pixi

ID

pixi

Links

Home page · Documentation · Repository

Upstream stars

⭐ 7,799

Last commit

2026-09-29

Version requirement

>= 0.65

Platforms

🐧 Linux · 🍎 macOS · 🪟 Windows

Operations

installed · install · upgrade · upgrade_all · remove · cleanup

purl types

pkg:conda/ · pkg:pixi/

CLI name

pixi

Every call

pixi --color=never --no-progress <command>

Issues and PRs

📦 manager: conda-based

Source

pixi.py

pixi installs conda packages, either into a project workspace or machine-wide as global tools.

mpm is system-scoped, so this wrapper drives the pixi global scope alone and never touches a pixi.toml workspace. Global tools resolve from conda channels, conda-forge by default, and land in their own prefix under $PIXI_HOME.

Important

pixi isolates each global tool in its own environment, and mpm keys packages on the environment name, not on the conda package names inside it. The environment is the unit every mutating pixi global verb addresses: uninstall deletes one whole environment and update refreshes one whole environment, neither taking a package name. pixi global install <pkg> names the environment after the package, so for everything mpm installs the two are the same string and every operation round-trips.

Todo

Declare a logo once Simple Icons ships the pixi mark requested in simple-icons/simple-icons#13796, a request already cleared of trademark concerns (labelled permission not needed). Their pixiv mark is an unrelated brand, not a stand-in.

What mpm adds to pixi

mpm reaches across every manager at once, not pixi alone: mpm installed and mpm outdated cover pixi alongside conda, mamba, micromamba and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.

Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.

Your pixi commands, in mpm

You already know pixi: each operation maps one-to-one onto mpm, in an interface shared by every manager.

To…

With pixi

With mpm

List what’s installed

pixi global list --json

mpm --pixi installed

Install a package

pixi global install hyperfine

mpm install pkg:pixi/hyperfine

Upgrade one package

pixi global update hyperfine

mpm --pixi upgrade hyperfine

Upgrade everything

pixi global update

mpm --pixi upgrade --all

Remove a package

pixi global uninstall hyperfine

mpm remove pkg:pixi/hyperfine

Clear caches

pixi clean cache --yes

mpm --pixi cleanup --cache

Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.

Operations

Operation

Supported

Notes

installed

✅

An environment is reported as the single package it is named after, with no version once its contents diverge; its extra packages are invisible to mpm.

outdated

❌

Nothing reports upgradable packages without performing the upgrade (prefix-dev/pixi#6279, closed pointing at a workspace-scoped dry run); upgrade --all maps to the native pixi global update.

orphans

search

❌

The --json mode cannot be capped and queries every known conda subdir, so a search would stall on it.

install

✅

upgrade

✅

upgrade_all

✅

remove

✅

Removing a package deletes its whole environment, taking any extra packages installed beside it.

sync

❌

The pixi global sync command reconciles the manifest by installing and removing, so it mutates rather than refreshes.

cleanup

✅

doctor

Configuration

  • Ignore pixi on the mpm CLI by passing the --no-pixi option.

  • Ignore it for every run in your configuration:

    [mpm]
    pixi = false
    
  • Raise the timeout of all pixi calls:

    [mpm.overrides.pixi]
    timeout = 900
    
  • Run mpm config-template pixi to print all overridable settings for your configuration file:

    [mpm.overrides.pixi]
    cli_names = [
        "pixi",
    ]
    cli_search_path = []
    dry_run = false
    ignore_auto_updates = true
    plan = false
    post_args = []
    pre_args = [
        "--color=never",
        "--no-progress",
    ]
    pre_cmds = []
    requirement = ">=0.65.0"
    stop_on_error = false
    unmaintained = false
    version_cli_options = [
        "--version",
    ]
    version_regexes = [
        "^pixi\\s+(?P<version>\\S+)",
    ]
    

The arguments and environment variables listed in the box atop this page are forced on every pixi call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.

Recipes

A few jobs you would otherwise script around pixi, one mpm command each:

  • Snapshot and clone a machine: mpm --pixi dump pixi.toml, then mpm restore pixi.toml on the next one.

  • Export a compliance SBOM: mpm --pixi sbom (CycloneDX by default, --spdx for SPDX).

Privilege escalation

mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.

None of its operations is privileged.

See privilege escalation for the full policy.

Cooldown

State of pixi’s release-age gating, from the cooldown support table:

  • Status: 🚧 Proposed (merged for pixi global, unreleased; workspaces since 0.47.0)

  • Mechanism: exclude-newer in pixi.toml and the global manifest, declarative only: no flag or env var

  • Reference: prefix-dev/pixi#7016

A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:

  • Registry: anaconda.org / conda-forge (pkg:conda)

  • Retraction: Relabel: “we do not allow edits or the deletion of packages on conda-forge” (immutability); a bad artifact is labelled broken and “Users will no longer be able to install them by default” (procedure)

  • Publish date: ✅ upload_time, with the broken label carried in labels (API)

With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.

Reference traces

A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know pixi well and a transcript below looks wrong, or a newer release changed its output format, report it.

$ pixi --color=never --no-progress global list --json
[
  {
    "name": "ripgrep",
    "dependencies": [
      {
        "name": "ripgrep",
        "version": "14.1.0"
      }
    ],
    "exposed": [
      {
        "exposed_name": "rg",
        "executable": "rg"
      }
    ]
  }
]

Version check

The version is probed by running:

$ pixi --version
pixi 0.78.0

and extracted with:

r"^pixi\s+(?P<version>\S+)"

Upstream project

Metrics

prefix-dev/pixi

Activity

commit activity commits since open issues open pull requests

Popularity

forks watchers contributors

Metadata

latest release release date license main language

Changelog

  • 8.0.1 (2026-09-23)

    • Record the global exclude-newer gate pixi merged, which stays declarative-only, so mpm has no knob to inject.

  • 8.0.0 (2026-09-20)

    • Resolve the pkg:conda, pkg:golang, pkg:haxe and pkg:nuget pURL types to these managers, which raised instead of routing.

    • Add the pixi global tool manager with installed, install, upgrade, remove and cleanup support, packages keyed on the global environment pixi global addresses.