macOS
brew install gnupgprovider-native install command
brew / rank 56
GNU Privacy Guard (OpenPGP). Version 2.5.21 via Homebrew; verified 2026-07-31.
install
brew install gnupgprovider-native install command
overview
GNU Privacy Guard (OpenPGP)
history
GnuPG, also known as GPG, is the GNU Privacy Guard: a free implementation of the OpenPGP standard used for encryption, signatures and key management.
GnuPG was introduced in 1997 as Free Software and became the GNU project's OpenPGP implementation. The project describes it as a complete and free implementation of OpenPGP, with command-line integration, key-management facilities and access modules for public-key directories.
The release-line history shows the 1.0 branch born in 1999, the 1.4 branch in 2004, the 2.0 branch in 2006 and later 2.x branches adding the more modular architecture around gpg-agent, dirmngr, gpgsm, smart-card support and supporting libraries.
GnuPG became a standard security tool in Unix-like systems and software-distribution workflows. The project download page notes that common Linux distributions such as Debian, Fedora, Red Hat and Ubuntu include GnuPG, while Gpg4win provides an integrated Windows distribution with a context menu tool, crypto manager and Outlook plugin.
Its ecosystem includes libraries and frontends as well as helper packages such as pinentry, GPGME, GPA and Scute. That surrounding stack made GnuPG a platform for applications needing OpenPGP operations rather than only an interactive command.
Practitioners use GnuPG to encrypt and decrypt files or messages, create and verify signatures, manage public and private keys, fetch or publish keys through directory mechanisms, operate smart cards and verify downloaded source releases. Its command-line interface also makes it common in scripts, build systems and release automation.
For package users, GnuPG is foundational plumbing: it links archive signatures, maintainer keys, trust databases, agents, pinentry programs, smart-card daemons and language bindings. Installing it often means installing the small operational security stack around OpenPGP, not just the gpg binary.
security posture
No matching local secret-handling manifest was found for gnupg. Nucleus package metadata is still published here so future coverage has a stable package URL.
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
~/.gnupg/gpg.conf~/.gnupg/gpg-agent.conf~/.gnupg/dirmngr.conf~/.gnupg/common.confCredential-bearing paths to review before unattended agent runs.
~/.gnupg/private-keys-v1.d/~/.gnupg/secring.gpg~/.gnupg/trustdb.gpgexecutables
| Command | Kind | Exposure | Note |
|---|---|---|---|
addgnupghome | executable | indexed executable | Discovered from the local executable index. |
applygnupgdefaults | executable | indexed executable | Discovered from the local executable index. |
dirmngr | executable | indexed executable | Discovered from the local executable index. |
dirmngr-client | executable | indexed executable | Discovered from the local executable index. |
gpg | executable | indexed executable | Discovered from the local executable index. |
gpg-agent | executable | indexed executable | Discovered from the local executable index. |
gpg-authcode-sign.sh | executable | indexed executable | Discovered from the local executable index. |
gpg-card | executable | indexed executable | Discovered from the local executable index. |
gpg-connect-agent | executable | indexed executable | Discovered from the local executable index. |
gpg-mail-tube | executable | indexed executable | Discovered from the local executable index. |
gpg-wks-client | executable | indexed executable | Discovered from the local executable index. |
gpg-wks-server | executable | indexed executable | Discovered from the local executable index. |
gpgconf | executable | indexed executable | Discovered from the local executable index. |
gpgparsemail | executable | indexed executable | Discovered from the local executable index. |
gpgscm | executable | indexed executable | Discovered from the local executable index. |
gpgsm | executable | indexed executable | Discovered from the local executable index. |
gpgsplit | executable | indexed executable | Discovered from the local executable index. |
gpgtar | executable | indexed executable | Discovered from the local executable index. |
gpgv | executable | indexed executable | Discovered from the local executable index. |
kbxutil | executable | indexed executable | Discovered from the local executable index. |
watchgnupg | executable | indexed executable | Discovered from the local executable index. |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | brew:gnupg |
|---|---|
| Version | 2.5.21 |
| Package manager | Homebrew |
| Homepage | https://gnupg.org/ |
| Last updated | 2026-07-31T08:47:02+01:00 |
| Pulse | updated |
| Bottle | not recorded |
| Service | none declared |
source trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.