Nala

ID

nala

Links

Documentation · Repository

Upstream stars

⭐ 921

Last commit

2026-09-19

Version requirement

>= 0.12.2

Platforms

🐧 Linux

Operations

installed · outdated · search · install · upgrade · upgrade_all · remove · sync · cleanup

purl types

pkg:deb/ · pkg:nala/

CLI name

nala

Forced environment

LC_ALL=C

Issues and PRs

📦 manager: dpkg-based

Source

nala.py

Front-end to Debian’s apt, driving libapt-pkg directly.

Nala reaches the same archives apt does, adding a parallel downloader, a mirror-scoring fetcher and a transaction history it can roll back. It is wrapped on the same grounds as the AUR helpers that sit over pacman: a distinct tool with a vocabulary of its own, rather than a translation layer over another CLI. It shares dpkg’s lock with the rest of that family, so mpm runs it serially against them.

What mpm adds to nala

Through mpm, nala gains --exact and --extended search, to narrow to exact names or match descriptions.

Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover nala alongside apt, apt-mint, aptitude and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.

Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.

Your nala commands, in mpm

You already know nala: each operation maps one-to-one onto mpm, in an interface shared by every manager.

To…

With nala

With mpm

List what’s installed

nala list --installed

mpm --nala installed

List outdated packages

nala list --upgradable

mpm --nala outdated

Search for a package

nala search vim

mpm --nala search vim

Install a package

sudo nala install --assume-yes firefox

mpm install pkg:nala/firefox

Upgrade one package

sudo nala install --assume-yes firefox

mpm --nala upgrade firefox

Upgrade everything

sudo nala upgrade --assume-yes

mpm --nala upgrade --all

Remove a package

sudo nala remove --assume-yes firefox

mpm remove pkg:nala/firefox

Clear caches

sudo nala clean

mpm --nala cleanup --cache

Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.

Operations

Operation

Supported

Notes

installed

✅

outdated

✅

orphans

search

✅

Exact and extended search backfilled by mpm.

install

✅

A package already installed as a dependency is marked explicit by mpm.

upgrade

✅

The tool’s upgrade takes no package argument, so a single upgrade runs through install, which moves an installed package to its candidate.

upgrade_all

✅

remove

✅

sync

✅

cleanup

✅

The --orphans flag runs the system-wide orphan sweep.

doctor

Configuration

  • Ignore nala on the mpm CLI by passing the --no-nala option.

  • Ignore it for every run in your configuration:

    [mpm]
    nala = false
    
  • Raise the timeout of all nala calls:

    [mpm.overrides.nala]
    timeout = 900
    
  • Run mpm config-template nala to print all overridable settings for your configuration file:

    [mpm.overrides.nala]
    cli_names = [
        "nala",
    ]
    cli_search_path = []
    dry_run = false
    ignore_auto_updates = true
    plan = false
    post_args = []
    pre_args = []
    pre_cmds = []
    requirement = ">=0.12.2"
    stop_on_error = false
    unmaintained = false
    version_cli_options = [
        "--version",
    ]
    version_regexes = [
        "nala\\s+(?P<version>\\S+)",
    ]
    
    [mpm.overrides.nala.extra_env]
    LC_ALL = "C"
    

The arguments and environment variables listed in the box atop this page are forced on every nala call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.

Recipes

A few jobs you would otherwise script around nala, one mpm command each:

  • Snapshot and clone a machine: mpm --nala dump nala.toml, then mpm restore nala.toml on the next one.

  • Export a compliance SBOM: mpm --nala sbom (CycloneDX by default, --spdx for SPDX).

Privilege escalation

System-wide manager: mpm wraps its privileged operations in sudo out of the box. Instead of letting the tool prompt mid-run, mpm primes the credential cache up-front, with a single branded password prompt at most. Turn escalation off for rootless setups with --no-sudo or the per-manager sudo override.

Its privileged operations are cleanup, install, remove, sync, upgrade, upgrade_all.

See privilege escalation for the full policy.

Concurrency

mpm never runs nala at the same time as apt, apt-mint, aptitude, deb-get or pacstall: they all install through dpkg and serialize on its /var/lib/dpkg/lock. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.

Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.

Cooldown

State of Nala’s release-age gating, from the cooldown support table:

Status: ❌ None

A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:

  • Registry: Distro binary archives (pkg:deb, pkg:rpm, pkg:alpm, pkg:apk)

  • Retraction: Index revert: removal is an archive operation and the mirror is rebuilt without the package. Debian, for one, requires filing an RM: bug against ftp.debian.org (developers-reference)

  • Publish date: ❌ the version string is the distro maintainer’s build, carrying no upstream publication date

With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.

Version check

The version is probed by running:

$ nala --version
nala 0.16.0

and extracted with:

r"nala\s+(?P<version>\S+)"

Upstream project

Metrics

volian/nala

Activity

open issues open merge requests

Popularity

forks contributors

Metadata

latest tag license

Changelog

  • 8.0.0 (2026-09-20)

    • Mark a package already installed as a dependency as explicitly installed when mpm install or mpm restore names it, so mpm cleanup --orphans keeps it.

    • Resolve pkg:alpm, pkg:conda, pkg:deb, pkg:melpa, pkg:pypi and pkg:rpm pURLs to these managers too, alongside the ones already handling each type.

    • Declare support for the Linux compatibility layers, WSL included, in place of the Linux distributions alone, so the readme’s operation matrix reports their platforms.

    • Add the Nala front-end to Debian’s apt with installed, outdated, search, install, upgrade, remove, sync and cleanup support, every call forced LC_ALL=C. It joins the dpkg lock family.

    • Sample the upstream project from GitLab, so the manager page gains the upstream stars and commit facts, and its live badges.