Conda

ID

conda

Links

Home page · Documentation · Repository · Wikipedia

Upstream stars

⭐ 7,519

Last commit

2026-09-28

Version requirement

>= 4.6

Platforms

🐧 Linux · 🍎 macOS · 🪟 Windows

Operations

installed · outdated · search · install · upgrade · upgrade_all · remove · cleanup

purl types

pkg:conda/

CLI name

conda

Issues and PRs

📦 manager: conda-based

Source

conda.py

Conda cross-language package and environment manager.

Reads go through conda’s --json mode: installed packages come from conda list --json and search from conda search "*query*" --json. The outdated inventory is simulated from a dry run of the solver, as the method’s own docstring documents.

Note

Every operation targets conda’s currently active environment, which is base when none is activated. mpm neither activates nor switches environments: it inspects and mutates whatever environment conda resolves from the inherited CONDA_PREFIX / CONDA_DEFAULT_ENV, exactly as a bare conda call in the same shell would. Per-environment targeting is not supported yet.

What mpm adds to conda

Through mpm, conda gains --exact and --extended search, to narrow to exact names or match descriptions.

Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover conda alongside mamba, micromamba, pixi and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.

Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.

Your conda commands, in mpm

You already know conda: each operation maps one-to-one onto mpm, in an interface shared by every manager.

To…

With conda

With mpm

List what’s installed

conda list --json

mpm --conda installed

List outdated packages

conda update --all --dry-run --json

mpm --conda outdated

Search for a package

conda search "*pytz*" --json

mpm --conda search <pkg>

Install a package

conda install --yes pytz

mpm install pkg:conda/pytz

Upgrade one package

conda update --yes pytz

mpm --conda upgrade pytz

Upgrade everything

conda update --all --yes

mpm --conda upgrade --all

Remove a package

conda remove --yes pytz

mpm remove pkg:conda/pytz

Clear caches

conda clean --all --yes

mpm --conda cleanup --cache

Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.

Operations

Operation

Supported

Notes

installed

✅

outdated

✅

orphans

search

✅

Exact and extended search backfilled by mpm.

install

✅

upgrade

✅

upgrade_all

✅

remove

✅

sync

cleanup

✅

doctor

Configuration

  • Ignore conda on the mpm CLI by passing the --no-conda option.

  • Ignore it for every run in your configuration:

    [mpm]
    conda = false
    
  • Raise the timeout of all conda calls:

    [mpm.overrides.conda]
    timeout = 900
    
  • Run mpm config-template conda to print all overridable settings for your configuration file:

    [mpm.overrides.conda]
    cli_names = [
        "conda",
    ]
    cli_search_path = []
    dry_run = false
    ignore_auto_updates = true
    plan = false
    post_args = []
    pre_args = []
    pre_cmds = []
    requirement = ">=4.6.0"
    stop_on_error = false
    unmaintained = false
    version_cli_options = [
        "--version",
    ]
    version_regexes = [
        "conda\\s+(?P<version>\\S+)",
    ]
    

Recipes

A few jobs you would otherwise script around conda, one mpm command each:

  • Snapshot and clone a machine: mpm --conda dump conda.toml, then mpm restore conda.toml on the next one.

  • Export a compliance SBOM: mpm --conda sbom (CycloneDX by default, --spdx for SPDX).

Privilege escalation

mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.

None of its operations is privileged.

See privilege escalation for the full policy.

Concurrency

mpm never runs conda at the same time as mamba or micromamba: they act on one environment prefix and one package cache, and conda honors none of the locks mamba takes on them. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.

Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.

Cooldown

State of Conda’s release-age gating, from the cooldown support table:

  • Status: 🚧 Proposed

  • Mechanism: --exclude-newer / exclude_newer (open issue + PR)

  • Reference: conda/conda#15759

A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:

  • Registry: anaconda.org / conda-forge (pkg:conda)

  • Retraction: Relabel: “we do not allow edits or the deletion of packages on conda-forge” (immutability); a bad artifact is labelled broken and “Users will no longer be able to install them by default” (procedure)

  • Publish date: ✅ upload_time, with the broken label carried in labels (API)

With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.

Reference traces

A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Conda well and a transcript below looks wrong, or a newer release changed its output format, report it.

$ conda list --json
[
  {
    "base_url": "https://repo.anaconda.com/pkgs/main",
    "build_number": 0,
    "build_string": "py312hca03da5_0",
    "channel": "pkgs/main",
    "dist_name": "pip-24.0-py312hca03da5_0",
    "name": "pip",
    "platform": "osx-arm64",
    "version": "24.0"
  },
  {
    "base_url": "https://repo.anaconda.com/pkgs/main",
    "build_number": 0,
    "build_string": "py312_0",
    "channel": "pkgs/main",
    "dist_name": "pytz-2024.1-py312_0",
    "name": "pytz",
    "platform": "osx-arm64",
    "version": "2024.1"
  }
]
$ conda update --all --dry-run --json
{
  "actions": {
    "FETCH": [],
    "LINK": [
      {
        "base_url": "https://repo.anaconda.com/pkgs/main",
        "build_number": 0,
        "build_string": "py312_0",
        "channel": "pkgs/main",
        "dist_name": "pytz-2024.2-py312_0",
        "name": "pytz",
        "platform": "osx-arm64",
        "version": "2024.2"
      }
    ],
    "UNLINK": [
      {
        "base_url": "https://repo.anaconda.com/pkgs/main",
        "build_number": 0,
        "build_string": "py312_0",
        "channel": "pkgs/main",
        "dist_name": "pytz-2024.1-py312_0",
        "name": "pytz",
        "platform": "osx-arm64",
        "version": "2024.1"
      }
    ],
    "PREFIX": "/opt/conda"
  },
  "dry_run": true,
  "prefix": "/opt/conda",
  "success": true
}
$ conda update --all --dry-run --json
{
  "message": "All requested packages already installed.",
  "success": true
}

Version check

The version is probed by running:

$ conda --version
conda 24.5.0

and extracted with:

r"conda\s+(?P<version>\S+)"

Upstream project

Metrics

conda/conda

Activity

commit activity commits since open issues open pull requests

Popularity

forks watchers contributors

Metadata

latest release release date license main language

Changelog

  • 8.0.0 (2026-09-20)

    • Resolve the pkg:conda, pkg:golang, pkg:haxe and pkg:nuget pURL types to these managers, which raised instead of routing.

    • Stop running conda, mamba and micromamba concurrently: they act on one environment prefix and one package cache.

  • 7.1.0 (2026-07-07)

    • Add Conda package manager with installed, outdated, search, install, upgrade, remove, and cleanup support, cross-platform on Linux, macOS, and Windows; requires conda >=4.6.0.