pkg.soopen package index

brew / rank 1256

Install aliyun-cli with Homebrew, Nix, pacman, zypper, winget, scoop

Universal Command-Line Interface for Alibaba Cloud. Version 3.4.11 via Homebrew; verified 2026-07-29. Also installable with nix: nix profile install nixpkgs#aliyun-cli.

agent safety

Agent safety answer

aliyun-cli controls Alibaba Cloud resources from local credentials.

Credential access

Reads Alibaba Cloud access keys, profiles, and environment credentials.

Remote mutation

Can create, delete, and modify cloud resources.

Publish/artifact risk

Can deploy infrastructure and upload artifacts to cloud services.

Recommended control

Gate mutating aliyun commands and credential access.

Agent-use guidance

Allow read-only listing; require approval for writes, deletes, and deploys.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install aliyun-cli

local Homebrew formula metadata

Linux

Nixverified · 92%
nix profile install nixpkgs#aliyun-cli

nixpkgs package indexes · pkgs/by-name/al/aliyun-cli/package.nix · source: api.github.com

Arch Linux pacmanverified · 92%
sudo pacman -S aliyun-cli

Arch Linux sync databases · aliyun-cli · source: geo.mirror.pkgbuild.com

openSUSE zypperverified · 92%
sudo zypper install aliyun-cli

openSUSE Tumbleweed package metadata · aliyun-cli · source: download.opensuse.org

Windows

Windows Package Managerverified · 92%
winget install --id Alibaba.AlibabaCloudCLI -e

Windows Package Manager source index · Alibaba.AlibabaCloudCLI · source: cdn.winget.microsoft.com

Scoopverified · 92%
scoop install main/aliyun

Scoop official bucket manifest trees · bucket/aliyun.json · source: api.github.com

overview

Package summary

Universal Command-Line Interface for Alibaba Cloud

Commands and aliases

  • aliyun

history

Project history and usage

Alibaba Cloud CLI is Alibaba Cloud's open-source command-line interface for managing Alibaba Cloud resources through OpenAPI.

Project history

The public repository begins in git history on 2015-06-30. The current README describes the CLI as a Go tool built on top of Alibaba Cloud OpenAPI and distributed through GitHub releases, platform installers, a one-line installer, and package managers.

The changelog records a v0.1 entry dated 2018-01-11 with a Go refactoring, basic configuration, and automatic endpoint location. Later pre-v3 entries added richer configuration commands, authentication modes, completion, paging, ossutil integration, and v3.0.0 GA refactoring.

Adoption history

The README explicitly supports trying the CLI in Alibaba Cloud Shell before local installation, which gives it both a hosted-cloud and local-terminal path. It documents Homebrew installation, direct downloads for macOS, Linux, and Windows, and links to GitHub releases.

The input package-manager facts show broad downstream packaging: Homebrew, Nix, pacman, Scoop, winget, and zypper.

How it is used

Users normally start with aliyun configure, which writes profile data including credentials, region, output format, and language. The README documents authentication modes including AK, RAM role ARN, ECS RAM role, OIDC, external credential process, CredentialsURI, chainable RAM role ARN, and CloudSSO.

Once configured, the aliyun executable invokes Alibaba Cloud OpenAPI actions and product commands from the terminal, with troubleshooting support tied to RequestID or error messages.

Why package nerds care

aliyun-cli is the canonical terminal entry point for Alibaba Cloud automation. For package maintainers, it is a multi-platform cloud CLI with real credential storage, release assets, shell completion, and frequent cloud-service surface changes.

Timeline

  • 2015: Public Git history begins.
  • 2018: Changelog records v0.1 with Go refactoring and basic configuration.
  • 2018: v3.0.1 tag exists in repository history.
  • 2026: v3.4.2 tag appears in repository history.

Related projects

  • Alibaba Cloud OpenAPI: service interface layer used by the CLI.
  • ossutil: object-storage toolset integrated according to the changelog.

Sources

  • Git history from https://github.com/aliyun/aliyun-cli.git
  • Official README: https://raw.githubusercontent.com/aliyun/aliyun-cli/master/README.md
  • Official changelog: https://raw.githubusercontent.com/aliyun/aliyun-cli/master/CHANGELOG.md
  • source_facts.package-manager

security posture

Risk level: orange

infrastructure mutation or orchestration signal.

Risk classifier

orange risk · medium confidence · infrastructure

Why

  • infrastructure mutation or orchestration signal

Signals

  • text:cloud

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.aliyun/config.json

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
~/.aliyun/config.json

executables

Installed executables

CommandKindExposureNote
aliyunexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version3.4.11
manager updated2026-07-29
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:aliyun-cli
Version3.4.11
Package managerHomebrew
Homepagehttps://github.com/aliyun/aliyun-cli
Repositoryhttps://github.com/aliyun/aliyun-cli
Last updated2026-07-29T11:52:59Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

aliyun-cli

nix profile install nixpkgs#aliyun-cli
  • normalized package name match
  • Matched by: Aliyun Cli
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/al/aliyun-cli/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
pacman95%

aliyun-cli 3.4.8-1

Alibaba Cloud CLI

https://github.com/aliyun/aliyun-cli

sudo pacman -S aliyun-cli
  • License: Apache-2.0
  • Architecture: x86_64
  • 1 dependencies
  • normalized package name match
  • Matched by: Aliyun Cli
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: aliyun-cli from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
zypper95%

aliyun-cli 3.4.8-1.1

Alibaba Cloud CLI

https://github.com/aliyun/aliyun-cli

sudo zypper install aliyun-cli
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: aliyun-cli
  • 1 provides
  • normalized package name match
  • Matched by: Aliyun Cli
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: aliyun-cli from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst
winget95%

Alibaba.AlibabaCloudCLI

winget install --id Alibaba.AlibabaCloudCLI -e
  • normalized package name match
  • Matched by: Aliyun Cli
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: Alibaba.AlibabaCloudCLI from https://cdn.winget.microsoft.com/cache/source.msix
Scoop92%

main/aliyun

scoop install main/aliyun
  • installed executable or alias match
  • Matched by: Aliyun
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/aliyun.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated agent safety answer
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation