stanzas. This improves the accuracy of style checks for Cask definitions that use conditional system or architecture blocks.

Library/Homebrew/rubocops/cask/extend · high confidence

Homebrew Bundle subcommands are restructured into a modular class hierarchy

The \brew bundle\ command-line interface has been refactored from a monolithic implementation into distinct, typed subcommand classes (Add, Check, Cleanup, Dump, Edit, Env, Exec, Install, List, Remove, and Sh) located in \Library/Homebrew/bundle/subcommand/\. This change introduces strict type annotations (\\# typed: strict\) and leverages the \AbstractSubcommand\ base class to standardize argument parsing, usage banners, and execution contexts across all bundle operations. For users, this ensures consistent behavior and help text across subcommands, while enabling more robust extension support and isolated execution environments (such as the sandboxed \exec\ and \sh\ commands) without altering the external command syntax.

Library/Homebrew/bundle/subcommand · high confidence

Implement Linux freedesktop trash for cask removal

Cask removal on Linux now moves files to the freedesktop Trash (XDG Trash) instead of permanently deleting them, aligning with standard Linux desktop behavior. This change introduces new utility scripts and modules (\trash.rb\, \rmdir.sh\, \copy\_xattrs.rb\) to handle trash operations, including creating \.trashinfo\ metadata files and managing file moves to the \\~/.local/share/Trash\ directory. On macOS, the existing FFI-based xattr copying and directory removal logic remains unchanged but is now gated behind platform-specific requirements.

Library/Homebrew/cask/utils · high confidence

Introduce OS::Mac and OS::Linux modules for platform-specific system information

Homebrew now provides dedicated \OS::Mac\ and \OS::Linux\ modules to query system information, replacing the previous generic \MacOS\ and \Linux\ implementations. The \OS::Mac\ module handles macOS-specific details such as version detection, SDK path resolution, Xcode/CLT location, and language settings, while the new \OS::Linux\ module provides equivalent functionality for Linux, including OS version parsing via \lsb\_release\, WSL detection, and language configuration. This change centralizes platform logic, improves type safety with Sorbet strict typing, and ensures consistent behavior across different operating systems.

Library/Homebrew/os · high confidence

Introduce macOS-specific dependency equality and installation logic

A new \UsesFromMacOSDependency\ class has been added to handle dependencies that are provided by macOS itself. This class implements specific equality checks (comparing name, tags, and bounds) and an \installed?\ method that determines if a dependency is satisfied by the current macOS version or a bottle's build version, ensuring correct dependency resolution for macOS-provided libraries.

Library/Homebrew/dependency · high confidence

Introduce new CLI argument parsing architecture

Homebrew replaces the legacy ARGV global with a structured, strictly typed CLI argument system. This change introduces new classes in the \Library/Homebrew/cli\ directory: \CLI::Args\ for managing processed options and flags, \CLI::NamedArgs\ for resolving formula and cask names, and \CLI::Parser\ for defining subcommand options and constraints. The new system enforces strict typing via Sorbet, improves error messages for invalid arguments, and provides a more robust foundation for command-line interactions.

Library/Homebrew/cli · high confidence

Introduce secure environment handling and unified build environment modules

This change introduces a new \EnvSensitive\ module that automatically detects and sanitizes sensitive environment variables (such as tokens and passwords) by either deleting them or replacing them with deferred placeholders that are only expanded at download time, significantly improving security for formula evaluation. It also refactors the build environment into a shared \SharedEnvExtension\ module containing common logic for compiler flags and path management, which is then included by both the \Stdenv\ and \Superenv\ modules to reduce code duplication and ensure consistent behavior across different build modes.

Library/Homebrew/extend/ENV · high confidence

Introduce superenv shims for compilers and build tools

Homebrew now provides a comprehensive set of wrapper shims in Library/Homebrew/shims/super to manage compiler and build tool invocations. The central cc shim (also exposed as c++, clang, gcc, g++, ld, and cpp) intercepts build commands to apply environment sanitization, flag refurbishment, and sysroot handling, ensuring consistent builds across different host configurations. Additional shims handle specific tooling: the ninja shim respects parallelism settings via MAKEFLAGS, the swift shim configures the environment to use Swift-bundled Clang, and symlinks are created for numerous GCC versions (4.2 through 16) and shared utilities like curl, git, and svn.

Library/Homebrew/shims/super · high confidence

Linux super shim environment for build tools

The Linux super shim directory now provides a comprehensive set of symlinks and a wrapper script for common build tools (including GCC, Clang, Make, Ninja, Git, and others). These shims ensure that CMake and other build systems locate the correct Homebrew-provided versions of these tools before system paths, resolving conflicts with host-installed compilers and utilities during formula builds.

Library/Homebrew/shims/linux · high confidence

Man page generation now uses ERB templates

The \brew.1\ man page is now generated from an ERB template (\brew.1.md.erb\) rather than static text or other formats. This change allows the documentation to dynamically include command lists, developer commands, global options, and environment variables directly from Homebrew's internal configuration and parser definitions, ensuring the man page stays in sync with the CLI without manual updates.

Library/Homebrew/manpages · high confidence

New Tapioca compilers for Sorbet RBI generation

The project introduces a suite of new Tapioca compilers in the \sorbet/tapioca/compilers\ directory to automatically generate Sorbet RBI type signatures for previously untyped or dynamically defined parts of the codebase. These new compilers cover \Args\ (generating CLI argument accessors for Homebrew commands), \EnvConfig\ (typing dynamic environment variable accessors), \Tty\ (typing dynamic color/style codes), \ApiStructs\ (typing \FormulaStruct\ and \CaskStruct\ predicates), \OnSystem\ (typing conditional execution methods on \Formula\, \Resource\, and \Cask::DSL\), \Forwardables\ (typing delegated methods), \RspecDynamicMatchers\ (typing dynamically defined RSpec matchers), and \RuboCop\/\Stanza\ (typing RuboCop DSL methods). This shift replaces manual or legacy RBI generation with a compiler-based approach, ensuring type signatures stay in sync with runtime behavior.

Library/Homebrew/sorbet/tapioca/compilers · high confidence

New Version Parser Architecture for Improved Performance

A new \Version::Parser\ class hierarchy has been introduced in \Library/Homebrew/version/parser.rb\ to handle version string extraction. This change includes a \RegexParser\ base class and specific implementations like \StemParser\ and \UrlParser\, which use regular expressions to parse version information from file paths. The \StemParser\ specifically optimizes handling of SourceForge download URLs and files without extensions, aiming to speed up version detection. This refactoring provides a more structured and extensible approach to version parsing within the Homebrew codebase.

Library/Homebrew/version · high confidence

New architecture, OS, and Xcode requirements with stricter type checking

This change introduces dedicated requirement classes for specifying software dependencies on specific architectures (via \ArchRequirement\, supporting \:x86\_64\, \:arm64\, etc.), operating systems (via \LinuxRequirement\ and \MacOSRequirement\), and Xcode versions (via \XcodeRequirement\). \MacOSRequirement\ now supports version comparators (e.g., \\>=\, \\<=\) and explicitly disables support for macOS versions older than Catalina, while \XcodeRequirement\ provides clearer error messages when the installed Xcode version is insufficient or incompatible with the current macOS. All new requirement files are implemented with Sorbet \typed: strict\ signatures to improve type safety and maintainability.

Library/Homebrew/requirements · high confidence

New bin/brew shell wrapper for environment initialization and configuration loading

Homebrew now uses a new \bin/brew\ shell script as the entry point to initialize the environment before invoking the Ruby core. This wrapper enforces that Bash is used, validates that the current working directory exists and is readable, and ensures the real and effective UIDs match to prevent unsupported privilege scenarios. It calculates \HOMEBREW\_PREFIX\ and \HOMEBREW\_REPOSITORY\ by resolving the script's location (handling symlinks) and defaults to \/usr/local\ if the binary is located there. The script loads configuration from system (\/etc/homebrew/brew.env\), prefix-specific, and user (\\~/.homebrew/brew.env\ or \$XDG\_CONFIG\HOME/homebrew/brew.env\) environment files, applying a strict allowlist for exported variables and preventing users from overriding critical internal paths. It also records which \HOMEBREW\\*\ variables were set by the user to support analytics sampling.

bin · high confidence

New formula post-install actions for GCC, glibc, Clang, PHP, and gzipped executables

The Homebrew installation process now includes dedicated post-install steps for several core components. For GCC on Linux, a specs file is generated to configure runtime paths and header directories, optionally integrating with glibc. The glibc formula now installs locale data and symlinks system timezone information. On macOS, Clang receives system configuration files tailored to the specific kernel and architecture. PHP installations are configured with proper PEAR/PECL directory structures and opcache settings. Additionally, a new action supports the installation of gzipped executables, automatically decompressing them during the formula installation phase.

_Library/Homebrew/install\steps · high confidence

New macOS 'super' shim wrappers for build tools

The \Library/Homebrew/shims/mac/super/bin\ directory now contains a comprehensive set of wrapper scripts and symlinks for common build tools (including \cc\, \clang\, \gcc\, \make\, \ruby\, \swift\, \xcrun\, and others). These shims intercept calls to system utilities to enforce Homebrew's environment settings—such as \SDKROOT\, \DEVELOPER\_DIR\, and \HOMEBREW\_CCCFG\—ensuring that builds use Homebrew's preferred SDKs and compiler flags rather than the system defaults. This change standardizes how Homebrew manages the build environment on macOS, particularly for tools that rely on Xcode Command Line Tools.

Library/Homebrew/shims/mac · high confidence

New shim utilities and SCM compatibility alias

The shims directory now includes a new \Library/Homebrew/shims/scm\ symlink pointing to \shared\ to maintain compatibility with older update-reset scripts. Additionally, \Library/Homebrew/shims/utils.sh\ has been added, providing core utility functions such as \quiet\_safe\_cd\, \absdir\, \dirbasepath\, \realpath\, \executable\, \lowercase\, and \safe\_exec\. The \safe\_exec\ function specifically prevents fork-bombs and exec loops by detecting when a shim attempts to execute itself or a shared shim from another Homebrew checkout, ensuring stable command execution.

Library/Homebrew/shims · high confidence

New update report system with quiet mode and trust requirements

Homebrew introduces a new \update\_report\ system that consolidates update reporting logic into dedicated \Reporter\ and \ReporterHub\ classes. This change adds a quiet mode for automatic updates, allowing users to suppress update reports during background operations via the \auto\_update\_quiet\ environment configuration. It also enforces trust requirements for automatic tap migration installs, ensuring that only trusted taps are automatically tapped during updates. The new system handles formula and cask updates, deletions, renames, and migrations, providing a more structured and secure update experience.

_Library/Homebrew/cmd/update\report · high confidence

Refactor Cask RuboCop AST into typed Stanza, CaskBlock, and CaskHeader classes

The internal structure of the Cask RuboCop cops has been refactored to use dedicated, Sorbet-typed AST wrapper classes (\Stanza\, \CaskBlock\, \CaskHeader\) instead of raw \RuboCop::AST::Node\ objects. This change improves type safety and code organization for the cask style checking logic, ensuring that stanza analysis, comment association, and header parsing are handled through explicit interfaces rather than implicit node structures.

Library/Homebrew/rubocops/cask/ast · high confidence

Refactor duplicable checks and add IRB helpers

The duplicable? checks for Method, UnboundMethod, and Singleton objects have been moved into their own dedicated files (method.rb, unbound\_method.rb, singleton.rb) to improve code organization. Additionally, new IRB helper methods f() and c() have been added to the Symbol class for convenient Formula and Cask lookups, and a new Requirements class has been introduced to manage dependency requirements with type safety.

_Library/Homebrew/brew\_irb\helpers, Library/Homebrew/dependencies, Library/Homebrew/extend/object/duplicable · high confidence

Refactored Pathname extensions with strict typing and eager initialization

The \Library/Homebrew/extend/pathname\ directory has been restructured into distinct, strictly typed modules (\DiskUsageExtension\, \EagerInitializeExtension\, \ObserverPathnameExtension\, and \WriteMkpathExtension\). This change introduces eager initialization of lazy instance variables (\@disk\_usage\, \@file\_count\) to stabilize Ruby object shapes and eliminate shape-variation warnings. It also adds strict Sorbet type annotations across all extensions, refactors disk usage computation to use \lstat\ for single-stat accuracy, and enforces a safety check in \write\ to prevent accidental overwrites of existing files.

Library/Homebrew/extend/pathname · high confidence

Refactored archive extraction into a modular strategy architecture

The monolithic archive handling logic has been split into individual, type-safe strategy classes (e.g., \UnpackStrategy::Zip\, \UnpackStrategy::Dmg\, \UnpackStrategy::Tar\) located in the \Library/Homebrew/unpack\strategy\ directory. This change introduces dedicated support for new formats like \.zst\ (zstd) and \.crate\, while fixing extraction behaviors for \.dmg\ images (using \ditto\ and fixing UID handling), \.zip\ files (removing \\\_MACOSX\ metadata), and \.tar\ archives (fixing sub-extraction for bzip2/xz/zstd). Users benefit from more reliable unpacking of diverse archive types and improved handling of macOS disk images and Adobe Air installers.

_Library/Homebrew/unpack\strategy · high confidence

Refactored cask RuboCop mixins with Sorbet type annotations

The cask RuboCop mixin files in \Library/Homebrew/rubocops/cask/mixin\ have been updated to include Sorbet type annotations (\\# typed: strict\) and corresponding \.rbi\ interface files. This change introduces or updates mixins such as \CaskHelp\, \OnDescStanza\, \OnHomepageStanza\, and \OnUrlStanza\ to enforce stricter type checking, ensuring that the common functionality for checking cask stanzas (like \desc\, \homepage\, and \url\) is more robust and less prone to runtime errors. This is a structural improvement to the internal tooling used for validating cask definitions.

Library/Homebrew/rubocops/cask/mixin · high confidence

Refactored reinstall logic into a dedicated module with improved keg backup handling

The \reinstall\ command logic has been extracted into a new \Homebrew::Reinstall\ module (\Library/Homebrew/reinstall/reinstall.rb\). This change introduces an \InstallationContext\ struct to manage installation state and refactors the core \reinstall\_formula\ method to explicitly handle keg backup and restoration. Specifically, the module now unlinks and renames the current keg to a \.reinstall\ backup path before installation, and restores this backup if the installation fails, providing better resilience against broken states during reinstallation.

Library/Homebrew/reinstall · high confidence

Refactored standalone initialization and Sorbet runtime optimization

The standalone initialization logic has been consolidated into a new \init.rb\ file, which now handles Ruby version validation, portable Ruby detection, and gem environment setup earlier in the boot process. Sorbet runtime checks are now conditionally disabled by default to improve performance, with a no-op implementation provided when the runtime is not enabled, while still supporting recursive type checking and strict final checks when explicitly enabled via environment variables.

Library/Homebrew/standalone · high confidence

Replace Ronn with Kramdown for manpage parsing

The manpage parser has switched from the Ronn tool to a custom Kramdown-based parser. This new parser mimics Ronn's variable syntax (e.g., \\<var\>\) by treating HTML-like tags as variables, while disabling native HTML, table, and typographic symbol parsing to prevent misinterpretation of command descriptions. This change ensures compatibility with existing manpage content while leveraging Kramdown's underlying engine.

Library/Homebrew/manpages/parser · high confidence

Services module restructured into Homebrew namespace with strict typing

The \brew services\ functionality has been refactored from the legacy \Homebrew::Services\ module into a new \Homebrew::Services\ namespace, introducing a modular architecture with dedicated files for CLI handling (\cli.rb\), formula wrapping (\formula\_wrapper.rb\), service enumeration (\formulae.rb\), and system abstraction (\system.rb\). This change enforces strict type checking (\\# typed: strict\) across the services codebase and integrates the \Utils::Output\ mixin for consistent messaging. The refactoring also updates the service detection logic to prioritize \launchctl print\ over \list\ on macOS and improves systemd integration by normalizing labels and supporting timer-based services.

Library/Homebrew/services · high confidence

Services subcommands are refactored into dedicated classes

The \brew services\ CLI subcommands (start, stop, restart, run, kill, list, info, cleanup) have been restructured from a monolithic implementation into individual, dedicated subcommand classes (e.g., \StartSubcommand\, \StopSubcommand\). This change improves code organization and maintainability by isolating the logic for each subcommand, while preserving the existing user-facing behavior and command-line arguments for all services operations.

Library/Homebrew/services/subcommand · high confidence

Sorbet RBI definitions added for API-loaded Formula and Cask structs

Autogenerated Sorbet RBI files have been added for \Homebrew::API::FormulaStruct\ and \Homebrew::API::CaskStruct\, defining boolean query methods (such as \deprecate?\, \disable?\, \bottle?\, and \auto\_updates?\) that correspond to attributes loaded from the Homebrew API. These type signatures enable static type checking for the new struct-based loading of formulae and casks, ensuring that code accessing these API-derived objects is correctly typed.

Library/Homebrew/sorbet/rbi/dsl/homebrew/api · high confidence

Standardize Bundler configuration for Homebrew development

The Homebrew development environment now uses a unified Bundler configuration file that disables shared gems, sets the installation path to vendor/bundle, enables automatic cleanup, and explicitly disables forcing the Ruby platform. This change ensures consistent dependency isolation and prevents platform-specific binary issues during local development.

Library/Homebrew/.bundle · high confidence

Standardized core Ruby extensions with Sorbet type signatures

The \extend/\ directory has been restructured to provide a unified, type-safe foundation for Ruby core class extensions. New files introduce strict Sorbet type signatures for \ENV\ (including \EnvActivation\ and \Superenv\/\Stdenv\ integration), \Pathname\ (with methods like \install\, \atomic\_write\, and \version\), \Kernel\ (wrapping \which\ and \with\_env\), \Array\ (adding \second\ through \fifth\), \String\ (adding \exclude?\), \Enumerable\ (adding \compact\_blank\), \Object\ (backporting \blank?\, \present?\, and \presence\), \Module\ (adding \exclude?\), and \OptionParser\ (accepting \Pathname\). This change ensures consistent typing and behavior across Homebrew's internal Ruby codebase.

Library/Homebrew/extend · high confidence

Stop hook blocks session exit if brew lgtm check fails

A new stop hook has been added to the .codex configuration that runs the local \./bin/brew lgtm\ command when a session ends. If this command fails, the session is blocked from stopping, requiring the user to review and fix the output before proceeding; if it succeeds, the session continues normally.

.codex · high confidence

Test-bot now runs formulae and dependent tests in parallel shards

The test-bot infrastructure has been refactored to support parallel execution of formulae and dependent tests. New classes like \FormulaeDependents\ and \BottlesFetch\ handle fetching bottles and testing dependents in parallel, while \FormulaeDetect\ and \Formulae\ manage the detection and testing of formulae. The \TestRunner\ orchestrates these steps, and \CleanupBefore\ and \CleanupAfter\ handle environment setup and teardown. This change aims to speed up the testing process by running independent tasks concurrently.

_Library/Homebrew/test\bot · high confidence

Unified command shims for curl, git, rustc, and svn

Homebrew now uses a shared set of wrapper scripts in Library/Homebrew/shims/shared to manage external tool execution. The new curl shim ensures that SSL certificate settings (SSL\_CERT\_FILE) are correctly passed to the underlying curl binary via both --cacert and --capath, preventing issues where CA path defaults are not cleared. The git shim provides a robust fallback chain for locating the git executable, specifically handling cases where Xcode Command Line Tools are missing or where /usr/bin/git is a stub, ensuring Homebrew can always find a working git binary. Additionally, a rustc\_wrapper shim allows Homebrew to inject custom optimization flags (HOMEBREW\_RUSTFLAGS) into Rust compilation processes while respecting user-defined .cargo/config.toml settings, and svn is aliased to git to handle legacy references.

Library/Homebrew/shims/shared · high confidence

Updated Sorbet RBI definitions for RSpec matchers

The Sorbet RBI file for RSpec matchers has been regenerated to include type signatures for a comprehensive set of custom matchers used in Homebrew's test suite, such as \be\_a\_build\, \be\_bottled\, \be\_linked\, and \be\_official\. This update ensures that static type checking correctly recognizes these dynamic matcher methods, improving type safety and developer experience when writing or maintaining tests.

_Library/Homebrew/sorbet/rbi/dsl/r\spec · high confidence

Updated Sorbet RBI files for Cask RuboCop AST classes

The Sorbet RBI type definitions for the Cask RuboCop AST classes have been regenerated to reflect current dynamic methods. Specifically, \RuboCop::Cask::AST::CaskBlock\ now includes a signature for \cask\_body\, and \RuboCop::Cask::AST::Stanza\ has been expanded with boolean checkers for various cask stanzas (such as \app\, \artifact\, \depends\_on\) and new conditional helpers for macOS versions (including \on\_big\_sur\, \on\_sequoia\, \on\_sonoma\, \on\_ventura\) and architectures (\on\_arm\, \on\_intel\). This ensures static type checking aligns with the actual DSL methods available in cask recipes.

_Library/Homebrew/sorbet/rbi/dsl/rubo\cop/cask · high confidence

Updated Sorbet RBI files for Homebrew RuboCop cops

The Sorbet RBI type definitions for the Homebrew RuboCop cop library have been regenerated to reflect the current dynamic methods. This update adds type signatures for the new \UnreferencedLet\ cop and ensures accurate type information for existing cops such as \ApiNameMembership\, \Blank\, \CompactBlank\, \FormulaPathMethods\, \MoveToExtendOS\, \NegateInclude\, \NoFileutilsRmrf\, \Presence\, \Present\, and \SafeNavigationWithBlank\, improving static type checking accuracy for developers working on these linting rules.

_Library/Homebrew/sorbet/rbi/dsl/rubo\cop/cop/homebrew · high confidence

Updated Sorbet RBI shims for stricter type checking

The Sorbet type-checking configuration in the shims directory has been updated to 'strict' mode, requiring precise type definitions for internal and external dependencies. New shim files define signatures for the Fiber class (specifically its initialize method), ParallelTests runner, and a PortableFormula class to support external taps. The RSpec shim now includes necessary helper modules and corrects the ExpectHost signature to support block-based matchers. Additionally, the Sorbet-runtime shim explicitly defines the build\_type method for various type classes to ensure compatibility with the runtime's type system.

Library/Homebrew/sorbet/rbi/shims · high confidence

Updated Sorbet RBI stubs for FormulaAudit RuboCop cops

The Sorbet RBI stubs in Library/Homebrew/sorbet/rbi/dsl/rubo\_cop/cop/formula\_audit have been regenerated to reflect the current dynamic methods of the FormulaAudit RuboCop cops. This update adds type signatures for specific helper methods in the ComponentsOrder, DependencyOrder, DeprecateDisableDate, DeprecateDisableReason, GenerateCompletionsDSL, GitUrls, JavaVersions, Licenses, Miscellaneous, NoAutobump, OptionDeclarations, Patches, PythonVersions, and Test cops, while keeping other cops as empty class stubs where no dynamic methods were detected.

_Library/Homebrew/sorbet/rbi/dsl/rubo\_cop/cop/formula\audit · high confidence

Updated Sorbet RBI stubs for Livecheck and AST classes

Autogenerated Sorbet RBI stubs have been updated for \Homebrew::Livecheck::Strategy::ExtractPlist::Item\, \Homebrew::Livecheck::Strategy::Sparkle::Item\, and \Utils::AST::FormulaAST\. These changes reflect the migration of DSL type definitions to Tapioca compilers, ensuring that dynamic methods like \short\_version\, \version\, \nice\_version\, and \process\ are correctly typed for static analysis.

Library/Homebrew/sorbet/rbi/dsl/homebrew/livecheck, Library/Homebrew/sorbet/rbi/dsl/utils · high confidence

Updated Sorbet RBI stubs for RuboCop Cask and Formula cops

The Sorbet RBI stubs in \Library/Homebrew/sorbet/rbi/dsl/rubo\_cop/cop/\ have been regenerated using Tapioca, replacing the previous Parlour-based extensions. This update adds or refreshes type signatures for RuboCop cops such as \NoAutobump\, \OnDescStanza\, \OnHomepageStanza\, \OnSystemConditionals\, \OnUrlStanza\, \StanzaGrouping\, \Variables\, \FormulaCop\, and \OnSystemConditionalsHelper\, ensuring static type checking aligns with the current dynamic method definitions in the cask and formula linting logic.

_Library/Homebrew/sorbet/rbi/dsl/rubo\cop/cop/cask · high confidence

Updated Sorbet RBI type definitions for EnvConfig and Service DSLs

The Sorbet RBI files for the \Homebrew::EnvConfig\ and \Homebrew::Service\ DSLs have been regenerated to reflect current runtime methods. For \EnvConfig\, the type signatures now include numerous new environment variables related to bundle management (e.g., \bundle\_cleanup\no\\*\, \bundle\_dump\no\\*\, \bundle\secrets?\), cask options, and API settings, ensuring type-checking accuracy for these configuration options. For \Service\, the RBI file defines the standard path helper methods (\bin\, \etc\, \libexec\, \opt\\*\, \var\) with their expected argument and return types, improving static analysis for service formulae.

Library/Homebrew/sorbet/rbi/dsl/homebrew · high confidence

Updated Sorbet RBI type definitions for Homebrew CLI commands

The Sorbet RBI files in \Library/Homebrew/sorbet/rbi/dsl/homebrew/cmd\ have been regenerated to reflect the current state of the Homebrew command-line interface. This update adds type signatures for the argument parsers of numerous commands, including \alias\, \analytics\, \as\_brew\_user\, \autoremove\, \bundle\ (and its subcommands like \add\, \check\, \cleanup\, \dump\, \edit\, \env\, \exec\, \install\, \list\, \remove\, \sh\), \cache\, \cleanup\, \command\, \command\_not\_found\_init\, \commands\, \completions\, \config\, \deps\, \desc\, \developer\, \docs\, \doctor\, \env\, \exec\, \fetch\, \formulae\, \gist\_logs\, \help\, \home\, \info\, \install\, \leaves\, \link\, \list\, \log\, and \mcp\_server\. For users and developers relying on static type checking, this ensures that the type definitions for command-line arguments and subcommands are accurate and up to date.

Library/Homebrew/sorbet/rbi/dsl/homebrew/cmd · high confidence

Updated Sorbet RBI type definitions for vendored gems

The Sorbet RBI files in Library/Homebrew/sorbet/rbi/gems have been regenerated to reflect the current state of vendored gems, including ast, bindata, concurrent-ruby, csv, drb, elftools, erubi, json\_schemer, kramdown, lint\_roller, and minitest. This update ensures that static type checking for these dependencies remains accurate and consistent with their actual implementations.

Library/Homebrew/sorbet/rbi/gems · high confidence

Updated Sorbet RBI type signatures for Homebrew dev commands

The Sorbet RBI files in \Library/Homebrew/sorbet/rbi/dsl/homebrew/dev\_cmd\ have been regenerated to reflect the current argument structures of the Homebrew developer commands. This update ensures that static type checking accurately recognizes the flags and options available for commands such as \advisory-match\, \audit\, \benchmark\, \bump\, \contributions\, \create\, \debugger\, \lgtm\, \prof\, \release\, \style\, \tests\, and \typecheck\, among others.

_Library/Homebrew/sorbet/rbi/dsl/homebrew/dev\cmd · high confidence

Updated command-not-found handlers for Bash, Zsh, and Fish

The command-not-found integration has been migrated to new handler scripts for Bash, Zsh, and Fish shells. These updated handlers now invoke \brew which-formula --explain\ to provide users with specific installation instructions when a command is not found, rather than just displaying a generic error. The change also includes the addition of a LICENSE file and updated license headers across the handler scripts.

Library/Homebrew/command-not-found · high confidence

Updated vendored elftools gem to version 2.2.0

The vendored elftools Ruby gem has been updated to version 2.2.0. This update refreshes the internal ELF parsing constants, including machine architectures, dynamic table types, and relocation types, by regenerating them from the binutils-gdb source. Users benefit from improved accuracy and broader architecture support when Homebrew analyzes ELF binaries.

Library/Homebrew/vendor/bundle/ruby/4.0.0/gems/elftools-2.2.0 · high confidence

Test coverage

3 commits adding/updating tests in Library/Homebrew/test/support/fixtures/tarballs; Add test fixture for structured install steps; Added Cask test helper stubs for installation and system commands; Added Linux-specific test coverage; Added aged Caskroom fixture data for cask update-report tests; Added cask test fixtures for API and installation scenarios; Added comprehensive test coverage for Cask artifact installation and uninstallation; Added comprehensive test coverage for all unpack strategies; Added comprehensive test coverage for cask components; Added invalid cask fixtures for style and validation testing; Added livecheck test fixtures for cask skip, throttle, and deprecated states; Added shared test coverage for cask uninstall and zap phases; Added shared test helper for verifying formula existence; Added test coverage for CLI argument parsing and named argument resolution; Added test coverage for Cask DSL and Staged components; Added test coverage for Cask DSL components; Added test coverage for CaskLoader loaders; Added test coverage for GitHub utility classes; Added test coverage for Homebrew TestBot components; Added test coverage for Homebrew bundle extensions and service management; Added test coverage for Homebrew shims; Added test coverage for Language::Java, Language::Node, and Language::Python; Added test coverage for OS detection and SDK path resolution; Added test coverage for architecture, Linux, and macOS requirement specs; Added test coverage for argument parsing, user switching, and pkgconf reinstallation; Added test coverage for bundle subcommands; Added test coverage for core Ruby extensions; Added test coverage for macOS FFI modules; Added test coverage for macOS-specific Homebrew components; Added test coverage for text-based RuboCop formula audit cops; Added test coverage for the Homebrew Services CLI and backend components; Added test coverage for the Homebrew vulnerability scanner components; Added test fixtures for cask outdated scenarios; Added test fixtures for patch application scenarios; Added test fixtures for receipt validation, formula installation, and update logic; Added test fixtures for third-party casks; Added test helper to verify undefined constants at startup; Added test suite for Homebrew Livecheck; Added tests for Bootsnap cache stability, sudo detection, and startup umask; Added tests for CPU type and family detection; Added tests for Cask CI check and zap validation logic; Added tests for Cask trash utilities; Added tests for CaskStructGenerator API serialization; Added tests for FormulaStructGenerator dependency and requirement processing; Added tests for Homebrew AST utility helpers; Added tests for Homebrew diagnostic checks and findings; Added tests for Node shebang detection and rewriting; Added tests for Python shebang detection and virtualenv resource installation; Added tests for RuboCop formula audit cops; Added tests for Tapioca Cask config compiler; Added tests for URL audit RuboCop cops; Added tests for WriteMkpathExtension; Added tests for livecheck RuboCop cops; Added unit tests for bottle tag parsing, collector logic, and tab loading; Added unit tests for keg relocation logic; Added unit tests for version parser components; Expanded RuboCop test coverage for Cask style enforcement; Expanded RuboCop test coverage for formula and cask audits; Expanded cask test fixtures for comprehensive validation; Expanded test coverage across Homebrew core components; Expanded test coverage for Homebrew command-line interface; Expanded test coverage for Homebrew dev commands; Expanded test coverage for Homebrew utility modules; Expanded test coverage for livecheck strategies; New test helper modules for fixtures, coverage, and subcommand mocking; New test helper shared contexts for Cask, integration, and trust store isolation; New test support infrastructure for Homebrew.

Dependencies

Routine dependency updates across Homebrew and documentation builds

This change updates Ruby dependencies in the main Homebrew codebase (/Library/Homebrew) and the documentation site (/docs). The updates include patch and minor version bumps for development tools such as Sorbet, RuboCop, RSpec, and Tapioca, as well as runtime dependencies like Nokogiri, Faraday, and Activesupport. These changes keep the build environment and static site generator current with upstream releases.

(dependencies) · high confidence

Updated vendored Ruby gems and bundler setup

The vendored gem set in Library/Homebrew/vendor/bundle/bundler has been updated, including upgrades to rubocop (1.91.0), sorbet (0.6.13506), and ruby-macho (7.0.0). The bundler setup script now explicitly configures the Ruby load path for these dependencies and disables automatic gem discovery to ensure consistent, isolated execution of Homebrew's internal tooling.

Library/Homebrew/vendor/bundle/bundler · high confidence

Upgrade vendored Ruby to 3.4.7

The vendored Ruby interpreter has been upgraded to version 3.4.7. This update brings the latest performance improvements, bug fixes, and language features from the Ruby 3.4 series to the Homebrew core, ensuring that Homebrew's internal tooling and formula build environments run on a modern, supported Ruby version.

Library/Homebrew/cmd · high confidence

Vendor BinData 3.0.0 gem for binary data parsing

Brew now includes the BinData 3.0.0 gem, providing a declarative DSL for reading and writing structured binary data. This update adds support for complex binary formats through features like bit-aligned primitives, delayed I/O for multi-pass processing, and flexible array and choice types, enabling more robust handling of binary protocols and file formats within Homebrew's internal tools.

Library/Homebrew/vendor/bundle/ruby/4.0.0/gems/bindata-3.0.0 · high confidence

Vendor Mechanize gem version 2.14.1

The mechanize gem (version 2.14.1) is now vendored within the Homebrew codebase, including its source files and license. This ensures a consistent, isolated dependency for HTTP and web page manipulation tasks, independent of the system Ruby environment.

Library/Homebrew/vendor/gems · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 49 → 70 (+21.3)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 81 (-18.6)
  • Architecture 98 (new)
  • Maturity 61 → 75 (+13.2)
  • Readiness 34 → 69 (+34.4)
  • Security 52 → 76 (+23.6)
  • Accessibility 66 (new)

Resolved (34)

  • Coverage not measured — test suite did not build
  • Decision (electing STV PLC and Schulze project leader) is explicit but the body is a minute listing motions, reports, and presentations with no context/problem or consequences/trade-offs (docs/governance/2021-agm-minutes.md)
  • Dimension evaluation failed
  • Empty ADR with only a title and a list of contributors (no context, decision, or consequences) (docs/governance/2019-membership.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low IaC: DS-0026 (Dockerfile)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No artifact signing
  • No context/problem and no consequences; this is a pure minute-taking record with no real decision or trade-off discussion (docs/governance/2019-plc-minutes.md)
  • No context/problem and no explicit decision (TSC member appointments are administrative rather than an architecture decision) (docs/governance/2021-plc-minutes.md)
  • No context/problem and no explicit decision are stated (only procedural items such as voting passed, member presentations) (docs/governance/2022-agm-minutes.md)
  • No context/problem statement and no explicit decision; this is a full meeting minutes record rather than an ADR (docs/governance/2023-agm-minutes.md)
  • No exposed public API
  • …and 14 more

New (846)

  • A real membership/decision document must state the problem and its consequences; this is a bare contributor list with no content (docs/governance/2020-membership.md)
  • API.fetch_json_api_file (cognitive 48) (Library/Homebrew/api.rb)
  • API.fetch_json_api_file (cyclomatic 34) (Library/Homebrew/api.rb)
  • API.open_rest (cognitive 20) (Library/Homebrew/utils/github/api.rb)
  • API.open_rest (cyclomatic 17) (Library/Homebrew/utils/github/api.rb)
  • API.raise_error (cyclomatic 16) (Library/Homebrew/utils/github/api.rb)
  • AbstractFileDownloadStrategy.parse_basename (cognitive 19) (Library/Homebrew/download_strategy/abstract_file_download_strategy.rb)
  • AdvisoryMatch.reconcile_formula (cognitive 28) (Library/Homebrew/dev-cmd/advisory-match.rb)
  • AdvisoryMatch.reconcile_formula (cyclomatic 21) (Library/Homebrew/dev-cmd/advisory-match.rb)
  • AdvisoryMatch.run (cognitive 64) (Library/Homebrew/dev-cmd/advisory-match.rb)
  • AdvisoryMatch.run (cyclomatic 69) (Library/Homebrew/dev-cmd/advisory-match.rb)
  • AdvisoryOverrides.initialize (cognitive 25) (Library/Homebrew/vulns/advisory_overrides.rb)
  • AdvisoryOverrides.initialize (cyclomatic 22) (Library/Homebrew/vulns/advisory_overrides.rb)
  • Annotation.to_s (cognitive 17) (Library/Homebrew/utils/github/actions.rb)
  • AssertStatements.audit_formula (cyclomatic 16) (Library/Homebrew/rubocops/lines.rb)
  • Attestation.check_attestation (cognitive 17) (Library/Homebrew/attestation.rb)
  • Attestation.check_attestation (cognitive 19) (Library/Homebrew/utils/attestation.rb)
  • Attestation.check_core_attestation (cognitive 16) (Library/Homebrew/attestation.rb)
  • Audit.audit_min_os (cognitive 28) (Library/Homebrew/cask/audit.rb)
  • Audit.audit_min_os (cyclomatic 29) (Library/Homebrew/cask/audit.rb)
  • …and 826 more

Changes since last survey

  • 300 commits — 274 feature/other, 26 fixes

By area

  • Library/Homebrew — 144 commits
  • (repo) — 135 commits
  • .github/workflows — 8 commits
  • (root) — 4 commits
  • .github/scripts — 2 commits
  • .github/ISSUE_TEMPLATE — 1 commit
  • docs/Formula-Cookbook.md — 1 commit
  • docs/Gemfile.lock — 1 commit
  • docs/How-To-Open-a-Homebrew-Pull-Request.md — 1 commit
  • docs/Support-Tiers.md — 1 commit
  • docs/Tips-and-Tricks.md — 1 commit
  • docs/_layouts — 1 commit

Notable commits

  • fix: Fix CLT version check on Intel Tahoe
  • fix: Fix Sorbet LSP crash from two config dirs
  • fix: Fix cask_sparkle_min_os audit options handling
  • fix: Fix historical loading and CPANSA fallback
  • fix: Fix ownership check to use local variable for recursive option
  • fix: Fix pkgconf infinite reinstall after macOS upgrade
  • fix: Fix pkgconf reinstall test doubles and add test - Stub formula.full_name in reinstall_spec and shared example to prevent unexpected-message errors from build_install_context args - Add same-major version mismatch regression test to diagnostic_spec
  • fix: Fix shorter-prefix Perl bottle relocation
  • fix: Fix test
  • fix: Merge branch 'main' into fix/pwsh-export-value
  • fix: Merge pull request #23961 from aguashui/typos-and-grammar-fixes
  • fix: Merge pull request #23971 from Homebrew/ww/fix-buildpath
  • fix: Merge pull request #23975 from rawsun007/fix/cleanup-stale-formula-receiver
  • fix: Merge pull request #23996 from rawsun007/fix/pwsh-profile-lines
  • fix: Merge pull request #24010 from rawsun007/fix/pwsh-export-value
  • fix: Merge pull request #24035 from rawsun007/fix/shell-export-double-quotes
  • fix: Merge pull request #24039 from Homebrew/fix-cask_sparkle_min_os-options-handling
  • fix: Merge pull request #24042 from rawsun007/fix/shell-profile-single-quote
  • fix: Merge pull request #24053 from rawsun007/fix/curl-duplicate-singleton-headers
  • fix: Merge pull request #24056 from Homebrew/revert-23620-SMillerDev-patch-1
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Homebrew/brew was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ce46735f348df8af3258e854c8a008d272f683b8 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d0929f7ac71f.