pkg.soopen package index

brew / rank 1182

Install wireguard-go with Homebrew, apk, apt, MacPorts, Nix

Userspace Go implementation of WireGuard. Version 0.0.20250522 via Homebrew; verified 2026-07-25. Also installable with debian: sudo apt install golang-golang.zx2c4-wireguard-dev.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install wireguard-go

local Homebrew formula metadata

MacPortsverified · 94%
sudo port install wireguard-go

MacPorts ports tree · net/wireguard-go/Portfile · source: api.github.com

Linux

Alpine Linux apkverified · 92%
sudo apk add wireguard-go

Alpine Linux edge package indexes · wireguard-go · source: dl-cdn.alpinelinux.org

Debian aptverified · 92%
sudo apt install wireguard-go

Debian stable package indexes · wireguard-go · source: deb.debian.org

Nixverified · 92%
nix profile install nixpkgs#wireguard-go

nixpkgs package indexes · pkgs/by-name/wi/wireguard-go/package.nix · source: api.github.com

overview

Package summary

Userspace Go implementation of WireGuard

Commands and aliases

  • wireguard-go

history

Project history and usage

wireguard-go is the official Go userspace implementation of WireGuard, the modern encrypted layer-3 VPN protocol created by Jason A. Donenfeld. It exists alongside the Linux kernel implementation and is most useful where a kernel driver is unavailable, undesirable, or less portable than a userspace tunnel process.

Project history

WireGuard itself was designed as a small, auditable alternative to IPsec and OpenVPN, with a public technical paper describing it as a secure network tunnel implemented as a Linux kernel virtual network interface. The WireGuard project later organized several official implementation repositories, including the kernel implementation, cross-platform tools, and wireguard-go as a cross-platform userspace implementation maintained by Donenfeld.

The role of wireguard-go became clearer after WireGuard entered the Linux kernel line: Linux users are generally expected to use the kernel module for performance and integration, while wireguard-go remains the portable fallback for platforms and situations where a userspace TUN implementation is the practical route. Its README explicitly tells Linux users that the kernel module is faster and better integrated, which gives the package a deliberately narrow but important niche.

Adoption history

WireGuard's wider adoption accelerated when it was merged for Linux 5.6 in 2020, turning the protocol from an out-of-tree module plus tools into a standard Linux networking feature. That made userspace implementations less central on modern Linux but more valuable as cross-platform compatibility pieces for macOS, BSD-derived systems, containers, embedded environments, and application stacks that need a WireGuard tunnel without depending on a kernel module.

In package-manager culture, wireguard-go is commonly installed with wireguard-tools or used by higher-level products that need an implementation of the WireGuard protocol in userspace. It is not the glamorous default path on current Linux, but it is the package that makes the same protocol available when the native interface is missing.

How it is used

A typical invocation creates a WireGuard-style network interface by running a command such as `wireguard-go wg0`; the interface can then be configured with `wg(8)` plus ordinary platform networking tools. The upstream README describes it as creating the interface and then forking into the background, with a foreground mode available for supervision and logging.

The package is usually part of a larger WireGuard setup rather than a complete VPN product by itself. Users still need keys, peers, allowed IPs, routing, and address configuration, usually handled through `wg`, `wg-quick`, system network managers, or application-specific wrappers.

Why package nerds care

For package maintainers, wireguard-go is the portability valve in the WireGuard ecosystem: small, official, and intentionally less preferred than the kernel implementation on Linux, but essential when kernels, operating systems, or sandboxed deployments cannot provide a native WireGuard device.

Its significance is mostly negative space: if the platform has first-class WireGuard support, users may never notice it; when it does not, this package is often the thing that lets the rest of the WireGuard tooling keep working.

Timeline

  • 2017: Donenfeld's WireGuard technical paper describes the design goals of a small, production-oriented secure network tunnel.
  • 2019: The WireGuard project lists wireguard-go as the official cross-platform userspace implementation in Go.
  • 2020: WireGuard is included in Linux 5.6, shifting mainstream Linux use toward the kernel driver while preserving wireguard-go for portability.
  • 2026: The WireGuard repositories page still lists wireguard-go as a complete official implementation.

Related projects

  • wireguard-tools provides `wg` and `wg-quick`, the common command-line tools used to configure interfaces created by either the kernel implementation or wireguard-go.
  • wireguard-linux and wireguard-linux-compat cover the kernel side of the same protocol, while other official repositories cover Android, BSD, Rust, and experimental implementations.

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
wireguard-goexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version0.0.20250522
manager updated2026-07-25
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:wireguard-go
Version0.0.20250522
Package managerHomebrew
Homepagehttps://www.wireguard.com/
Last updated2026-07-25T22:40:21+02:00
Pulseupdated
Bottlenot recorded
Servicenone declared

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Debian apt95%

golang-golang.zx2c4-wireguard-dev 0.0.20231211-1

Userspace implementation of WireGuard in Go (library)

https://git.zx2c4.com/wireguard-go/about/

sudo apt install golang-golang.zx2c4-wireguard-dev
  • Section: golang
  • Architecture: all
  • Source Package: wireguard-go
  • 6 dependencies
  • normalized package name match
  • Matched by: Wireguard Go
Debian stable package indexes · deb.debian.org · Debian stable package indexes: golang-golang.zx2c4-wireguard-dev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Debian apt95%

wireguard-go 0.0.20231211-1+b9

Userspace implementation of WireGuard in Go (program)

https://git.zx2c4.com/wireguard-go/about/

sudo apt install wireguard-go
  • Section: golang
  • Architecture: amd64
  • Source Package: wireguard-go
  • 1 dependencies
  • normalized package name match
  • Matched by: Wireguard Go
Debian stable package indexes · deb.debian.org · Debian stable package indexes: wireguard-go from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Nix95%

wireguard-go

nix profile install nixpkgs#wireguard-go
  • normalized package name match
  • Matched by: Wireguard Go
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/wi/wireguard-go/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Ubuntu apt95%

golang-golang.zx2c4-wireguard-dev 0.0.20230223-1

Userspace implementation of WireGuard in Go (library)

https://git.zx2c4.com/wireguard-go/about/

sudo apt install golang-golang.zx2c4-wireguard-dev
  • Section: universe/golang
  • Architecture: all
  • Source Package: wireguard-go
  • 3 dependencies
  • normalized package name match
  • Matched by: Wireguard Go
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: golang-golang.zx2c4-wireguard-dev from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
Ubuntu apt95%

wireguard-go 0.0.20230223-1

Userspace implementation of WireGuard in Go (program)

https://git.zx2c4.com/wireguard-go/about/

sudo apt install wireguard-go
  • Section: universe/golang
  • Architecture: amd64
  • 1 dependencies
  • normalized package name match
  • Matched by: Wireguard Go
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: wireguard-go from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
apk95%

wireguard-go 0.0.20250522-r10

Next generation secure network tunnel: userspace implementation in go

https://www.wireguard.com

sudo apk add wireguard-go
  • License: GPL-2.0-only
  • Architecture: x86_64
  • Source Package: wireguard-go
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Wireguard Go
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: wireguard-go from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
apk95%

wireguard-go-doc 0.0.20250522-r10

Next generation secure network tunnel: userspace implementation in go (documentation)

https://www.wireguard.com

sudo apk add wireguard-go-doc
  • License: GPL-2.0-only
  • Architecture: x86_64
  • Source Package: wireguard-go
  • normalized package name match
  • Matched by: Wireguard Go
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: wireguard-go-doc from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
MacPorts95%

wireguard-go

sudo port install wireguard-go
  • normalized package name match
  • Matched by: Wireguard Go
MacPorts ports tree · api.github.com · MacPorts ports tree: net/wireguard-go/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation