pkg.soopen package index

brew / Rang 170

bubblewrap mit Homebrew, apk, apt, dnf, Nix, pacman, zypper installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für bubblewrap in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install bubblewrap

local Homebrew formula metadata

Linux

Alpine Linux apkverifiziert · 92%
sudo apk add bubblewrap

Alpine Linux edge package indexes · bubblewrap · Quelle: dl-cdn.alpinelinux.org

Debian aptverifiziert · 92%
sudo apt install bubblewrap

Debian stable package indexes · bubblewrap · Quelle: deb.debian.org

Fedora dnfverifiziert · 92%
sudo dnf install bubblewrap

Fedora Rawhide package metadata · bubblewrap · Quelle: dl.fedoraproject.org

Nixverifiziert · 92%
nix profile install nixpkgs#bubblewrap

nixpkgs package indexes · pkgs/by-name/bu/bubblewrap/package.nix · Quelle: api.github.com

Arch Linux pacmanverifiziert · 92%
sudo pacman -S bubblewrap

Arch Linux sync databases · bubblewrap · Quelle: geo.mirror.pkgbuild.com

openSUSE zypperverifiziert · 92%
sudo zypper install bubblewrap

openSUSE Tumbleweed package metadata · bubblewrap · Quelle: download.opensuse.org

Überblick

Paketzusammenfassung

Unprivileged sandboxing tool for Linux

Befehle und Aliase

  • bwrap

Verlauf

Projektgeschichte und Nutzung

bubblewrap is a low-level Linux sandboxing tool that constructs restricted process environments with namespaces, bind mounts, seccomp, and related kernel features. It is best known as the small, auditable sandbox primitive used by Flatpak and similar desktop/container tools.

Projektgeschichte

The bubblewrap README positions it against system-administrator container runtimes such as Docker and systemd-nspawn: those tools are not suitable to hand directly to unprivileged users, while bubblewrap is designed around unprivileged sandbox construction.

The original code predates modern unprivileged user namespaces and inherits from xdg-app helper code, which in turn derives from linux-user-chroot. Older bubblewrap also supported a setuid mode for systems without unprivileged user namespaces, but the README notes that setuid support has been removed.

The public GitHub repository was created in February 2016. The repository description identifies bubblewrap as a low-level unprivileged sandboxing tool used by Flatpak and similar projects, with topics for Linux containers and user namespaces.

Adoptionsgeschichte

bubblewrap spread because Flatpak and related desktop sandboxing systems needed a small shared primitive instead of each project carrying its own privileged helper. The README lists Flatpak, rpm-ostree unprivileged, and bwrap-oci as users or intended users.

The input package metadata shows broad Linux distribution packaging through Alpine, Debian, Fedora/dnf, Nix, Arch/pacman, Ubuntu, and openSUSE/zypper, plus Homebrew. That breadth reflects its role as plumbing for sandbox frameworks rather than as an end-user application.

Security-sensitive adoption is cautious: bubblewrap constructs a sandbox, but the actual security boundary depends on the arguments supplied by the caller. This makes it attractive for larger frameworks that own policy and want a narrow mechanism.

Wie es verwendet wird

bwrap creates a new mount namespace whose root is an empty tmpfs, then command-line options bind selected host paths, create proc/dev views, unshare namespaces, apply seccomp filters, and run a command inside the resulting environment.

Typical direct use is scripting a constrained shell or process; typical indirect use is through Flatpak or another framework that assembles a policy-specific bwrap command. The project has no ordinary per-user config file or credentials store.

Warum Paket-Nerds sich dafür interessieren

bubblewrap is package-manager-significant because a small CLI becomes part of the desktop Linux trust base. Its package version, setuid/user-namespace behavior, CVE history, and distribution kernel defaults can affect whether higher-level sandboxing stacks actually work.

It is also a clean example of separating mechanism from policy: package the tiny sandbox constructor once, let Flatpak and peers define the higher-level sandbox rules.

Zeitleiste

  • Pre-2016: Code lineage passes through linux-user-chroot and xdg-app helper.
  • 2016: Public GitHub repository for bubblewrap is created.
  • 2010s: bubblewrap becomes associated with Flatpak-style application sandboxing.
  • 2020s: setuid mode is removed; user namespaces are the documented sandbox basis.
  • 2026: Tags include v0.11.x, showing continuing maintenance.

Related projects

  • Flatpak is the most prominent higher-level application sandbox stack using bubblewrap.
  • xdg-app helper is part of bubblewrap's code lineage.
  • linux-user-chroot is an older related sandbox/chroot tool in the lineage.
  • Firejail is a comparable desktop sandboxing project discussed in the bubblewrap README.
  • xdg-dbus-proxy is commonly paired with bubblewrap to mediate D-Bus access.

Sicherheitslage

Risikostufe: grün

narrow executable package without higher-risk signals.

Risikoklassifikator

grün Risiko · niedrig Konfidenz · appliance

Warum

  • narrow executable package without higher-risk signals

Signale

  • metadata:no-higher-risk-signals

Installationsverhalten

  • Es wurden keine Homebrew-Bottle-Metadaten erfasst.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
bwrapExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-08-03
Manager-Version0.11.2
Manager aktualisiert2026-06-11
lokale Datenunbekannt
Upstreamnicht verfügbar
neueste erkannte Versionnicht erkannt
  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:bubblewrap
Version0.11.2
PaketmanagerHomebrew
Homepagehttps://github.com/containers/bubblewrap
Repositoryhttps://github.com/containers/bubblewrap
Zuletzt aktualisiert2026-06-11T17:22:39Z
Pulseupdated
Bottlenicht erfasst
Dienstkeiner deklariert

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Debian apt95%

bubblewrap 0.11.0-2+deb13u1

utility for unprivileged chroot and namespace manipulation

https://github.com/containers/bubblewrap

sudo apt install bubblewrap
  • Section: admin
  • Architecture: amd64
  • 3 Abhängigkeiten
  • 1 optionale Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
Debian stable package indexes · deb.debian.org · Debian stable package indexes: bubblewrap from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Nix95%

bubblewrap

nix profile install nixpkgs#bubblewrap
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/bu/bubblewrap/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Ubuntu apt95%

bubblewrap 0.9.0-1build1

utility for unprivileged chroot and namespace manipulation

https://github.com/containers/bubblewrap

sudo apt install bubblewrap
  • Section: admin
  • Architecture: amd64
  • 3 Abhängigkeiten
  • 1 optionale Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: bubblewrap from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz
apk95%

bubblewrap 0.11.2-r0

Unprivileged sandboxing tool

https://github.com/containers/bubblewrap

sudo apk add bubblewrap
  • License: LGPL-2.0-or-later
  • Architecture: x86_64
  • Source Package: bubblewrap
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: bubblewrap from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz
apk95%

bubblewrap-bash-completion 0.11.2-r0

Bash completions for bubblewrap

https://github.com/containers/bubblewrap

sudo apk add bubblewrap-bash-completion
  • License: LGPL-2.0-or-later
  • Architecture: x86_64
  • Source Package: bubblewrap
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: bubblewrap-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz
apk95%

bubblewrap-doc 0.11.2-r0

Unprivileged sandboxing tool (documentation)

https://github.com/containers/bubblewrap

sudo apk add bubblewrap-doc
  • License: LGPL-2.0-or-later
  • Architecture: x86_64
  • Source Package: bubblewrap
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: bubblewrap-doc from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz
apk95%

bubblewrap-static 0.11.2-r0

Unprivileged sandboxing tool (static binary)

https://github.com/containers/bubblewrap

sudo apk add bubblewrap-static
  • License: LGPL-2.0-or-later
  • Architecture: x86_64
  • Source Package: bubblewrap
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: bubblewrap-static from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz
apk95%

bubblewrap-zsh-completion 0.11.2-r0

Zsh completions for bubblewrap

https://github.com/containers/bubblewrap

sudo apk add bubblewrap-zsh-completion
  • License: LGPL-2.0-or-later
  • Architecture: x86_64
  • Source Package: bubblewrap
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: bubblewrap-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz
dnf95%

bubblewrap 0.11.2-2.fc45

Core execution tool for unprivileged containers

https://github.com/containers/bubblewrap/

sudo dnf install bubblewrap
  • License: LGPL-2.0-or-later
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: bubblewrap
  • 5 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: bubblewrap from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst
pacman95%

bubblewrap 0.11.2-1

Unprivileged sandboxing tool

https://github.com/containers/bubblewrap

sudo pacman -S bubblewrap
  • License: LGPL-2.0-or-later
  • Architecture: x86_64
  • 3 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: bubblewrap from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
zypper95%

bubblewrap 0.11.2-1.3

Core execution tool for unprivileged containers

https://github.com/containers/bubblewrap

sudo zypper install bubblewrap
  • License: LGPL-2.0-or-later
  • Category: Productivity/Security
  • Architecture: x86_64
  • Source Package: bubblewrap
  • 3 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: bubblewrap from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst
zypper95%

bubblewrap-zsh-completion 0.11.2-1.3

Zsh tab-completion for bubblewrap

https://github.com/containers/bubblewrap

sudo zypper install bubblewrap-zsh-completion
  • License: LGPL-2.0-or-later
  • Category: System/Shells
  • Architecture: x86_64
  • Source Package: bubblewrap
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Bubblewrap
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: bubblewrap-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation