Spack

ID

spack

Links

Home page · Documentation · Repository

Upstream stars

⭐ 5,134

Last commit

2026-10-05

Version requirement

>= 1

Platforms

🐧 Linux · 🍎 macOS

Operations

installed · search · install · remove · sync · cleanup

purl types

pkg:spack/

CLI name

spack

Every call

spack --no-env <command>

Issues and PRs

📦 manager: spack

Source

spack.py

Spack, the package manager built for supercomputers and HPC clusters.

A package is a spec: a package name carrying a version, a compiler, a target architecture and a set of build options, each combination installed into a prefix of its own. mpm keys a package on its id alone, so the spec is reduced to the name every verb accepts back.

Note

Every spec the tool’s database holds is reported, which is broader than what it built: packages pulled in as build dependencies appear, and so do externals like the system compiler it registers on first use. No flag separates them out.

Warning

A read bootstraps the host on first use: upstream clones the package repository automatically on the first run, so an inventory or a search on a fresh install fetches some twenty thousand objects into ~/.spack before answering.

What mpm adds to spack

Through mpm, spack gains --exact search, to narrow results to exact names.

Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover spack alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.

Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.

Your spack commands, in mpm

You already know spack: each operation maps one-to-one onto mpm, in an interface shared by every manager.

To…

With spack

With mpm

List what’s installed

spack find --format <name>@<version>

mpm --spack installed

Search for a package

spack list --format version_json zlib-ng

mpm --spack search zlib-ng

Install a package

spack install zlib@1.3.1

mpm install pkg:spack/zlib@1.3.1

Remove a package

spack uninstall --yes-to-all --all zlib

mpm remove pkg:spack/zlib

Clear caches

spack clean --downloads --misc-cache --python-cache --stage

mpm --spack cleanup --cache

Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.

Operations

Operation

Supported

Notes

installed

✅

The inventory repeats a name as many times as the host has builds of it, holding several builds at once being the tool’s whole purpose.

outdated

❌

The tool ships no comparison command at all.

orphans

search

✅

Exact search backfilled by mpm.

install

✅

upgrade

❌

Installing an already-present package adds a second build rather than replacing the first, so an upgrade wired to it would report success and leave the old build in place.

upgrade_all

❌

Installing an already-present package adds a second build rather than replacing the first, so an upgrade wired to it would report success and leave the old build in place.

remove

✅

sync

✅

cleanup

✅

The --orphans flag runs the system-wide orphan sweep.

doctor

Configuration

  • Ignore spack on the mpm CLI by passing the --no-spack option.

  • Ignore it for every run in your configuration:

    [mpm]
    spack = false
    
  • Raise the timeout of all spack calls:

    [mpm.overrides.spack]
    timeout = 900
    
  • Run mpm config-template spack to print all overridable settings for your configuration file:

    [mpm.overrides.spack]
    cli_names = [
        "spack",
    ]
    cli_search_path = []
    dry_run = false
    ignore_auto_updates = true
    plan = false
    post_args = []
    pre_args = [
        "--no-env",
    ]
    pre_cmds = []
    requirement = ">=1.0.0"
    stop_on_error = false
    unmaintained = false
    version_cli_options = [
        "--version",
    ]
    version_regexes = [
        "(?P<version>\\S+)",
    ]
    

The arguments and environment variables listed in the box atop this page are forced on every spack call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.

Recipes

A few jobs you would otherwise script around spack, one mpm command each:

  • Snapshot and clone a machine: mpm --spack dump spack.toml, then mpm restore spack.toml on the next one.

  • Export a compliance SBOM: mpm --spack sbom (CycloneDX by default, --spdx for SPDX).

Privilege escalation

mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.

None of its operations is privileged.

See privilege escalation for the full policy.

Cooldown

State of Spack’s release-age gating, from the cooldown support table:

Status: ❌ None (builds from source)

A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:

  • Registry: Source-based recipe trees

  • Retraction: Index revert of the recipe tree

  • Publish date: ❌ a recipe carries no publication date

With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.

Reference traces

A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Spack well and a transcript below looks wrong, or a newer release changed its output format, report it.

Version check

The version is extracted from the output of spack --version with:

r"(?P<version>\S+)"

Upstream project

Metrics

spack/spack

Activity

commit activity commits since open issues open pull requests

Popularity

forks watchers contributors

Metadata

latest release release date license main language

Changelog

  • 8.0.0 (2026-09-20)

    • Add the Spack package manager with installed, search, install, remove, sync and cleanup support, every call forced --no-env. No outdated and no upgrade: installing over a package adds a second build rather than replacing the first.