pkgxdev/pkgx
61.6
Adequate · 29 September 2026
2.7k
lines of production code
Rust
primary language
2
measurements over time
What this system is
pkgx is a package management system that installs and manages software dependencies across multiple operating systems and container environments. It supports parallel installation of multi-version dependencies to resolve conflicts and provides a CLI for querying package availability and executing commands with structured output. The system is designed to work with custom distribution endpoints and includes tooling for maintaining Docker images and automating releases.
Features
Initial repository structure and documentation for pkgx
This change introduces the foundational files for the pkgx project, including the Apache 2.0 license, a comprehensive README detailing installation and usage across macOS, Linux, Windows, Docker, and CI/CD environments, and a tea.yaml file for repository ownership validation. It also adds configuration files such as .envrc for Cargo environment sourcing, .gitignore for build artifacts, .gitbook.yaml for documentation redirects, and AGENTS.md for contributor guidelines.
(repo-wide) · high confidence
New Docker images for Arch Linux, BusyBox, Ubuntu, and Debian variants
Users can now run pkgx in a wider variety of container environments with the addition of new Dockerfiles for Arch Linux, BusyBox, Ubuntu, and Debian. The Debian builds are split into two distinct profiles: a default "fat" image that includes development libraries (libc6-dev, g++, etc.) for compiling code, and a "slim" image containing only the runtime binaries for a smaller footprint. Additionally, a BusyBox variant is provided for minimal environments, and Ubuntu/Arch images are available for those specific base systems.
docker · high confidence
New scripts for Docker Hub image maintenance and release publishing
Added two new scripts to the repository: \find-orphaned-docker-hub-images.py\ identifies Docker Hub image tags that have unique digests (orphaned tags) for the \pkgxdev/pkgx\ image, aiding in cleanup; and \publish-release.sh\ automates the creation of draft GitHub releases, triggers the continuous deployment workflow, and finalizes the release after verifying the build status.
scripts · high confidence
Support parallel installation of multi-version dependencies
The library now allows packages with non-intersecting version constraints to coexist in the same environment. Specifically, \unicode.org\, \openssl.org\, and \abseil.io\ are recognized as multi-version projects; if their dependency requirements cannot be satisfied by a single version, the system installs separate instances for each distinct ABI line (e.g., OpenSSL 1.1 and 3) rather than failing with a conflict error.
crates/lib/src · high confidence
Behavioural changes
Configurable distribution URL and pantry tarball via build-time environment variables
The library now allows overriding the default distribution endpoint and the pantry tarball filename at build time. By setting the \PKGX\_DIST\_URL\ environment variable, users can point the binary to a custom distribution server (defaulting to \https://dist.pkgx.dev\ or \https://dist.pkgx.dev/v2\ on Windows). Additionally, the \PKGX\_PANTRY\_TARBALL\_FILENAME\ variable allows specifying a custom tarball name (defaulting to \pantry.tar.xz\). This is achieved through a new \build.rs\ script that injects these values into the compiled binary.
crates/lib · high confidence
Introduce new CLI modes and structured JSON output
The CLI now supports distinct operational modes: --query (-Q) to check program availability or list all available programs, --help (-h) for usage information, and --version (-v) to display the version. Users can now request structured output via --json=v2, which provides detailed package metadata including environment variables, runtime environment, associated programs, and companions. The tool also supports the @latest version specifier for packages, allows changing the working directory with --chdir (-C), and provides a --sync flag to force a database sync before execution.
crates/cli · high confidence
Dependencies
Initial dependency configuration for pkgx workspace
The project establishes a Rust workspace structure with \crates/cli\ (version 2.11.0) and \crates/lib\ (version 0.9.0), defining core dependencies such as \tokio\, \rusqlite\, \nix\, and \reqwest\ (0.13). The CLI crate includes \indicatif\ for progress reporting and configures \native-tls\ with vendored OpenSSL for non-macOS builds to ensure standalone operation in minimal environments.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 64 → 62 (-2.0)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.
Lenses
- Code Health 88 → 88 (+0.0)
- Architecture 100 → 94 (-5.8)
- Maturity 60 → 60 (+0.0)
- Readiness 71 → 53 (-17.6)
- Security 54 → 61 (+7.3)
- Performance 100 (new)
Resolved (2)
- Documentation: no installation or build instructions (docs/installing-pkgx.md)
- Off-boarding risk: anonymized user #1
New (18)
- Ambiguous overlap between 'select' and 'resolve'. Both take a PackageReq and Config and return a Result. It is unclear if 'select' is a pre-resolution lookup (e.g., finding the package in the pantry) or if 'resolve' is the actual resolution step. The naming convention differs ('select' vs 'resolve') for potentially similar or sequential operations.
- Documentation: no installation or build instructions (docs/pkging/pantry-api.md)
- Documentation: no project overview (docs/pkging/pantry-api.md)
- Documentation: no usage examples (docs/pkging/pantry.md)
- Inconsistent naming and arity for environment manipulation. 'map' and 'mix' are generic verbs. 'mix' takes only input, while 'mix_runtime' takes input, installations, and a connection. It is unclear if 'map' is a transformation step for 'mix', or if 'mix' and 'mix_runtime' are overloaded versions of the same operation with different dependencies. The distinction between 'mix' and 'mix_runtime' is not immediately obvious from signatures alone.
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Off the main sequence: libpkgx
- Outdated: anyhow
- Outdated: async-compression
- Outdated: console
- Outdated: futures
- Outdated: indicatif
- Outdated: native-tls
- Outdated: reqwest
- Outdated: serde_json
- Outdated: tempfile
- Outdated: tokio-stream
- Outdated: tokio-util
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
pkgxdev/pkgx was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6de1d7e953b98061f69db95d4bd45a2a6ee5d7da — the exact code this score is about.
- Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fbec9b1e08c2.