pkg.sopackage field notes

brew / 順位 1590

vcpkg を Homebrew でインストール

vcpkg のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install vcpkg

provider-native install command

概要

パッケージ概要

C++ Library Manager

コマンドとエイリアス

  • vcpkg

履歴

プロジェクトの歴史と使われ方

vcpkg is Microsoft's open-source C and C++ package manager, built around a curated ports registry, a command-line tool, and integration points for native build systems. It began as a way to make Windows C++ library consumption less painful, then grew into a cross-platform workflow for Windows, macOS, Linux, and multiple target triplets.

The project matters because it brought package-manager ergonomics to an ecosystem that historically depended on handwritten build instructions, vendored source trees, system packages, or project-specific CMake glue. Its package-nerd identity is the combination of source-built ports, reproducible baselines, triplets, binary caching, and manifest files checked into application repositories.

プロジェクトの歴史

The public Microsoft/vcpkg repository was created on 2016-09-15, matching Microsoft's later description of the September 2022 release as vcpkg's sixth anniversary. Early vcpkg centered on a shared installed tree and simple commands for acquiring C++ libraries; the maintained registry became the main social and technical object, with contributors adding and updating port recipes.

By 2020, vcpkg's implementation was being separated into the Microsoft/vcpkg-tool repository, whose GitHub metadata describes it as the components of the vcpkg binary. That split reflects the project's maturation from a scripts-and-ports repository into a package manager with an independently released tool and a fast-moving registry.

採用の歴史

Microsoft's C++ Team reported in October 2022 that vcpkg had passed 2,000 unique open-source libraries in its public registry, with over 10,000 available port versions, 95 contributors active during that release window, 4.8k forks, and 16.8k GitHub stars. On 2026-07-02, GitHub API metadata for Microsoft/vcpkg showed more than 27k stars and 7.6k forks, indicating continued adoption in the C++ tooling community.

The public vcpkg site describes a catalog of 2,849 open-source libraries, while Microsoft Learn material presents vcpkg as a free C/C++ package manager for acquiring and managing libraries and adding private libraries. The adoption story is therefore both public-registry growth and enterprise workflow growth: teams can pin baselines, use custom registries, and share binary caches in CI.

使われ方

Modern vcpkg use is usually manifest mode: projects commit a vcpkg.json file declaring direct dependencies and, when needed, a vcpkg-configuration.json file for registries and baselines. Microsoft Learn describes manifest mode as the recommended workflow for most users, while classic mode remains available for installing packages directly into a vcpkg tree.

Package users care about triplets because vcpkg packages are built for a target configuration rather than merely downloaded as opaque archives. CI-heavy users care about binary caching, which Microsoft documents as a way to persist vcpkg-built binaries across clean build agents, including GitHub Actions workflows.

パッケージ好きにとっての重要性

vcpkg is significant because it treats C++ package management as a build-recipe and ABI problem instead of only a download problem. Ports can encode source retrieval and build steps, triplets encode target choices, manifests encode project dependencies, and baselines make dependency versions reviewable in source control.

For package maintainers, vcpkg also became a visible catalog of C and C++ library portability work. A working port is not just a version number; it is evidence that a library can be fetched, patched if necessary, configured, built, and tested across at least one supported target.

タイムライン

  • 2016-09-15: The Microsoft/vcpkg GitHub repository was created.
  • 2020-12-08: The Microsoft/vcpkg-tool repository was created for the vcpkg binary components.
  • 2022-10-06: Microsoft marked vcpkg's sixth anniversary and reported more than 2,000 unique libraries in the public registry.
  • 2024: Microsoft Learn continued positioning manifest mode as the recommended workflow for most users.
  • 2026-07-02: GitHub API metadata showed Microsoft/vcpkg with more than 27k stars and active pushes on the same day.

Related projects

  • vcpkg is commonly compared with Conan, system package managers, language-specific package managers, and project-local vendoring. Its closest internal companion is vcpkg-tool, the repository for the compiled tool that works with the main ports registry.
  • In CMake projects, vcpkg is often used through its toolchain integration, so its practical ecosystem overlaps heavily with CMake, MSBuild, Visual Studio, GitHub Actions, NuGet-style binary caches, and private source registries.

ソース

セキュリティ状態

リスクレベル: グリーン

library-like package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • library-like package without higher-risk signals

信号

  • metadata:library-like

インストール挙動

  • Homebrew bottle メタデータは記録されていません。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
vcpkg.jsonvcpkg-configuration.json

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
vcpkg実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-08-03
マネージャ版2026-07-27
マネージャ更新日2026-08-01
ローカルデータ不明
上流利用不可
検出された最新未検出
  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:vcpkg
バージョン2026-07-27
パッケージマネージャHomebrew
ホームページhttps://github.com/microsoft/vcpkg
リポジトリhttps://github.com/microsoft/vcpkg-tool
最終更新2026-08-01T02:49:51Z
Pulseupdated
Bottle未記録
サービス宣言なし

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation