pkg.soopen package index

brew / rank 7710

Install parlay with Homebrew, Nix, scoop

Enrich SBOMs with data from third party services. Version 0.11.0 via Homebrew; verified 2026-09-11. Also installable with nix: nix profile install nixpkgs#parlay.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install parlay

local Homebrew formula metadata

Linux

Nixverified · 92%
nix profile install nixpkgs#parlay

nixpkgs package indexes · pkgs/by-name/pa/parlay/package.nix · source: api.github.com

Windows

Scoopverified · 92%
scoop install main/parlay

Scoop official bucket manifest trees · bucket/parlay.json · source: api.github.com

overview

Package summary

Enrich SBOMs with data from third party services

Commands and aliases

  • parlay

history

Project history and usage

Parlay is Snyk's command-line tool for enriching software bills of materials with package metadata, licenses, vulnerability information, and security-score references.

Project history

Snyk developed Parlay as an open-source utility for supplementing sparse CycloneDX and SPDX SBOM component records with third-party package and security metadata.

The supported enrichment sources documented by the project include ecosyste.ms, Snyk vulnerability data, and OpenSSF Scorecard references.

Adoption history

source_facts.package-manager records distribution through Homebrew, Nix, and Scoop. The official releases also provide cross-platform binaries and Linux packages.

How it is used

Users pass CycloneDX JSON/XML or SPDX 2.3 JSON to provider-specific enrichment commands and receive an augmented SBOM.

Parlay supports standard input and output, allowing multiple enrichers and downstream SBOM tools to be chained in shell pipelines.

Snyk-backed commands require a token supplied through the SNYK_TOKEN environment variable; the official documentation does not prescribe a credentials file.

Why package nerds care

Parlay belongs to the newer package-tooling layer that treats SBOMs as inputs to a pipeline rather than finished artifacts. Its support for piping enriched output into other scanners is especially aligned with composable command-line supply-chain workflows.

Timeline

  • 2026-02-10: Version 0.11.0 was published in the official GitHub releases.

Related projects

  • The README demonstrates interoperability with Syft, cdxgen, Bomber, CycloneDX, SPDX, ecosyste.ms, Snyk, and OpenSSF Scorecard.

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Build metadata lists 1 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
parlaycliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-09-19
manager version0.11.0
manager updated2026-09-11
local dataok
upstreamcurrent
latest detectedv0.11.0

https://github.com/snyk/parlay

  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:parlay
Version0.11.0
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/parlay
Homepagehttps://github.com/snyk/parlay
Repositoryhttps://github.com/snyk/parlay
LicenseApache-2.0
Source archivehttps://github.com/snyk/parlay/archive/refs/tags/v0.11.0.tar.gz
Last updated2026-09-11T18:27:49Z
Pulseupdated
Build dependenciesgo
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameparlay
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

parlay

nix profile install nixpkgs#parlay
  • normalized package name match
  • Matched by: Parlay
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/pa/parlay/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Scoop95%

main/parlay

scoop install main/parlay
  • normalized package name match
  • Matched by: Parlay
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/parlay.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation