The Aube homepage
Score6.5
Rank#10 of 18
Free planNo
Runs onLinux, macOS, Windows

Summary

Aube is an open-source Node.js package manager written in Rust for Linux, macOS and Windows. Its aubr command checks whether dependencies are missing or out of date before running a project script. Aube can read and update pnpm, npm, Yarn and Bun lockfiles, while a content-addressable store lets projects and worktrees share package directory trees. For one-off tools, aubx uses a locally available binary or installs the tool in a temporary project. Workspace packages, filters and catalogs are supported through pnpm-workspace.yaml or aube-workspace.yaml, and commands can use a Node version pinned by the project. During version selection, security checks consider publishing evidence, release age and known malicious packages. Lifecycle scripts need project approval or built-in trust, with explicit denials taking priority. Optional integrity verification checks fetched registry tarballs against recorded values. Aube supports embedding for Rust, Node-API hosts and C ABI consumers, and a GitHub Action can install its native binary. Yarn Plug’n’Play projects are not supported and need a node_modules linker.

Who it is for

Aube may suit Node.js developers who want shared package storage, workspace support and security checks during dependency selection. It is not a fit for Yarn Plug’n’Play projects unless they use a node_modules linker.

What is good

  • Supports pnpm, npm, Yarn and Bun lockfiles.
  • Shares package trees across projects and worktrees.
  • Supports workspaces, filters and catalogs.
  • Security checks include release age and malicious packages.
  • Open source under the MIT License.

What to know first

  • Yarn Plug’n’Play projects are unsupported.
  • The optional build jail is off by default.
  • Migration may expose project assumptions about dependency layout.
  • Integrity verification must be enabled to check tarballs.

Verdict

Aube brings several package-manager workflows together, including lockfile support, workspaces and dependency checks. Before switching, review the lockfile changes and run project tests, as the maker recommends.

Compared on JavaScript package managers

Workspace support
Yesaube.sh
Lockfile support
Yesaube.sh
Peer dependency handling
Yesaube.sh
Package publishing
Yesaube.sh
Offline package cache
Yesaube.sh
Global installation
Yesaube.sh

Facts

Product
Aube is a Node.js package manager written in Rust.aube.sh · 1 Oct 2026
Automatic installs
The aubr command installs missing or stale dependencies before running a project script.aube.sh · 1 Oct 2026
Lockfiles
Aube reads and writes supported pnpm, npm, Yarn, and Bun lockfiles in place.aube.sh · 1 Oct 2026
Shared storage
Aube uses a content-addressable store and shares package directory trees across projects and worktrees.aube.sh · 1 Oct 2026
One-off tools
The aubx command uses a local binary when available or installs a tool in a throwaway project.aube.sh · 1 Oct 2026
Workspaces
Aube supports workspace packages, filters, and catalogs through pnpm-workspace.yaml or aube-workspace.yaml.github.com · 1 Oct 2026
Node runtimes
Commands can use a project-pinned Node version from devEngines.runtime, .node-version, or .nvmrc.github.com · 1 Oct 2026
Security defaults
Aube checks publishing evidence, release age, and known malicious packages during version selection.aube.sh · 1 Oct 2026
Build permissions
Dependency lifecycle scripts require project approval or built-in trust, and explicit denies take precedence.aube.sh · 1 Oct 2026
Integrity
With integrity verification enabled, Aube checks fetched registry tarballs against recorded integrity values and fails on mismatches.aube.sh · 1 Oct 2026
Integrations
Aube provides embedding integrations for Rust, Node-API hosts, and C ABI consumers.aube.sh · 1 Oct 2026
CI integration
The jdx/aube-action GitHub Action installs the native binary and optionally Node.js.aube.sh · 1 Oct 2026
Support
The project directs users to GitHub Issues for bugs, GitHub Discussions for questions, and Discord for conversation.aube.sh · 1 Oct 2026
Compatibility limit
Yarn Plug'n'Play projects are not supported and require a node_modules linker.github.com · 1 Oct 2026
License
Aube is released under the MIT License.github.com · 1 Oct 2026
Run scripts
The aubr command checks for missing or stale dependencies before running a project script.aube.sh · 2 Oct 2026
Install options
The maker documents installation through mise, Homebrew, npm, Cargo, Ubuntu PPA, Fedora COPR, and source builds.aube.sh · 2 Oct 2026
Dependency build controls
Dependency lifecycle scripts require project approval or built-in trust, and explicit denies take precedence.aube.sh · 2 Oct 2026
Security checks
The documented defaults include a 24-hour minimum release age and checks for known malicious packages during fresh resolution.aube.sh · 2 Oct 2026
Build jail limits
The optional build jail is off by default; the maker documents native write and network restrictions on macOS and Linux, while filesystem reads remain unrestricted.aube.sh · 2 Oct 2026
Platform support
The installation page lists Homebrew for macOS or Linux and packages for supported Ubuntu and Fedora/RHEL distributions; the security page also describes Windows behavior for jailed scripts.aube.sh · 2 Oct 2026
Migration caveat
The maker says aube's isolated dependency layout and security defaults can expose assumptions in existing projects and recommends reviewing the lockfile diff and running tests before switching.aube.sh · 2 Oct 2026

Best Aube alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Aube yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources