Scoop sfsu

Note

Since 2026-09-21, the sfsu readme looks for maintainers: its author no longer runs Windows, and commits only to bug fixes and parity with Scoop. It points to hok as an alternative.

ID

sfsu

Link

Repository

Upstream stars

⭐ 254

Last commit

2026-09-26

Version requirement

>= 1.16

Platforms

🪟 Windows

Operations

installed · outdated · search · install · upgrade · upgrade_all · remove · sync · cleanup

purl types

pkg:sfsu/

CLI name

sfsu

Every call

sfsu <command> --no-color

Issues and PRs

📦 manager: scoop-based

Source

sfsu.py

sfsu (Stupid Fast Scoop Utils) is a Rust reimplementation of Scoop’s slower read paths, working against the same buckets and ~/scoop install tree.

mpm reaches for sfsu only where it is both faster than Scoop and speaks JSON: installed, outdated and search all pass --json and are parsed as structured objects instead of the whitespace tables Scoop prints.

What mpm adds to sfsu

Through mpm, sfsu gains --exact and --extended search, to narrow to exact names or match descriptions.

Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover sfsu alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.

Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.

Your sfsu commands, in mpm

You already know sfsu: each operation maps one-to-one onto mpm, in an interface shared by every manager.

To…

With sfsu

With mpm

List what’s installed

sfsu list --json

mpm --sfsu installed

List outdated packages

sfsu status --only apps --json

mpm --sfsu outdated

Search for a package

sfsu search --json zoxide

mpm --sfsu search zoxide

Clear caches

sfsu cleanup --all --cache

mpm --sfsu cleanup --cache

Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.

Operations

Operation

Supported

Notes

installed

✅

outdated

✅

orphans

search

✅

Exact and extended search backfilled by mpm.

install

✅

The tool ships no mutating verb, so the operation runs the scoop binary instead.

upgrade

✅

The tool ships no mutating verb, so the operation runs the scoop binary instead.

upgrade_all

✅

The tool ships no mutating verb, so the operation runs the scoop binary instead.

remove

✅

The tool ships no mutating verb, so the operation runs the scoop binary instead.

sync

✅

cleanup

✅

doctor

Configuration

  • Ignore sfsu on the mpm CLI by passing the --no-sfsu option.

  • Ignore it for every run in your configuration:

    [mpm]
    sfsu = false
    
  • Raise the timeout of all sfsu calls:

    [mpm.overrides.sfsu]
    timeout = 900
    
  • Run mpm config-template sfsu to print all overridable settings for your configuration file:

    [mpm.overrides.sfsu]
    cli_names = [
        "sfsu",
    ]
    cli_search_path = []
    dry_run = false
    ignore_auto_updates = true
    plan = false
    post_args = [
        "--no-color",
    ]
    pre_args = []
    pre_cmds = []
    requirement = ">=1.16.0"
    stop_on_error = false
    unmaintained = false
    version_cli_options = [
        "--version",
    ]
    version_regexes = [
        "sfsu\\s+(?P<version>\\S+)",
    ]
    

The arguments and environment variables listed in the box atop this page are forced on every sfsu call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.

Recipes

A few jobs you would otherwise script around sfsu, one mpm command each:

  • Snapshot and clone a machine: mpm --sfsu dump sfsu.toml, then mpm restore sfsu.toml on the next one.

  • Export a compliance SBOM: mpm --sfsu sbom (CycloneDX by default, --spdx for SPDX).

Privilege escalation

mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.

None of its operations is privileged.

See privilege escalation for the full policy.

Concurrency

mpm never runs sfsu at the same time as scoop: they work on the same ~/scoop tree, sfsu delegating its mutating operations to the scoop binary itself. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.

Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.

Cooldown

State of Scoop sfsu’s release-age gating, from the cooldown support table:

Status: 🚧 Inherits from scoop

A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:

  • Registry: Git-manifest indexes

  • Retraction: Index revert: reverting the manifest, Portfile or derivation commit withdraws the version

  • Publish date: ❌ only the commit date, which is client-set and trivially backdated. A date declared in the manifest, like winget’s optional ReleaseDate, is author-supplied too and no sounder

With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.

Reference traces

A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Scoop sfsu well and a transcript below looks wrong, or a newer release changed its output format, report it.

> sfsu list --json --no-color
[
  {
    "name": "7zip",
    "version": "26.00",
    "source": "main",
    "updated": "2026-03-18 17:54:32",
    "notes": ""
  },
  {
    "name": "git",
    "version": "2.53.0.3",
    "source": "main",
    "updated": "2026-03-15 09:12:04",
    "notes": ""
  }
]
> sfsu status --only apps --json --no-color
{
  "packages": [
    {
      "name": "git",
      "current": "2.53.0.2",
      "available": "2.53.0.3",
      "missing_dependencies": [],
      "info": null
    }
  ]
}

Version check

The version is probed by running:

$ sfsu --version
sfsu 1.17.2
sprinkles 0.22.0 (crates.io published version)

and extracted with:

r"sfsu\s+(?P<version>\S+)"

Upstream project

Metrics

winpax/sfsu

Activity

commit activity commits since open issues open pull requests

Popularity

forks watchers contributors

Metadata

latest release release date license main language

Changelog

  • 8.1.0.dev0 (unreleased)

    • Note on its page that upstream looks for new maintainers and now ships only fixes.

  • 8.0.0 (2026-09-20)

    • Stop running sfsu concurrently with scoop, whose buckets and cache its own update and cleanup reach.

    • Correct the commands shown on each manager’s page, which named fewer options than mpm actually runs.

  • 6.4.0 (2026-04-27)

    • Add sfsu (Scoop alternative) package manager with installed, outdated, search, install, upgrade, remove, sync, and cleanup support. Mutating operations delegate to Scoop.