Vagrant¶
Note
Upstream has slowed: the last stable release is 2.4.9 of August 2025, though the repository is still committed to. Note also that Vagrant is distributed under the Business Source License from 2.4.3 onwards, which some distributions treat as non-free.
- ID
vagrant- Links
- Upstream stars
⭐ 27,210
- Last commit
2026-09-03
- Version requirement
>= 2.4
- Platforms
🐧 Linux · 🍎 macOS · 🪟 Windows
- Operations
installed·outdated·search·install·upgrade·upgrade_all·remove·cleanup- purl types
pkg:vagrant/- CLI name
vagrant- Forced environment
VAGRANT_CHECKPOINT_DISABLE=1- Issues and PRs
- Source
Vagrant’s box manager, covering the base images it fetches from its registry.
Vagrant orchestrates virtual machines, which is not package management. Two
of its subcommand trees are: vagrant box, covering versioned base images
pulled from a registry, and vagrant plugin, covering Vagrant’s own
extensions. Only one can be the inventory, and boxes are it. They carry the
whole operation set, where plugins offer neither an outdated nor a search
of any kind, and a plugin is a RubyGem installed into a private gem home
rather than something with a registry of its own.
A package is a box, identified by the bare name the listing prints, which
may be a registry name like ubuntu/jammy64, a purely local name, or a
full URL. The provider and the architecture are deliberately dropped from
the identifier.
Caution
Vagrant evaluates the working directory’s Vagrantfile trigger
configuration on every subcommand, so a malformed Vagrantfile breaks
even box list. Only the version probe is immune.
What mpm adds to vagrant¶
Through mpm, vagrant gains:
a one-command
upgrade --allthat refreshes every outdated package in a single run--exactand--extendedsearch, to narrow to exact names or match descriptions
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover vagrant alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your vagrant commands, in mpm¶
You already know vagrant: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
— |
|
Remove a package |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✅ |
A box installed in several versions appears once per name, keeping the newest version. |
|
✅ |
|
|
||
|
✅ |
Exact and extended search backfilled by |
|
✅ |
|
|
✅ |
|
|
✅ |
No native |
|
✅ |
|
|
❌ |
There is no command that refreshes box metadata without also downloading. |
|
✅ |
The |
|
Configuration¶
Ignore
vagranton thempmCLI by passing the--no-vagrantoption.Ignore it for every run in your configuration:
[mpm] vagrant = false
Raise the timeout of all
vagrantcalls:[mpm.overrides.vagrant] timeout = 900
Run
mpm config-template vagrantto print all overridable settings for your configuration file:[mpm.overrides.vagrant] cli_names = [ "vagrant", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [] pre_cmds = [] requirement = ">=2.4.0" stop_on_error = false unmaintained = false version_cli_options = [ "--version", ] version_regexes = [ "^Vagrant[ \\t]+(?P<version>\\S+)$", ] [mpm.overrides.vagrant.extra_env] VAGRANT_CHECKPOINT_DISABLE = "1"
The arguments and environment variables listed in the box atop this page are forced on every vagrant call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Recipes¶
A few jobs you would otherwise script around vagrant, one mpm command each:
Snapshot and clone a machine:
mpm --vagrant dump vagrant.toml, thenmpm restore vagrant.tomlon the next one.Export a compliance SBOM:
mpm --vagrant sbom(CycloneDX by default,--spdxfor SPDX).
Privilege escalation¶
mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.
None of its operations is privileged.
See privilege escalation for the full policy.
Cooldown¶
State of Vagrant’s release-age gating, from the cooldown support table:
Status: ❌ None
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: Vagrant Cloud boxes
Retraction: Author deletion: a box version is published by its own author to the public registry and can be withdrawn there, the version disappearing from the metadata Vagrant reads while any copy already downloaded stays in the local box store
Publish date: ✅ the registry records a creation date per box version, though
mpmreads no release-age gate from it
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.
Reference traces¶
A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Vagrant well and a transcript below looks wrong, or a newer release changed its output format, report it.
$ vagrant box list
linuxmint-21.3-cinnamon-64bit (hyperv, 0)
mintv1 (hyperv, 0)
wolvverine/LinuxMintCinnamon (hyperv, 1.1, (amd64))
$ vagrant box outdated --global
* 'ubuntu/jammy64' for 'virtualbox' is outdated! Current: 20231012.0.0. Latest: 20240126.0.0
* 'ubuntu/jammy64' for 'virtualbox' is outdated! Current: 20230914.0.0. Latest: 20240126.0.0
* 'ubuntu/jammy64' for 'virtualbox' is outdated! Current: 20230616.0.0. Latest: 20240126.0.0
Version check¶
The version is probed by running:
$ vagrant --version
Vagrant 2.4.9
and extracted with:
r"^Vagrant[ \t]+(?P<version>\S+)$"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0(2026-09-20)Add Vagrant’s box manager with
installed,outdated,search,install,upgrade,removeandcleanupsupport, one package per box name.Warn and report no package, instead of crashing, when a JSON listing cannot be parsed.