# carton mit Homebrew, apt, winget installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für carton in AI-Agent-Workflows.

## Installation

```sh
sudo av install brew:carton
```

Weitere Installationsbefehle:

### macOS

- Homebrew (100%):

```sh
brew install carton
```

  Evidenz: local Homebrew formula metadata

### Linux

- Debian apt (92%):

```sh
sudo apt install carton
```

  Evidenz: Debian stable package indexes: carton from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

### Windows

- winget (92%):

```sh
winget install --id Unifan.Carton -e
```

  Evidenz: Windows Package Manager source index: Unifan.Carton from https://cdn.winget.microsoft.com/cache/source.msix

## Paketfakten

- **Paketschlüssel:** brew:carton
- **Paketmanager:** Homebrew
- **Paketmanager-Seite:** <https://formulae.brew.sh/formula/carton>
- **Version:** 1.0.35
- **Quellzusammenfassung:** Perl module dependency manager (aka Bundler for Perl)
- **Homepage:** <https://metacpan.org/pod/Carton>
- **Repository:** <https://github.com/perl-carton/carton>
- **Upstream-Dokumentation:** <https://metacpan.org/pod/Carton>
- **Lizenz:** Artistic-1.0-Perl OR GPL-1.0-or-later
- **Quellarchiv:** <https://cpan.metacpan.org/authors/id/M/MI/MIYAGAWA/Carton-v1.0.35.tar.gz>
- **Zuletzt aktualisiert:** 2026-06-13T01:03:34+02:00
- **Generiert:** 2026-08-04T22:13:35+00:00

## Executables

- carton (cli)
- carton (Alias)

## Abhängigkeiten

- perl

## Installationsverhalten

- Post-install-Hook: nicht definiert
- Bottle: verfügbar auf arm64_big_sur, arm64_linux, arm64_monterey, arm64_sequoia, arm64_sonoma, arm64_tahoe, arm64_ventura, big_sur, catalina, monterey, sonoma, ventura

## Version und Aktualität

- Seite generiert: 2026-08-04
- Manager-Version: 1.0.35
- Manager aktualisiert: 2026-06-13
- lokale Daten: OK
- Upstream-Repository: https://metacpan.org/pod/Carton
- Info: Release/tag comparison is only available for GitHub repositories.
## Projektgeschichte und Nutzung

Carton is a Perl application dependency manager, described by its official README and MetaCPAN metadata as a Bundler-like tool for Perl. It tracks dependencies declared in cpanfile and pins resolved module versions in cpanfile.snapshot.

### Projektgeschichte

The public GitHub repository was created in 2011 and the README copyright line credits Tatsuhiko Miyagawa from 2011 onward. The latest MetaCPAN release metadata identifies Carton-v1.0.35, authored by MIYAGAWA and dated May 7, 2022.

### Adoptionsgeschichte

Carton came from the Perl/CPAN application-deployment world, where repeatable local dependency installs mattered for web apps and services. Its README tells developers to commit cpanfile and cpanfile.snapshot so other machines and deployment boxes install the same dependency tree.

### Wie es verwendet wird

A typical workflow declares modules in cpanfile, runs carton install, commits cpanfile and cpanfile.snapshot, then runs commands through carton exec or points Perl at local/lib/perl5. Deployment mode installs exactly from the snapshot, and carton bundle can vendor tarballs into vendor/cache for cached or offline installs.

### Warum Paket-Nerds sich dafür interessieren

Carton is important package-manager plumbing because it adapts the lockfile-and-local-install pattern to CPAN applications. Its README explicitly references Bundler, pip, npm, cpanm, cpanfile, and Carmel, making it a useful bridge between Perl packaging culture and the broader application dependency-manager era.

### Zeitleiste

- 2011: Public GitHub repository created and copyright begins.
- 2022: MetaCPAN release metadata lists Carton-v1.0.35.
- 2020s: README documents cpanfile, cpanfile.snapshot, local installs, deployment mode, and vendored cache workflows.

### Related projects

- The README's SEE ALSO section points to Carmel, cpanm, cpanfile, Bundler, pip, npm, perlrocks, and only.
- Carton is closely tied to CPAN, cpanfile, local::lib-style local installs, and Perl application deployment.

### Quellen

- <https://api.github.com/repos/perl-carton/carton>
- <https://github.com/perl-carton/carton>
- <https://metacpan.org/pod/Carton>
- <https://metacpan.org/pod/Carton::Doc::Install>
- <https://formulae.brew.sh/api/formula/carton.json>


## Sicherheitshinweise

infrastructure mutation or orchestration signal.

- **Geiger-Risiko:** orange / mittel
- infrastructure mutation or orchestration signal


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: ./cpanfile
## Details aus der Quelldatenbank

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** carton
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable

## Andere Paketmanager-Einträge

- Debian apt - carton - 1.0.35-1: normalized package name match | Debian stable package indexes: carton from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | Perl module dependency manager (aka Bundler for Perl) | https://metacpan.org/release/Carton
- Ubuntu apt - carton - 1.0.35-1: normalized package name match | Ubuntu 24.04 LTS package indexes: carton from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz | Perl module dependency manager (aka Bundler for Perl) | https://metacpan.org/release/Carton
- winget - Unifan.Carton: normalized package name match | Windows Package Manager source index: Unifan.Carton from https://cdn.winget.microsoft.com/cache/source.msix


## Verwandte Links

- [Secret-risk packages](https://pkg.so/de/secret-risk-packages/) - Has protected-tool coverage, approval-gate, or non-low Geiger security signals.
- [Terminal utility packages](https://pkg.so/de/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Text processing packages](https://pkg.so/de/text-processing-tools/) - Matched text, document, or structured-data processing metadata.
- [Developer build packages](https://pkg.so/de/developer-build-tools/) - Matched build, compiler, generator, or developer workflow metadata.
- [perl](https://pkg.so/de/brew/perl/) - Runtime dependency declared by Homebrew.
- [cpanminus](https://pkg.so/de/brew/cpanminus/) - Shares pkgdb curated category or tags: cli, cpan, developer-tools, perl.
- [cpm](https://pkg.so/de/brew/cpm/) - Shares pkgdb curated category or tags: cli, cpan, developer-tools, perl.
- [cocoapods](https://pkg.so/de/brew/cocoapods/) - Shares pkgdb curated category or tags: cli, dependency-manager, developer-tools.
- [mint](https://pkg.so/de/brew/mint/) - Shares pkgdb curated category or tags: cli, dependency-manager, developer-tools.
- [lcov](https://pkg.so/de/brew/lcov/) - Shares pkgdb curated category or tags: cli, developer-tools, perl.
- [composer](https://pkg.so/de/brew/composer/) - Shares pkgdb curated category or tags: cli, dependency-manager, developer-tools.
- [cask](https://pkg.so/de/brew/cask/) - Shares pkgdb curated category or tags: cli, dependency-manager, developer-tools.
- [conan](https://pkg.so/de/brew/conan/) - Shares pkgdb curated category or tags: cli, dependency-manager, developer-tools.
- [carthage](https://pkg.so/de/brew/carthage/) - Local package facts share a topical domain. Shared terms: cli, dependency, dependency-manager, developer, developer-tools.

## Combined YAML source

View the package source record on GitHub. [combined/carton.yml](https://github.com/mxcl/pkgdb/blob/main/combined/carton.yml)


## Quellen

- pkg.so package database
- Geiger risk classifier
- package-page enrichment
- curated configuration and credential file locations
- curated package history
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
