Homebrew 6.0 introduces tap trust, requiring explicit agreement before third-party taps run code, and adds Linux sandboxing via Bubblewrap. The update also includes a brew vulns sub-command to check installed packages for known vulnerabilities. Project lead Mike McQuaid stated Homebrew was less vulnerable 10-15 years ago than npm is today.
Tap to vote and see what everyone thinks.
Summary by ByteBrief