Nala¶
- ID
nala- Links
- Upstream stars
⭐ 921
- Last commit
2026-09-19
- Version requirement
>= 0.12.2
- Platforms
🐧 Linux
- Operations
installed·outdated·search·install·upgrade·upgrade_all·remove·sync·cleanup- purl types
pkg:deb/·pkg:nala/- CLI name
nala- Forced environment
LC_ALL=C- Issues and PRs
- Source
Front-end to Debian’s apt, driving libapt-pkg directly.
Nala reaches the same archives apt does, adding a parallel downloader, a
mirror-scoring fetcher and a transaction history it can roll back. It is
wrapped on the same grounds as the AUR helpers that sit over pacman: a
distinct tool with a vocabulary of its own, rather than a translation layer
over another CLI. It shares dpkg’s lock with the rest of that family, so
mpm runs it serially against them.
What mpm adds to nala¶
Through mpm, nala gains --exact and --extended search, to narrow to exact names or match descriptions.
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover nala alongside apt, apt-mint, aptitude and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your nala commands, in mpm¶
You already know nala: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Search for a package |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
|
|
Remove a package |
|
|
Clear caches |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✅ |
|
|
✅ |
|
|
||
|
✅ |
Exact and extended search backfilled by |
|
✅ |
A package already installed as a dependency is marked explicit by |
|
✅ |
The tool’s |
|
✅ |
|
|
✅ |
|
|
✅ |
|
|
✅ |
The |
|
Configuration¶
Ignore
nalaon thempmCLI by passing the--no-nalaoption.Ignore it for every run in your configuration:
[mpm] nala = false
Raise the timeout of all
nalacalls:[mpm.overrides.nala] timeout = 900
Run
mpm config-template nalato print all overridable settings for your configuration file:[mpm.overrides.nala] cli_names = [ "nala", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [] pre_cmds = [] requirement = ">=0.12.2" stop_on_error = false unmaintained = false version_cli_options = [ "--version", ] version_regexes = [ "nala\\s+(?P<version>\\S+)", ] [mpm.overrides.nala.extra_env] LC_ALL = "C"
The arguments and environment variables listed in the box atop this page are forced on every nala call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Recipes¶
A few jobs you would otherwise script around nala, one mpm command each:
Snapshot and clone a machine:
mpm --nala dump nala.toml, thenmpm restore nala.tomlon the next one.Export a compliance SBOM:
mpm --nala sbom(CycloneDX by default,--spdxfor SPDX).
Privilege escalation¶
System-wide manager: mpm wraps its privileged operations in sudo out of the box. Instead of letting the tool prompt mid-run, mpm primes the credential cache up-front, with a single branded password prompt at most. Turn escalation off for rootless setups with --no-sudo or the per-manager sudo override.
Its privileged operations are cleanup, install, remove, sync, upgrade, upgrade_all.
See privilege escalation for the full policy.
Concurrency¶
mpm never runs nala at the same time as apt, apt-mint, aptitude, deb-get or pacstall: they all install through dpkg and serialize on its /var/lib/dpkg/lock. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.
Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.
Cooldown¶
State of Nala’s release-age gating, from the cooldown support table:
Status: ❌ None
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: Distro binary archives (
pkg:deb,pkg:rpm,pkg:alpm,pkg:apk)Retraction: Index revert: removal is an archive operation and the mirror is rebuilt without the package. Debian, for one, requires filing an
RM:bug againstftp.debian.org(developers-reference)Publish date: ❌ the version string is the distro maintainer’s build, carrying no upstream publication date
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.
Version check¶
The version is probed by running:
$ nala --version
nala 0.16.0
and extracted with:
r"nala\s+(?P<version>\S+)"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0(2026-09-20)Mark a package already installed as a dependency as explicitly installed when
mpm installormpm restorenames it, sompm cleanup --orphanskeeps it.Resolve
pkg:alpm,pkg:conda,pkg:deb,pkg:melpa,pkg:pypiandpkg:rpmpURLs to these managers too, alongside the ones already handling each type.Declare support for the Linux compatibility layers, WSL included, in place of the Linux distributions alone, so the readme’s operation matrix reports their platforms.
Add the Nala front-end to Debian’s apt with
installed,outdated,search,install,upgrade,remove,syncandcleanupsupport, every call forcedLC_ALL=C. It joins the dpkg lock family.Sample the upstream project from GitLab, so the manager page gains the upstream stars and commit facts, and its live badges.