Zef

ID

zef

Link

Repository

Upstream stars

⭐ 225

Last commit

2026-09-17

Platforms

🅱️ BSD · 🐧 Linux · 🍎 macOS · ⨂ Unix · 🪟 Windows

Operations

installed · search · install · upgrade · upgrade_all · remove · sync

purl types

pkg:perl6/ · pkg:zef/

CLI name

zef

Issues and PRs

📦 manager: zef

Source

zef.py

Zef, the module manager of the Raku language.

A package is a Raku distribution, identified by the bare name its identity string opens with. Raku names are colon-separated (JSON::Fast) and the identity appends its own colon-prefixed fields to them (JSON::Fast:ver<0.20>:auth<zef:timo>), so every pattern here matches the name lazily up to the literal :ver< rather than splitting on colons.

What mpm adds to zef

Through mpm, zef gains --exact and --extended search, to narrow to exact names or match descriptions.

Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover zef alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.

Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.

Your zef commands, in mpm

You already know zef: each operation maps one-to-one onto mpm, in an interface shared by every manager.

To…

With zef

With mpm

List what’s installed

zef list --installed

mpm --zef installed

Search for a package

zef search JSON::Fast

mpm --zef search JSON::Fast

Install a package

zef install JSON::Fast::Hyper

mpm install pkg:zef/JSON::Fast::Hyper

Upgrade one package

zef upgrade JSON::Fast

mpm --zef upgrade JSON::Fast

Upgrade everything

zef upgrade

mpm --zef upgrade --all

Remove a package

zef uninstall JSON::Fast::Hyper

mpm remove pkg:zef/JSON::Fast::Hyper

Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.

Operations

Operation

Supported

Notes

installed

✅

Two distributions may share a name and differ only by their auth field; the listing keeps one entry per name at the highest version.

outdated

❌

The tool reports no staleness of its own.

orphans

search

✅

The tool’s search answers one row per (distribution, version) pair, so results are reduced to one entry per name. Exact and extended search backfilled by mpm.

install

✅

upgrade

✅

upgrade_all

✅

remove

✅

sync

✅

cleanup

doctor

Configuration

  • Ignore zef on the mpm CLI by passing the --no-zef option.

  • Ignore it for every run in your configuration:

    [mpm]
    zef = false
    
  • Raise the timeout of all zef calls:

    [mpm.overrides.zef]
    timeout = 900
    
  • Run mpm config-template zef to print all overridable settings for your configuration file:

    [mpm.overrides.zef]
    cli_names = [
        "zef",
    ]
    cli_search_path = []
    dry_run = false
    ignore_auto_updates = true
    plan = false
    post_args = []
    pre_args = []
    pre_cmds = []
    stop_on_error = false
    unmaintained = false
    version_cli_options = [
        "--version",
    ]
    version_regexes = [
        "^(?P<version>\\d+\\.\\d+\\.\\d+)",
    ]
    

Recipes

A few jobs you would otherwise script around zef, one mpm command each:

  • Snapshot and clone a machine: mpm --zef dump zef.toml, then mpm restore zef.toml on the next one.

  • Export a compliance SBOM: mpm --zef sbom (CycloneDX by default, --spdx for SPDX).

Privilege escalation

mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.

None of its operations is privileged.

See privilege escalation for the full policy.

Cooldown

State of Zef’s release-age gating, from the cooldown support table:

Status: ❌ None

A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:

  • Registry: Raku ecosystem (pkg:perl6)

  • Retraction: Immutable once published: fez, the ecosystem zef resolves against, accepts an upload per version and offers its authors no delete or yank verb, so a withdrawal is an administrative request rather than a client-visible operation

  • Publish date: ❌ the identity a distribution is known by carries a version, an authority and an API level but no date, and neither the listing nor the search reports one

With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.

Reference traces

A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Zef well and a transcript below looks wrong, or a newer release changed its output format, report it.

$ zef list --installed
===> Found via inst#/opt/homebrew/Cellar/rakudo-star/2026.07/share/perl6/site
App::Prove6:ver<0.0.18>:auth<zef:leont>
Config::TOML:ver<0.1.3>:auth<zef:raku-community-modules>
Config:ver<3.0.4>:auth<cpan:TYIL>:api<3>
Crane:ver<0.1.2>:auth<zef:raku-community-modules>
Digest:ver<1.1.0>:auth<zef:grondilu>

Version check

The version is probed by running:

$ zef --version
1.1.3

and extracted with:

r"^(?P<version>\d+\.\d+\.\d+)"

Upstream project

Metrics

ugexe/zef

Activity

commit activity commits since open issues open pull requests

Popularity

forks watchers contributors

Metadata

latest release release date license main language

Changelog

  • 8.0.0 (2026-09-20)

    • Add the Zef Raku package manager with installed, search, install, upgrade, remove and sync support, both listings reduced to one entry per distribution name.