Back
Homebrew 6.0.0 arrives with mandatory tap trust and Linux sandboxing
SiTech AI Team3 წთ. საკითხავი

Homebrew 6.0.0 arrives with mandatory tap trust and Linux sandboxing

Homebrew 6.0.0 requires third-party taps to be explicitly trusted before their Ruby code runs, makes the compact internal JSON API the default, sandboxes Linux builds and ships three security fixes.

Homebrew 6.0.0 was released on 11 June 2026, and its headline is security: third-party taps must now be explicitly trusted before any of their Ruby code is evaluated or run. The first major release since 5.1.0 also makes the compact internal JSON API the default, brings sandboxing to Linux, and switches everyday commands to a confirmation-first "ask" mode.

Tap trust becomes mandatory

The announcement is blunt about the risk: a third-party tap can contain arbitrary, unsandboxed Ruby that runs on the machine installing it. Homebrew now requires taps — and tap-qualified formulae and casks — to be trusted before their code runs, while the official taps stay trusted by default. Untrusted taps are flagged before execution, auto-tapping them is disabled, and allow, forbid and trust lists are pinned to remotes. brew tap gains trust-management commands, brew trust accepts --json=v1, brew tap-info reports a trusted field, and brew bundle honours a trusted: option.

Faster updates, Linux sandbox, ask by default

The internal JSON API, which bundles all Homebrew metadata into a single download so that brew updates faster and uses the network less, is now the default; HOMEBREW_USE_INTERNAL_API, the opt-in since 5.0.0, is deprecated. On Linux, build, test and postinstall phases now run inside a Bubblewrap sandbox, matching macOS. After the project's user survey, ask mode became the default for developers, so brew install and brew upgrade print a dependency summary and wait for confirmation.

Intel Macs are on the way out

Version 6.0.0 adds initial support for macOS 27 (Golden Gate), which drops Intel support — so the support tiers shift: in September 2026, macOS Intel x86_64 moves to Tier 3, with no CI support and no new bottles; in September 2027 it becomes unsupported entirely and related code is deleted. On Linux, the Ubuntu 24.04 CI migration raised the baseline to glibc 2.39, moving systems with older glibc, such as Ubuntu 22.04, to Tier 2. The brew-rs experiment in moving parts of the Ruby frontend to Rust has concluded: benchmarks showed an advantage only on narrow, already-cached bottle fetches, so performance work returns to Ruby.

Security fixes and supply-chain work

Three advisories accompanied the release: a POST download strategy flaw that bypassed HTTPS-to-HTTP redirect protection, root code execution via Git hooks in the macOS .pkg postinstall, and an installer that trusted a user-controlled /var/tmp plist. All are fixed. Homebrew now filters sensitive environment variables during Ruby evaluation, can require cask checksums via HOMEBREW_CASK_OPTS_REQUIRE_SHA, and added download cooldowns for Bundler, RubyGems, npm and PyPI sources. New commands include brew exec, in the spirit of npx, and brew vulns, which checks installed packages against known vulnerabilities.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.