Spack¶
- ID
spack- Links
- Upstream stars
⭐ 5,134
- Last commit
2026-10-05
- Version requirement
>= 1
- Platforms
🐧 Linux · 🍎 macOS
- Operations
installed·search·install·remove·sync·cleanup- purl types
pkg:spack/- CLI name
spack- Every call
spack --no-env <command>- Issues and PRs
- Source
Spack, the package manager built for supercomputers and HPC clusters.
A package is a spec: a package name carrying a version, a compiler, a target architecture and a set of build options, each combination installed into a prefix of its own. mpm keys a package on its id alone, so the spec is reduced to the name every verb accepts back.
Note
Every spec the tool’s database holds is reported, which is broader than what it built: packages pulled in as build dependencies appear, and so do externals like the system compiler it registers on first use. No flag separates them out.
Warning
A read bootstraps the host on first use: upstream clones the package
repository automatically on the first run, so an inventory or a search on
a fresh install fetches some twenty thousand objects into ~/.spack
before answering.
What mpm adds to spack¶
Through mpm, spack gains --exact search, to narrow results to exact names.
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover spack alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your spack commands, in mpm¶
You already know spack: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
Search for a package |
|
|
Install a package |
|
|
Remove a package |
|
|
Clear caches |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✅ |
The inventory repeats a name as many times as the host has builds of it, holding several builds at once being the tool’s whole purpose. |
|
❌ |
The tool ships no comparison command at all. |
|
||
|
✅ |
Exact search backfilled by |
|
✅ |
|
|
❌ |
Installing an already-present package adds a second build rather than replacing the first, so an upgrade wired to it would report success and leave the old build in place. |
|
❌ |
Installing an already-present package adds a second build rather than replacing the first, so an upgrade wired to it would report success and leave the old build in place. |
|
✅ |
|
|
✅ |
|
|
✅ |
The |
|
Configuration¶
Ignore
spackon thempmCLI by passing the--no-spackoption.Ignore it for every run in your configuration:
[mpm] spack = false
Raise the timeout of all
spackcalls:[mpm.overrides.spack] timeout = 900
Run
mpm config-template spackto print all overridable settings for your configuration file:[mpm.overrides.spack] cli_names = [ "spack", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [ "--no-env", ] pre_cmds = [] requirement = ">=1.0.0" stop_on_error = false unmaintained = false version_cli_options = [ "--version", ] version_regexes = [ "(?P<version>\\S+)", ]
The arguments and environment variables listed in the box atop this page are forced on every spack call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Recipes¶
A few jobs you would otherwise script around spack, one mpm command each:
Snapshot and clone a machine:
mpm --spack dump spack.toml, thenmpm restore spack.tomlon the next one.Export a compliance SBOM:
mpm --spack sbom(CycloneDX by default,--spdxfor SPDX).
Privilege escalation¶
mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.
None of its operations is privileged.
See privilege escalation for the full policy.
Cooldown¶
State of Spack’s release-age gating, from the cooldown support table:
Status: ❌ None (builds from source)
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: Source-based recipe trees
Retraction: Index revert of the recipe tree
Publish date: ❌ a recipe carries no publication date
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.
Reference traces¶
A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Spack well and a transcript below looks wrong, or a newer release changed its output format, report it.
$ spack --no-env find --format {name}@{version}
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
Version check¶
The version is extracted from the output of spack --version with:
r"(?P<version>\S+)"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0(2026-09-20)Add the Spack package manager with
installed,search,install,remove,syncandcleanupsupport, every call forced--no-env. Nooutdatedand noupgrade: installing over a package adds a second build rather than replacing the first.