# bubblewrap mit Homebrew, apk, apt, dnf, Nix, pacman, zypper installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für bubblewrap in AI-Agent-Workflows.

## Installation

```sh
sudo av install brew:bubblewrap
```

Weitere Installationsbefehle:

### macOS

- Homebrew (100%):

```sh
brew install bubblewrap
```

  Evidenz: local Homebrew formula metadata

### Linux

- apk (92%):

```sh
sudo apk add bubblewrap
```

  Evidenz: Alpine Linux edge package indexes: bubblewrap from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz

- Debian apt (92%):

```sh
sudo apt install bubblewrap
```

  Evidenz: Debian stable package indexes: bubblewrap from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

- dnf (92%):

```sh
sudo dnf install bubblewrap
```

  Evidenz: Fedora Rawhide package metadata: bubblewrap from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst

- Nix (92%):

```sh
nix profile install nixpkgs#bubblewrap
```

  Evidenz: nixpkgs package indexes: pkgs/by-name/bu/bubblewrap/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- pacman (92%):

```sh
sudo pacman -S bubblewrap
```

  Evidenz: Arch Linux sync databases: bubblewrap from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

- zypper (92%):

```sh
sudo zypper install bubblewrap
```

  Evidenz: openSUSE Tumbleweed package metadata: bubblewrap from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

## Paketfakten

- **Paketschlüssel:** brew:bubblewrap
- **Paketmanager:** Homebrew
- **Version:** 0.11.2
- **Quellzusammenfassung:** Unprivileged sandboxing tool for Linux
- **Homepage:** <https://github.com/containers/bubblewrap>
- **Repository:** <https://github.com/containers/bubblewrap>
- **Zuletzt aktualisiert:** 2026-06-11T17:22:39Z
- **Generiert:** 2026-08-03T19:37:03+00:00

## Executables

- bwrap (Alias)

## Installationsverhalten

- Bottle: nicht verfügbar

## Version und Aktualität

- Seite generiert: 2026-08-03
- Manager-Version: 0.11.2
## Projektgeschichte und Nutzung

bubblewrap is a low-level Linux sandboxing tool that constructs restricted process environments with namespaces, bind mounts, seccomp, and related kernel features. It is best known as the small, auditable sandbox primitive used by Flatpak and similar desktop/container tools.

### Projektgeschichte

The bubblewrap README positions it against system-administrator container runtimes such as Docker and systemd-nspawn: those tools are not suitable to hand directly to unprivileged users, while bubblewrap is designed around unprivileged sandbox construction.

The original code predates modern unprivileged user namespaces and inherits from xdg-app helper code, which in turn derives from linux-user-chroot. Older bubblewrap also supported a setuid mode for systems without unprivileged user namespaces, but the README notes that setuid support has been removed.

The public GitHub repository was created in February 2016. The repository description identifies bubblewrap as a low-level unprivileged sandboxing tool used by Flatpak and similar projects, with topics for Linux containers and user namespaces.

### Adoptionsgeschichte

bubblewrap spread because Flatpak and related desktop sandboxing systems needed a small shared primitive instead of each project carrying its own privileged helper. The README lists Flatpak, rpm-ostree unprivileged, and bwrap-oci as users or intended users.

The input package metadata shows broad Linux distribution packaging through Alpine, Debian, Fedora/dnf, Nix, Arch/pacman, Ubuntu, and openSUSE/zypper, plus Homebrew. That breadth reflects its role as plumbing for sandbox frameworks rather than as an end-user application.

Security-sensitive adoption is cautious: bubblewrap constructs a sandbox, but the actual security boundary depends on the arguments supplied by the caller. This makes it attractive for larger frameworks that own policy and want a narrow mechanism.

### Wie es verwendet wird

bwrap creates a new mount namespace whose root is an empty tmpfs, then command-line options bind selected host paths, create proc/dev views, unshare namespaces, apply seccomp filters, and run a command inside the resulting environment.

Typical direct use is scripting a constrained shell or process; typical indirect use is through Flatpak or another framework that assembles a policy-specific bwrap command. The project has no ordinary per-user config file or credentials store.

### Warum Paket-Nerds sich dafür interessieren

bubblewrap is package-manager-significant because a small CLI becomes part of the desktop Linux trust base. Its package version, setuid/user-namespace behavior, CVE history, and distribution kernel defaults can affect whether higher-level sandboxing stacks actually work.

It is also a clean example of separating mechanism from policy: package the tiny sandbox constructor once, let Flatpak and peers define the higher-level sandbox rules.

### Zeitleiste

- Pre-2016: Code lineage passes through linux-user-chroot and xdg-app helper.
- 2016: Public GitHub repository for bubblewrap is created.
- 2010s: bubblewrap becomes associated with Flatpak-style application sandboxing.
- 2020s: setuid mode is removed; user namespaces are the documented sandbox basis.
- 2026: Tags include v0.11.x, showing continuing maintenance.

### Related projects

- Flatpak is the most prominent higher-level application sandbox stack using bubblewrap.
- xdg-app helper is part of bubblewrap's code lineage.
- linux-user-chroot is an older related sandbox/chroot tool in the lineage.
- Firejail is a comparable desktop sandboxing project discussed in the bubblewrap README.
- xdg-dbus-proxy is commonly paired with bubblewrap to mediate D-Bus access.

### Quellen

- <https://api.github.com/repos/containers/bubblewrap>
- <https://api.github.com/repos/containers/bubblewrap/tags?per_page=10>
- <https://github.com/containers/bubblewrap#readme>
- source_facts.package-manager


## Sicherheitshinweise

narrow executable package without higher-risk signals.

- **Geiger-Risiko:** grün / niedrig
- narrow executable package without higher-risk signals

## Andere Paketmanager-Einträge

- Debian apt - bubblewrap - 0.11.0-2+deb13u1: normalized package name match | Debian stable package indexes: bubblewrap from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | utility for unprivileged chroot and namespace manipulation | https://github.com/containers/bubblewrap
- Nix - bubblewrap: normalized package name match | nixpkgs package indexes: pkgs/by-name/bu/bubblewrap/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- Ubuntu apt - bubblewrap - 0.9.0-1build1: normalized package name match | Ubuntu 24.04 LTS package indexes: bubblewrap from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz | utility for unprivileged chroot and namespace manipulation | https://github.com/containers/bubblewrap
- apk - bubblewrap - 0.11.2-r0: normalized package name match | Alpine Linux edge package indexes: bubblewrap from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz | Unprivileged sandboxing tool | https://github.com/containers/bubblewrap
- apk - bubblewrap-bash-completion - 0.11.2-r0: normalized package name match | Alpine Linux edge package indexes: bubblewrap-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz | Bash completions for bubblewrap | https://github.com/containers/bubblewrap
- apk - bubblewrap-doc - 0.11.2-r0: normalized package name match | Alpine Linux edge package indexes: bubblewrap-doc from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz | Unprivileged sandboxing tool (documentation) | https://github.com/containers/bubblewrap
- apk - bubblewrap-static - 0.11.2-r0: normalized package name match | Alpine Linux edge package indexes: bubblewrap-static from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz | Unprivileged sandboxing tool (static binary) | https://github.com/containers/bubblewrap
- apk - bubblewrap-zsh-completion - 0.11.2-r0: normalized package name match | Alpine Linux edge package indexes: bubblewrap-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz | Zsh completions for bubblewrap | https://github.com/containers/bubblewrap
- dnf - bubblewrap - 0.11.2-2.fc45: normalized package name match | Fedora Rawhide package metadata: bubblewrap from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst | Core execution tool for unprivileged containers | https://github.com/containers/bubblewrap/
- pacman - bubblewrap - 0.11.2-1: normalized package name match | Arch Linux sync databases: bubblewrap from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz | Unprivileged sandboxing tool | https://github.com/containers/bubblewrap
- zypper - bubblewrap - 0.11.2-1.3: normalized package name match | openSUSE Tumbleweed package metadata: bubblewrap from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Core execution tool for unprivileged containers | https://github.com/containers/bubblewrap
- zypper - bubblewrap-zsh-completion - 0.11.2-1.3: normalized package name match | openSUSE Tumbleweed package metadata: bubblewrap-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Zsh tab-completion for bubblewrap | https://github.com/containers/bubblewrap


## Combined YAML source

View the package source record on GitHub. [combined/bubblewrap.yml](https://github.com/mxcl/pkgdb/blob/main/combined/bubblewrap.yml)


## Quellen

- pkg.so package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
