pkg.sopackage field notes

brew / rank 56

Install gnupg with Homebrew

GNU Privacy Guard (OpenPGP). Version 2.5.21 via Homebrew; verified 2026-07-31.

install

Additional install commands

macOS

Homebrewverified ยท 100%
brew install gnupg

provider-native install command

overview

Package summary

GNU Privacy Guard (OpenPGP)

Commands and aliases

  • addgnupghome
  • applygnupgdefaults
  • dirmngr
  • dirmngr-client
  • gpg
  • gpg-agent
  • gpg-authcode-sign.sh
  • gpg-card
  • gpg-connect-agent
  • gpg-mail-tube
  • gpg-wks-client
  • gpg-wks-server
  • gpgconf
  • gpgparsemail
  • gpgscm
  • gpgsm
  • gpgsplit
  • gpgtar
  • gpgv
  • kbxutil
  • watchgnupg

history

Project history and usage

GnuPG, also known as GPG, is the GNU Privacy Guard: a free implementation of the OpenPGP standard used for encryption, signatures and key management.

Project history

GnuPG was introduced in 1997 as Free Software and became the GNU project's OpenPGP implementation. The project describes it as a complete and free implementation of OpenPGP, with command-line integration, key-management facilities and access modules for public-key directories.

The release-line history shows the 1.0 branch born in 1999, the 1.4 branch in 2004, the 2.0 branch in 2006 and later 2.x branches adding the more modular architecture around gpg-agent, dirmngr, gpgsm, smart-card support and supporting libraries.

Adoption history

GnuPG became a standard security tool in Unix-like systems and software-distribution workflows. The project download page notes that common Linux distributions such as Debian, Fedora, Red Hat and Ubuntu include GnuPG, while Gpg4win provides an integrated Windows distribution with a context menu tool, crypto manager and Outlook plugin.

Its ecosystem includes libraries and frontends as well as helper packages such as pinentry, GPGME, GPA and Scute. That surrounding stack made GnuPG a platform for applications needing OpenPGP operations rather than only an interactive command.

How it is used

Practitioners use GnuPG to encrypt and decrypt files or messages, create and verify signatures, manage public and private keys, fetch or publish keys through directory mechanisms, operate smart cards and verify downloaded source releases. Its command-line interface also makes it common in scripts, build systems and release automation.

Why package nerds care

For package users, GnuPG is foundational plumbing: it links archive signatures, maintainer keys, trust databases, agents, pinentry programs, smart-card daemons and language bindings. Installing it often means installing the small operational security stack around OpenPGP, not just the gpg binary.

Timeline

  • 1997: GnuPG was introduced as Free Software.
  • 1999: The 1.0 release branch was born.
  • 2004: The 1.4 release branch was born.
  • 2006: The 2.0 release branch was born.
  • 2014: The 2.2 release branch was born.
  • 2021: The 2.4 release branch was born.

Related projects

  • GnuPG implements OpenPGP and is related to PGP by protocol lineage. Its project ecosystem includes GPGME, pinentry, dirmngr, gpg-agent, gpgsm, Scute, GPA and Gpg4win.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for gnupg. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.gnupg/gpg.conf~/.gnupg/gpg-agent.conf~/.gnupg/dirmngr.conf~/.gnupg/common.conf

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
~/.gnupg/private-keys-v1.d/~/.gnupg/secring.gpg~/.gnupg/trustdb.gpg

executables

Installed executables

CommandKindExposureNote
addgnupghomeexecutableindexed executableDiscovered from the local executable index.
applygnupgdefaultsexecutableindexed executableDiscovered from the local executable index.
dirmngrexecutableindexed executableDiscovered from the local executable index.
dirmngr-clientexecutableindexed executableDiscovered from the local executable index.
gpgexecutableindexed executableDiscovered from the local executable index.
gpg-agentexecutableindexed executableDiscovered from the local executable index.
gpg-authcode-sign.shexecutableindexed executableDiscovered from the local executable index.
gpg-cardexecutableindexed executableDiscovered from the local executable index.
gpg-connect-agentexecutableindexed executableDiscovered from the local executable index.
gpg-mail-tubeexecutableindexed executableDiscovered from the local executable index.
gpg-wks-clientexecutableindexed executableDiscovered from the local executable index.
gpg-wks-serverexecutableindexed executableDiscovered from the local executable index.
gpgconfexecutableindexed executableDiscovered from the local executable index.
gpgparsemailexecutableindexed executableDiscovered from the local executable index.
gpgscmexecutableindexed executableDiscovered from the local executable index.
gpgsmexecutableindexed executableDiscovered from the local executable index.
gpgsplitexecutableindexed executableDiscovered from the local executable index.
gpgtarexecutableindexed executableDiscovered from the local executable index.
gpgvexecutableindexed executableDiscovered from the local executable index.
kbxutilexecutableindexed executableDiscovered from the local executable index.
watchgnupgexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version2.5.21
manager updated2026-07-31
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:gnupg
Version2.5.21
Package managerHomebrew
Homepagehttps://gnupg.org/
Last updated2026-07-31T08:47:02+01:00
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation