Vagrant

Note

Upstream has slowed: the last stable release is 2.4.9 of August 2025, though the repository is still committed to. Note also that Vagrant is distributed under the Business Source License from 2.4.3 onwards, which some distributions treat as non-free.

ID

vagrant

Links

Home page · Documentation · Repository · Wikipedia

Upstream stars

⭐ 27,210

Last commit

2026-09-03

Version requirement

>= 2.4

Platforms

🐧 Linux · 🍎 macOS · 🪟 Windows

Operations

installed · outdated · search · install · upgrade · upgrade_all · remove · cleanup

purl types

pkg:vagrant/

CLI name

vagrant

Forced environment

VAGRANT_CHECKPOINT_DISABLE=1

Issues and PRs

📦 manager: vagrant

Source

vagrant.py

Vagrant’s box manager, covering the base images it fetches from its registry.

Vagrant orchestrates virtual machines, which is not package management. Two of its subcommand trees are: vagrant box, covering versioned base images pulled from a registry, and vagrant plugin, covering Vagrant’s own extensions. Only one can be the inventory, and boxes are it. They carry the whole operation set, where plugins offer neither an outdated nor a search of any kind, and a plugin is a RubyGem installed into a private gem home rather than something with a registry of its own.

A package is a box, identified by the bare name the listing prints, which may be a registry name like ubuntu/jammy64, a purely local name, or a full URL. The provider and the architecture are deliberately dropped from the identifier.

Caution

Vagrant evaluates the working directory’s Vagrantfile trigger configuration on every subcommand, so a malformed Vagrantfile breaks even box list. Only the version probe is immune.

What mpm adds to vagrant

Through mpm, vagrant gains:

  • a one-command upgrade --all that refreshes every outdated package in a single run

  • --exact and --extended search, to narrow to exact names or match descriptions

Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover vagrant alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.

Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.

Your vagrant commands, in mpm

You already know vagrant: each operation maps one-to-one onto mpm, in an interface shared by every manager.

To…

With vagrant

With mpm

List what’s installed

vagrant box list

mpm --vagrant installed

List outdated packages

vagrant box outdated --global

mpm --vagrant outdated

Install a package

vagrant box add ubuntu/jammy64

mpm install pkg:vagrant/ubuntu/jammy64

Upgrade one package

vagrant box update --box ubuntu/jammy64

mpm --vagrant upgrade ubuntu/jammy64

Upgrade everything

—

mpm --vagrant upgrade --all

Remove a package

vagrant box remove --force --all ubuntu/jammy64

mpm remove pkg:vagrant/ubuntu/jammy64

Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.

Operations

Operation

Supported

Notes

installed

✅

A box installed in several versions appears once per name, keeping the newest version.

outdated

✅

orphans

search

✅

Exact and extended search backfilled by mpm.

install

✅

upgrade

✅

upgrade_all

✅

No native upgrade --all; backfilled by mpm.

remove

✅

sync

❌

There is no command that refreshes box metadata without also downloading.

cleanup

✅

The --orphans flag runs the system-wide orphan sweep.

doctor

Configuration

  • Ignore vagrant on the mpm CLI by passing the --no-vagrant option.

  • Ignore it for every run in your configuration:

    [mpm]
    vagrant = false
    
  • Raise the timeout of all vagrant calls:

    [mpm.overrides.vagrant]
    timeout = 900
    
  • Run mpm config-template vagrant to print all overridable settings for your configuration file:

    [mpm.overrides.vagrant]
    cli_names = [
        "vagrant",
    ]
    cli_search_path = []
    dry_run = false
    ignore_auto_updates = true
    plan = false
    post_args = []
    pre_args = []
    pre_cmds = []
    requirement = ">=2.4.0"
    stop_on_error = false
    unmaintained = false
    version_cli_options = [
        "--version",
    ]
    version_regexes = [
        "^Vagrant[ \\t]+(?P<version>\\S+)$",
    ]
    
    [mpm.overrides.vagrant.extra_env]
    VAGRANT_CHECKPOINT_DISABLE = "1"
    

The arguments and environment variables listed in the box atop this page are forced on every vagrant call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.

Recipes

A few jobs you would otherwise script around vagrant, one mpm command each:

  • Snapshot and clone a machine: mpm --vagrant dump vagrant.toml, then mpm restore vagrant.toml on the next one.

  • Export a compliance SBOM: mpm --vagrant sbom (CycloneDX by default, --spdx for SPDX).

Privilege escalation

mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.

None of its operations is privileged.

See privilege escalation for the full policy.

Cooldown

State of Vagrant’s release-age gating, from the cooldown support table:

Status: ❌ None

A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:

  • Registry: Vagrant Cloud boxes

  • Retraction: Author deletion: a box version is published by its own author to the public registry and can be withdrawn there, the version disappearing from the metadata Vagrant reads while any copy already downloaded stays in the local box store

  • Publish date: ✅ the registry records a creation date per box version, though mpm reads no release-age gate from it

With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.

Reference traces

A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Vagrant well and a transcript below looks wrong, or a newer release changed its output format, report it.

$ vagrant box list
linuxmint-21.3-cinnamon-64bit (hyperv, 0)
mintv1                        (hyperv, 0)
wolvverine/LinuxMintCinnamon  (hyperv, 1.1, (amd64))
$ vagrant box outdated --global
* 'ubuntu/jammy64' for 'virtualbox' is outdated! Current: 20231012.0.0. Latest: 20240126.0.0
* 'ubuntu/jammy64' for 'virtualbox' is outdated! Current: 20230914.0.0. Latest: 20240126.0.0
* 'ubuntu/jammy64' for 'virtualbox' is outdated! Current: 20230616.0.0. Latest: 20240126.0.0

Version check

The version is probed by running:

$ vagrant --version
Vagrant 2.4.9

and extracted with:

r"^Vagrant[ \t]+(?P<version>\S+)$"

Upstream project

Metrics

hashicorp/vagrant

Activity

commit activity open issues open pull requests

Popularity

forks watchers contributors

Metadata

latest tag license main language

Changelog

  • 8.0.0 (2026-09-20)

    • Add Vagrant’s box manager with installed, outdated, search, install, upgrade, remove and cleanup support, one package per box name.

    • Warn and report no package, instead of crashing, when a JSON listing cannot be parsed.