pkg.soopen package index

brew / rank 6525

Install ubi with Homebrew, winget

Universal Binary Installer. Version 0.10.0 via Homebrew; verified 2026-07-26. Also installable with winget: winget install --id houseabsolute.ubi -e.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install ubi

local Homebrew formula metadata

Windows

Windows Package Managerverified · 92%
winget install --id houseabsolute.ubi -e

Windows Package Manager source index · houseabsolute.ubi · source: cdn.winget.microsoft.com

overview

Package summary

Universal Binary Installer

Commands and aliases

  • ubi

history

Project history and usage

ubi, the Universal Binary Installer, is a small CLI for installing prebuilt binaries from GitHub releases and similar release pages. It belongs to the newer generation of package-helper tools that automate the common shell-script pattern of selecting the right OS and CPU asset, downloading it, and putting the binary on PATH.

Project history

The official repository describes ubi as the Universal Binary Installer. Its release page shows a 0.x project with signed tags, many platform-specific release assets, and continuing changes around asset selection, platform matching, Android support, libc matching, private-repository downloads, and supply-chain safety.

The project is maintained by Dave Rolsky under the houseabsolute namespace and is distributed under Apache-2.0 OR MIT in the batch input. Its own releases are themselves a demonstration of the problem it solves: the v0.9.0 release publishes many per-platform archives and checksum assets.

Adoption history

ubi is adopted in package-nerd workflows where users want a lightweight installer for GitHub-release binaries without writing a custom curl, tar, and grep script for each tool. The batch input lists Homebrew and winget availability, reflecting its cross-platform installer niche.

Release notes show the project responding to real packaging edge cases: asset names that contain misleading numbers, Android targets, musl versus glibc Linux assets, private repositories, and minimum release age to reduce supply-chain risk.

How it is used

ubi is used to pick a matching release artifact for the current platform, download it, and install the contained binary. Its package-nerd use case is bootstrapping CLI tools from upstream release assets when a native package does not exist or when the user wants upstream's current binary.

The v0.9.0 release added a --min-age-days flag to consider only releases at least a specified age, explicitly framed by the project as useful for mitigating supply-chain attacks.

Why package nerds care

ubi matters because GitHub Releases became an unofficial binary distribution layer for many small CLIs. A generic installer for those releases sits between full package managers and one-off install scripts.

For Homebrew users, the amusing recursion is that a package manager can install ubi, and ubi can then install tools that are not packaged or are wanted directly from upstream release artifacts.

Timeline

  • 2024-2026: The visible release history is in the 0.x series, with repeated changes around release-asset matching and platform support.
  • 2026: v0.9.0 is released with --min-age-days for release-age filtering.

Related projects

  • GitHub Releases are the primary ecosystem surface for ubi's installer model.
  • Homebrew and winget provide native package-manager distribution for ubi itself according to the batch input.

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Installs with 1 runtime dependencies.
  • Build metadata lists 2 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
ubicliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-04
manager version0.10.0
manager updated2026-07-26
local dataok
upstreamcurrent
latest detectedv0.10.0

https://github.com/houseabsolute/ubi

  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:ubi
Version0.10.0
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/ubi
Homepagehttps://github.com/houseabsolute/ubi
Repositoryhttps://github.com/houseabsolute/ubi
LicenseApache-2.0 OR MIT
Source archivehttps://github.com/houseabsolute/ubi/archive/refs/tags/v0.10.0.tar.gz
Last updated2026-07-26T21:15:45Z
Pulseupdated
Dependenciesxz
Build dependenciespkgconf, rust
Uses from macOSbzip2
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameubi
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

winget95%

houseabsolute.ubi

winget install --id houseabsolute.ubi -e
  • normalized package name match
  • Matched by: Ubi
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: houseabsolute.ubi from https://cdn.winget.microsoft.com/cache/source.msix

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation