{"id":4398,"date":"2026-06-22T15:12:26","date_gmt":"2026-06-22T15:12:26","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/06\/22\/homebrew-to-packages-no-id-no-service\/"},"modified":"2026-06-22T15:12:26","modified_gmt":"2026-06-22T15:12:26","slug":"homebrew-to-packages-no-id-no-service","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/06\/22\/homebrew-to-packages-no-id-no-service\/","title":{"rendered":"Homebrew to Packages: No ID, No Service"},"content":{"rendered":"<div><img data-opt-id=1623854027  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/06\/homebrew_6_security_770x330.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=1510451908  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/06\/homebrew_6_security_770x330-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p><span>Homebrew, the unofficial but default package manager for many Apple Mac users, now has safeguards to prevent supply-chain attacks. <\/span><\/p>\n<p><span>The approach mimics how GitHub just fortified npm against attacks by establishing a set of trusted repositories to download from. <\/span><\/p>\n<p><span>\u201cThe Homebrew team is aware of the supply-side security issues with other package managers. We\u2019ve taken various steps to mitigate these risks for our users,\u201d wrote current Homebrew Project Leader Mike McQuaid in the <\/span><a href=\"https:\/\/brew.sh\/2026\/06\/11\/homebrew-6.0.0\/\"><span>6.0.0 introductory post<\/span><\/a><span>. <\/span><\/p>\n<h3><b>Check the Guestlist<\/b><\/h3>\n<p><span>When Max Howell created Homebrew in 2009, he consistently named features with terms from beer brewing and consumption. Thus, when a user needs new software on their machine, they open a \u201ctap\u201d to a third-party repository. <\/span><\/p>\n<p><span>Now, the software\u2019s maintainers have added a safety mechanism to tap, preventing execution of installation code whose source hasn\u2019t already been vetted by the user or by Homebrew itself. It debuted with the release of Homebrew 6.0.0 last week. <\/span><\/p>\n<p><span>The Homebrew core engine now performs a gate check for each download request. Homebrew will block any tap that is not on a pre-approved list. The list is based on remote fully-qualified URLs. Other taps on the Internet will be considered untrusted until the user deems otherwise. <\/span><\/p>\n<p><span>Users can still download third-party software, but only after issuing a separate command: \u2018brew trust user\/repo\u2019.<\/span><\/p>\n<p><span>Users can also add third-party taps, including their own. To install an untrusted app, the user specifies in the command the<\/span><a href=\"https:\/\/github.com\/ddev\/ddev\/issues\/8450\"><span> full qualified domain path<\/span><\/a><span> to the installation formula. <\/span><\/p>\n<p><span>Homebrew halts dependency downloading from untrusted sources, instead of silently downloading it in the background as previous versions did. <\/span><\/p>\n<p><span>A Boolean `trusted` field is also baked into Homebrew\u2019s state management, which gives auditors information on which downloaded taps are trusted. <\/span><\/p>\n<p><span>Package maintainers may need to change their installation instructions and README files to detail how to put their repositories on their personal trust lists. Those with Homebrew baked into their CI\/CD pipelines will need to write \u2018brew trust\u2019 commands into their setup scripts at the appropriate points. <\/span><\/p>\n<h3><b>New Recipe for Brewers<\/b><\/h3>\n<p><span>Every application in the Homebrew ecosystem must include a Ruby script that tells Homebrew how to download, compile and\/or install the software. This is where the trouble starts.<\/span><\/p>\n<p><span>Homebrew hasn\u2019t yet been hit with any major attempts to poison its core repositories (that we know of), though other repositories, such as npm and PyPI, have been hit hard. Attackers altered setup scripts to sneak in poisoned packages (see: <\/span><a href=\"https:\/\/attack.mitre.org\/software\/S9008\/\"><span>Shai-Hulud<\/span><\/a><span> was one recent npm attack that used this approach). <\/span><\/p>\n<p><span>In fact, the<\/span><a href=\"https:\/\/securityboulevard.com\/2026\/06\/github-locks-down-npm-what-the-new-install-defaults-mean-for-your-supply-chain\/\"><span> npm maintainers<\/span><\/a><span> at GitHub re-engineered how npm downloads software using an approach similar to Homebrew\u2019s, namely by blocking any installation scripts that don\u2019t already have user approval. This update should come with the release of npm v12 <\/span><a href=\"https:\/\/github.blog\/changelog\/2026-06-09-upcoming-breaking-changes-for-npm-v12\/\"><span>due next month<\/span><\/a><span>. <\/span><\/p>\n<h3><b>Brewski Changes for Linux Users Too <\/b><\/h3>\n<p><span>In addition to serving the Mac community, Homebrew is also used quite a bit in the Linux community as well. McQuaid and his colleagues did some security work for this group as well. They incorporated <\/span><a href=\"https:\/\/github.com\/containers\/bubblewrap\"><span>Bubblewrap<\/span><\/a><span> into Homebrew, so that the software sandboxes application builds, tests and post-install phases (<\/span><a href=\"https:\/\/github.com\/secureblue\/secureblue\/issues\/1891\"><span>replicating<\/span><\/a><span> a functionality Macs already offer).<\/span><\/p>\n<p><span>With 6.0.0, this feature is <\/span><a href=\"https:\/\/github.com\/Homebrew\/brew\/pull\/22370\"><span>automatically enabled<\/span><\/a><span> for developers. When they test new software installations, Bubblewrap confines any actions taken by the start-up scripts to a new mount namespace. <\/span><\/p>\n<p><span>Homebrew 6.0 is the first major release since <\/span><a href=\"https:\/\/brew.sh\/2025\/11\/12\/homebrew-5.0.0\"><span>version 5.0<\/span><\/a><span> last November. In addition to the security features, it also includes a new JSON API, which <\/span><a href=\"https:\/\/github.com\/Homebrew\/brew\/pull\/22546\"><span>should speed<\/span><\/a><span> downloads and reduce network chatter. <\/span><\/p>\n<p><a href=\"https:\/\/devops.com\/homebrew-to-packages-no-id-no-service\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>Homebrew, the unofficial but default package manager for many Apple Mac users, now has safeguards to prevent supply-chain attacks. The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4399,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-4398","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4398","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=4398"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4398\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/4399"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=4398"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=4398"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=4398"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}