vcpkg

ID

vcpkg

Links

Home page · Documentation · Repository · Wikipedia

Upstream stars

⭐ 27,506

Last commit

2026-09-29

Platforms

🐧 Linux · 🍎 macOS · 🪟 Windows

Operations

installed · outdated · search · install · upgrade · upgrade_all · remove

purl types

pkg:vcpkg/

CLI name

vcpkg

Every call

vcpkg --classic <command>

Issues and PRs

📦 manager: vcpkg

Source

vcpkg.py

C and C++ library manager, covering what it installs machine-wide.

vcpkg has two modes and only one is a package manager in mpm’s sense. In manifest mode it reads a vcpkg.json from a project tree and installs beside it, which is project scope and out of scope here, recorded among the project-scoped ecosystems of Unsupported managers. In classic mode it installs into its own root, shared by everything on the machine, which Microsoft’s own documentation compares to brew or apt. That mode is what this wraps, on the same footing as the runtime managers mpm wraps for what they install globally.

Caution

A package is identified by its full specification, name:triplet, because that is vcpkg’s own unit: the same library built for two triplets is two installations, removed independently.

Warning

A vcpkg binary on PATH is not necessarily a working one. vcpkg is normally cloned and bootstrapped, and a packaged binary with no root configured errors on every operation asking for VCPKG_ROOT to be set. Homebrew ships exactly that, and says so in its own caveats. The failure is loud and self-explanatory rather than silent.

What mpm adds to vcpkg

Through mpm, vcpkg gains --exact and --extended search, to narrow to exact names or match descriptions.

Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover vcpkg alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.

Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.

Your vcpkg commands, in mpm

You already know vcpkg: each operation maps one-to-one onto mpm, in an interface shared by every manager.

To…

With vcpkg

With mpm

List what’s installed

vcpkg list --x-json

mpm --vcpkg installed

List outdated packages

vcpkg update

mpm --vcpkg outdated

Install a package

vcpkg install zlib:x64-linux

mpm install pkg:vcpkg/zlib:x64-linux

Upgrade one package

vcpkg upgrade --no-dry-run zlib:x64-linux

mpm --vcpkg upgrade zlib:x64-linux

Upgrade everything

vcpkg upgrade --no-dry-run

mpm --vcpkg upgrade --all

Remove a package

vcpkg remove zlib:x64-linux

mpm remove pkg:vcpkg/zlib:x64-linux

Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.

Operations

Operation

Supported

Notes

installed

✅

outdated

✅

orphans

search

✅

Results are named without a triplet; a bare name resolves against the default triplet at install time. Exact and extended search backfilled by mpm.

install

✅

upgrade

✅

upgrade_all

✅

remove

✅

sync

cleanup

doctor

Configuration

  • Ignore vcpkg on the mpm CLI by passing the --no-vcpkg option.

  • Ignore it for every run in your configuration:

    [mpm]
    vcpkg = false
    
  • Raise the timeout of all vcpkg calls:

    [mpm.overrides.vcpkg]
    timeout = 900
    
  • Run mpm config-template vcpkg to print all overridable settings for your configuration file:

    [mpm.overrides.vcpkg]
    cli_names = [
        "vcpkg",
    ]
    cli_search_path = []
    dry_run = false
    ignore_auto_updates = true
    plan = false
    post_args = []
    pre_args = [
        "--classic",
    ]
    pre_cmds = []
    stop_on_error = false
    unmaintained = false
    version_cli_options = [
        "--version",
    ]
    version_regexes = [
        "version (?P<version>\\d{4}-\\d{2}-\\d{2})",
    ]
    

The arguments and environment variables listed in the box atop this page are forced on every vcpkg call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.

Recipes

A few jobs you would otherwise script around vcpkg, one mpm command each:

  • Snapshot and clone a machine: mpm --vcpkg dump vcpkg.toml, then mpm restore vcpkg.toml on the next one.

  • Export a compliance SBOM: mpm --vcpkg sbom (CycloneDX by default, --spdx for SPDX).

Privilege escalation

mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.

None of its operations is privileged.

See privilege escalation for the full policy.

Cooldown

State of vcpkg’s release-age gating, from the cooldown support table:

Status: ❌ None

A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:

  • Registry: Git-manifest indexes

  • Retraction: Index revert: reverting the manifest, Portfile or derivation commit withdraws the version

  • Publish date: ❌ only the commit date, which is client-set and trivially backdated. A date declared in the manifest, like winget’s optional ReleaseDate, is author-supplied too and no sounder

With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.

Version check

The version is probed by running:

$ vcpkg --version
vcpkg package management program version 2026-07-27-unknownhash

See LICENSE.txt for license information.

and extracted with:

r"version (?P<version>\d{4}-\d{2}-\d{2})"

Upstream project

Metrics

microsoft/vcpkg

Activity

commit activity commits since open issues open pull requests

Popularity

forks watchers contributors

Metadata

latest release release date license main language

Changelog

  • 8.0.0 (2026-09-20)

    • Add the vcpkg C and C++ library manager, covering its classic mode: every call forces --classic, and packages are keyed on the name:triplet specification vcpkg addresses them by.

    • Warn and report no package, instead of crashing, when a JSON listing cannot be parsed.