Xcode xcodes¶
- ID
xcodes- Link
- Upstream stars
⭐ 4,839
- Last commit
2026-09-14
- Version requirement
>= 1
- Platforms
🍎 macOS
- Operations
installed·remove·sync- purl types
pkg:xcodes/- CLI name
xcodes- Issues and PRs
- Source
xcodes installs and manages Xcode versions on macOS (https://github.com/XcodesOrg/xcodes).
A package is one installed Xcode, identified by its marketing version exactly
as the listing renders it: 16.2, but also 26.4 Release Candidate and
27.0 Beta 5. Those spaces are not a problem here, because mpm substitutes a
package id as a single argv element and xcodes joins its version arguments
back together either way. A build number cannot stand in as a space-free
identifier: xcodes parses 17E192 as major 17 with a prerelease of e 192
and reports the version as not installed.
Note
The listing has two shapes, and mpm sees the machine-readable one. Written to
a terminal, xcodes pads the version column to align it for a human; written
anywhere else it separates the columns with a tab instead, a distinction its
source has carried deliberately since 1.0.0 for the benefit of tools like
this one. The tab is what the pattern below anchors on, which also rejects the
legible errors xcodes prints to stdout rather than stderr.
Caution
No install, and it is not a matter of flags. Downloading an Xcode always
authenticates against an Apple ID, on both data sources, and the prompts are
real reads from standard input: XCODES_USERNAME and XCODES_PASSWORD exist
but two-factor authentication has no environment path at all, being three
further interactive reads, and a federated Apple ID opens a browser and waits
for a pasted callback URL. A second prompt follows for the superuser password
the post-install steps need. An unattended install is therefore not
expressible, while everything below runs with no credentials whatsoever.
Warning
Never pass --data-source apple. The default source is a public feed served
over plain HTTP, which is what keeps the catalog readable anonymously; that
one flag routes the same reads through Apple’s authenticated endpoints and
turns every one of them into a login prompt.
No outdated: knowing an Xcode is behind means joining the installed set
against the catalog, which is two commands and a comparison rather than one
argument list. No search either, the catalog listing accepting no query, and
it is filtered to the host’s architecture by default, so its contents differ
between machines. No upgrade of either kind exists, and no cleanup: the
request to reclaim disk space has been open upstream since 2022.
sync maps to xcodes update, which despite its name refreshes the catalog
rather than any installed Xcode. It prints the whole catalog while doing so,
which is noise mpm does not read.
No escalation: the reads and the removal all run unprivileged, and only the install path xcodes cannot run unattended needs a superuser password.
What mpm adds to xcodes¶
mpm reaches across every manager at once, not xcodes alone: mpm installed and mpm outdated cover xcodes alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Operations¶
Operation |
Supported |
|---|---|
|
✅ |
|
|
|
|
|
|
|
|
|
|
|
|
|
✅ |
|
✅ |
|
|
|
Configuration¶
Ignore
xcodeson thempmCLI by passing the--no-xcodesoption.Ignore it for every run in your configuration:
[mpm] xcodes = false
Raise the timeout of all
xcodescalls:[mpm.overrides.xcodes] timeout = 900
Run
mpm config-template xcodesto print all overridable settings for your configuration file:[mpm.overrides.xcodes] cli_names = [ "xcodes", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [] pre_cmds = [] requirement = ">=1.0.0" stop_on_error = false unmaintained = false version_cli_options = [ "version", ] version_regexes = [ "^(?P<version>\\d+(?:\\.\\d+)+)$", ]
Recipes¶
A few jobs you would otherwise script around xcodes, one mpm command each:
Snapshot and clone a machine:
mpm --xcodes dump xcodes.toml, thenmpm restore xcodes.tomlon the next one.Export a compliance SBOM:
mpm --xcodes sbom(CycloneDX by default,--spdxfor SPDX).
Privilege escalation¶
mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.
None of its operations is privileged.
See privilege escalation for the full policy.
Cooldown¶
State of Xcode xcodes’s release-age gating, from the cooldown support table:
Status: ❌ None
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: Apple developer downloads
Retraction: Vendor withdrawal only: releases are served from Apple’s developer downloads and catalogued by the community feed xcodes reads, so a version disappears when Apple stops serving it, with no yank or unlist surface exposed to anyone else
Publish date: ✅ the catalog feed records a release date per version, though
mpmreads no release-age gate from it
Reference traces¶
A collection of raw native outputs captured from the manager’s own CLI and recorded in the bundled definition. If you know Xcode xcodes well and a transcript below looks wrong, or a newer release changed its output format, report it.
$ xcodes installed
15.4 (15F31d) /Applications/Xcode-15.4.0.app
16.2 (16C5032a) /Applications/Xcode-16.2.0.app
26.2 (17C52) [Apple Silicon] /Applications/Xcode-26.2.0.app
26.4 Release Candidate (17E192) /Applications/Xcode-26.4.0-Release.Candidate.app
Version check¶
The version is probed by running:
$ xcodes version
2.0.3
and extracted with:
r"^(?P<version>\d+(?:\.\d+)+)$"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0(2026-09-20)Add the xcodes Xcode version manager with
installed,removeandsyncsupport. It declares noinstall: downloading an Xcode always authenticates against an Apple ID, with no non-interactive path.