Arch Linux trizen¶
- ID
trizen- Links
- Upstream stars
⭐ 822
- Last commit
2025-08-11
- Version requirement
>= 1
- Platforms
🅱️ BSD · 🐧 Linux · ⨂ Unix
- Operations
installed·outdated·orphans·search·install·upgrade·upgrade_all·remove·sync·cleanup·doctor- purl types
pkg:alpm/·pkg:trizen/- CLI name
trizen- Every call
trizen --noconfirm --color never <command>- Issues and PRs
- Source
AUR helper wrapping pacman, driven through the trizen binary.
Inherits every operation, parser and forced argument from Pacman; the
binary, the version probe and the release floor are what differ. Its own
--query --upgrades reports AUR updates on top of the official
repositories.
Like the other helpers, trizen must run as the regular user: makepkg
refuses to build as root, and trizen calls sudo pacman itself for the
privileged steps. mpm therefore never wraps it in sudo.
Note
Upstream is slow rather than stopped: commits continue, but 1.68 of
December 2022 is still the newest release. It stays unflagged here because
the stability policy keys unmaintained on an abandoned upstream, not on a
quiet release cadence.
What mpm adds to trizen¶
Through mpm, trizen gains:
a one-command
cleanup --orphansthat removes every orphaned dependency at once--extendedsearch, to match against package descriptions
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover trizen alongside aura, dkp-pacman, pacaur, pacman, pamac, paru, pikaur, shelly, yay and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your trizen commands, in mpm¶
You already know trizen: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Search for a package |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
|
|
Remove a package |
|
|
List orphaned dependencies |
|
|
Clear caches |
|
|
Run health checks |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✅ |
|
|
✅ |
Only packages tracked in a sync database are reported; foreign packages (AUR builds, |
|
✅ |
|
|
✅ |
Extended search backfilled by |
|
✅ |
A package already installed as a dependency is marked explicit by |
|
✅ |
|
|
✅ |
|
|
✅ |
The |
|
✅ |
|
|
✅ |
The |
|
✅ |
Configuration¶
Ignore
trizenon thempmCLI by passing the--no-trizenoption.Ignore it for every run in your configuration:
[mpm] trizen = false
Raise the timeout of all
trizencalls:[mpm.overrides.trizen] timeout = 900
Run
mpm config-template trizento print all overridable settings for your configuration file:[mpm.overrides.trizen] cli_names = [ "trizen", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [ "--noconfirm", "--color", "never", ] pre_cmds = [] requirement = ">=1.0.0" stop_on_error = false unmaintained = false version_cli_options = [ "--version", ] version_regexes = [ "trizen\\s+(?P<version>\\S+)", ]
The arguments and environment variables listed in the box atop this page are forced on every trizen call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Recipes¶
A few jobs you would otherwise script around trizen, one mpm command each:
Snapshot and clone a machine:
mpm --trizen dump trizen.toml, thenmpm restore trizen.tomlon the next one.Export a compliance SBOM:
mpm --trizen sbom(CycloneDX by default,--spdxfor SPDX).Gate CI on health:
mpm --trizen doctorrelays Arch Linux trizen’s own diagnosis and exits non-zero on trouble.
Privilege escalation¶
Arch Linux trizen runs sudo from inside its own commands: mpm never wraps it, keeps an already-warm credential cache alive for those internal escalations, and warns when a mutating call goes silent on a terminal with a cold cache, since a password prompt may be hiding in the stream.
See privilege escalation for the full policy.
Concurrency¶
mpm never runs trizen at the same time as aura, pacaur, pacman, pamac, paru, pikaur or yay: they all reach the pacman database (/var/lib/pacman/db.lck), and two of them mutating at once fail to init their transaction. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.
Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.
Cooldown¶
State of Arch Linux trizen’s release-age gating, from the cooldown support table:
Status: ❌ None (Arch AUR helper; could take paru’s probe)
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: AUR
Retraction: None at the version level: an AUR package is a git repository with no per-version artifact to withdraw, so remediation is a maintainer push or deletion of the whole package
Publish date: ✅ server-set
LastModified, the push timestampmpm’syayoverlay andparuprobe gate on. Git commit dates are client-set (GIT_COMMITTER_DATE), forgeable, and never consulted
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.
Version check¶
The version is probed by running:
$ trizen --version
trizen 1.68
and extracted with:
r"trizen\s+(?P<version>\S+)"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0(2026-09-20)Mark a package already installed as a dependency as explicitly installed when
mpm installormpm restorenames it, sompm cleanup --orphanskeeps it.Resolve
pkg:alpm,pkg:conda,pkg:deb,pkg:melpa,pkg:pypiandpkg:rpmpURLs to these managers too, alongside the ones already handling each type.Add the trizen AUR helper with the full operation set inherited from
pacman.Stop running the AUR helpers concurrently with
pacmanand with each other, all of them driving the same pacman database.