Homebrew 7.0 debuts BrewUI, Landlock sandboxing
Homebrew 7.0.0 introduces concurrent installation workflows, kernel-native Landlock sandboxing on Linux, and the new BrewUI graphical interface for macOS. The update also adds built-in vulnerability auditing powered by OSV.dev, drops macOS Catalina support, and demotes Intel Macs to Tier 3 ahead of sunset in 2027.
Homebrew is aggressively trimming technical debt and phasing out legacy platforms to build a faster, sandboxed, and more secure package management ecosystem.
- –Demoting Intel x86_64 Macs to Tier 3 and setting an end-of-life date for September 2027 reflects the reality of open-source volunteer maintenance following Apple and GitHub's departure from Intel CI runners.
- –Switching to Landlock for Linux sandboxing eliminates cumbersome Bubblewrap and Docker permission friction, offering seamless unprivileged containment.
- –Deprecating arbitrary Ruby execution in `post_install` and cask flight hooks in favor of declarative `*_steps` significantly hardens the supply chain against malicious taps and simplifies sandboxing.
- –BrewUI bridges the gap for non-technical users while reinforcing terminal fluency by surfacing the underlying CLI commands for every UI action.
- –Direct integration of OSV.dev vulnerability auditing (`brew vulns`) bakes package-level security triage into standard developer environments without external taps.
DISCOVERED
1h ago
2026-09-13
PUBLISHED
5h ago
2026-09-13
RELEVANCE
AUTHOR
mikemcquaid
