Skip to content
HN On Hacker News ↗

7.0.0

▲ 637 points • 253 comments • by mikemcquaid • 4w ago • HN discussion ↗

Pangram verdict · v3.3

We believe that this text is a mix of AI, AI-assisted, and human-written content.

61 %

AI likelihood · overall

Mixed
29% human-written 70% AI-generated
SEGMENTS · HUMAN 2 of 7
SEGMENTS · AI 1 of 7
WORD COUNT 1,158
PEAK AI % 90% · §2
Analyzed
Sep 13
backend: pangram/v3.3
Segments scanned
7 windows
avg 165 words each
Distribution
29 / 70%
human / AI fraction
Verdict
Mixed
Pangram v3.3

Article text · 1,158 words · 7 segments analyzed

Human AI-generated
§1 Human · 23%

Today, I’m proud to announce Homebrew 7.0.0. The most significant changes since 6.0.0 are faster installations and upgrades, stronger sandboxing, a native macOS app, built-in vulnerability checks and an advisory database, the end of macOS 10.15 support and Intel Macs moving to Tier 3. Contents ⬆ Upgrading 🍺 All Homebrew users 🏎 Performance 🔒 Security Security advisories Installation and tap protection 🔎 Commands and configuration 🗃 Casks 🍎 macOS users 🖥 Homebrew app 🐧 Linux users 🍾 Non-default prefix users 🔍 Security teams and auditors 🐳 Homebrew users in CI 🛠 Tap maintainers 🪜 Install steps 🙏 Finally ⬆ Upgrading An auto-update or manual brew update (if you have $HOMEBREW_NO_AUTO_UPDATE set) will upgrade Homebrew for you. Now means 7.0.0. Deprecated interfaces warn until disablement; disabled interfaces reject use and removed interfaces are unavailable.

§2 AI · 90%

Environment 7.0.0 behaviour and action Timing PR links macOS 10.15 or earlier Upgrade to macOS 11 or later Now Minimum version macOS Sonoma 14 Tier 3; upgrade to Sequoia 15+ for bottles and .pkg installations Now Support window macOS Golden Gate 27 on Apple Silicon Fully supported (Tier 1), with prebuilt bottles Now Full support ghcr.io/homebrew/ubuntu22.04 Image removed; migrate to ghcr.io/homebrew/brew Now Notice, removal Homebrew/actions/*@master or @main master removed; pin a CalVer release or full SHA Now Branch migration, releases Setuid wrappers with different real and effective UIDs Rejected; run as the installation’s owner without a wrapper Now Execution model Third-party brew wrappers Tier 3; internal commands bypass wrappers; seek support from the wrapper project Now Wrapper changes Homebrew/brew master Frozen bootstrap; switch to main before removal 2027-03-01 Bootstrap Intel macOS 11 or later Tier 3; no new bottles; migrate to MacPorts before Homebrew stops running 2027-09-01 Support, bottles Apple Silicon macOS 11 Upgrade to macOS 12 or later before support ends 2027-09-01 Support schedule Third-party formula post_install and cask flight blocks Deprecated; migrate to *_steps; brew style --fix converts common hooks 2027-12-11 Deprecation, migration 🍺 All Homebrew users The following improvements apply across platforms unless stated otherwise. 🏎 Performance Greater concurrency across downloads, preparation and installation maximises performance while coordinating failures and summaries. brew install, brew reinstall and brew upgrade overlap package preparation and downloads, including brew bundle batches, reducing waits between packages and allowing a Brewfile to benefit from the same shared installation work as a command naming several packages. brew config gathers independent system details concurrently, so compiler, operating-system and repository checks overlap instead of making diagnostic reports wait for every subprocess in turn. brew tap-info --installed --json=v1 collects tap metadata concurrently, shortening inventory requests when several repositories need Git or network checks while preserving the output order expected by scripts. brew cleanup avoids repeated cache scans, speeding up cleanup for installations with many packages. brew fetch reads download information directly from API metadata for bottles and casks, starting downloads without loading complete package definitions merely to discover URLs and checksums. brew update prepares Ruby caches so subsequent commands start faster. Homebrew reuses parsed API data on warm runs while verifying signatures on every load, reducing preparation time for repeated package commands without dropping authenticity checks. Homebrew launches fewer subprocesses during startup, reducing command overhead, and reads terminal dimensions directly, avoiding hangs with uutils stty.

§3 Human · 24%

🔒 Security Homebrew 7.0.0 includes various security fixes and new installation protections. Security advisories The first fixed releases are listed below. GHSA-rg9r-ppxp-87hm, High, fixed in 6.0.12: unsigned cask-removal metadata could execute commands with sudo; all vulnerable recovery code and API accessors have been deleted. GHSA-5263-whxq-77hp, Moderate, fixed in 7.0.0: a malicious cask could execute code outside the macOS install sandbox through LaunchServices; Homebrew restricts application launching, Mach services and Unix socket connections. GHSA-hqpg-hjr9-c7j8, Moderate, fixed in 6.0.12: the macOS installer ignores prefix-owned Git configuration that could execute programs as root. GHSA-x82f-cj53-gqfr, Low, fixed in 6.0.7: brew livecheck restricts redirects to prevent server-side request forgery. GHSA-3m5g-jfx7-3p65, Low, fixed in 6.0.7: download redirects cannot forward secret headers to other hosts. GHSA-r9gp-p4vv-f93x, Low, fixed in 6.0.6: Git redirects cannot bypass tap restrictions. GHSA-9g4r-vmj2-j2gj, Low, fixed in 6.0.7: Subversion external URLs cannot become command options. GHSA-r7qx-325v-4ccx, Low, fixed in 6.0.6: patch targets cannot escape the staged source tree.

§4 Mixed · 67%

Installation and tap protection Tap trust remains the primary protection against malicious third-party casks; sandboxing mainly limits accidental damage and adds installation safeguards. It cannot make untrusted software safe to run: applications execute with the user’s privileges, and vendor .pkg installers run outside the sandbox and may require sudo. We balance tighter restrictions with keeping existing software working. Homebrew delivers structured setup as signed data and sandboxes formula and cask operations, reducing arbitrary Ruby execution and repeated package loading. Homebrew begins migrating dependency downloads into a fetch phase: migrated formulae download with network access and writable caches, then install disables networking and makes those caches read-only; migration remains ongoing. Homebrew blocks sandboxed reads of the home directory by default, keeping unrelated personal files outside package builds while allowing required Homebrew paths; private temporary directories let build tools communicate locally without enabling network access. Homebrew rejects mismatched real and effective user IDs before reading configuration, removing untested privilege-switching code for unsupported shared installations. Trust and environment migrations and replacements. 🔎 Commands and configuration Commands provide clearer previews, package information and service configuration. brew install --dry-run previews formulae and casks together. brew list --no-installed-on-request identifies formulae installed as dependencies. brew info distinguishes uninstallable packages with ⊘ from uninstalled packages with ✘ and marks unmet operating-system and architecture requirements, making it easier to understand whether a package can run on the current machine before starting an installation.

§5 Mixed · 37%

brew services reads persistent overrides from $HOMEBREW_USER_CONFIG_HOME/services/<formula>.env, allowing local service settings to survive package upgrades and take effect on restart without editing generated service files. New and restarted services use sh.brew.<formula> on macOS and Linux, recognising legacy registrations until restart. brew bundle restores language tools from declared sources: Cargo Git repositories or paths and source: for remote uv tools.

§6 Mixed · 61%

brew doctor --json provides structured diagnostics for automation; brew doctor also warns when another brew shadows the current installation in PATH, helping diagnose wrapper and installation conflicts. brew deps --brewfile inspects a Brewfile’s dependencies, making it easier to review the packages a development environment will bring in before installing that environment. brew untap offers to uninstall a tap’s packages first, allowing an unwanted package source and its installed software to be removed together. HOMEBREW_AUTO_UPDATE_QUIET suppresses automatic-update package details, keeping routine command output focused while still allowing Homebrew to update in the background of normal use. Homebrew stops exporting its own BUNDLER_VERSION to child processes, allowing formula builds to use their required Bundler version. Brewfiles record language-tool sources alongside other packages, reducing separate installation instructions when reproducing an environment on another machine.

§7 Mixed · 44%

Command and configuration migrations and replacements. 🗃 Casks Formula links take precedence when formulae and casks provide the same commands, with warnings explaining how to restore the cask links. brew upgrade skips incompatible casks while upgrading compatible applications; both it and brew outdated honour HOMEBREW_NO_UPGRADE_AUTO_UPDATES_CASKS, preserving self-updating applications’ opt-out.