conan@1 (deprecated)

Disable date: 2026-10-27

Install command:
brew install conan@1

Distributed, open source, package manager for C/C++

https://conan.io

License: MIT

Development: Pull requests

Formula JSON API: /api/formula/conan@1.json

Formula code: conan@1.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
tahoe
sequoia
sonoma
ventura
macOS on
Intel
sonoma
ventura
Linux ARM64
x86_64

Current versions:

stable 1.66.0

Revision: 3

Keg-only

Depends on:

certifi 2026.7.22 Mozilla CA bundle for Python
libyaml 0.2.5 YAML Parser
python@3.12 3.12.14 Interpreted, interactive, object-oriented programming language

Depends on when building from source:

pkgconf 3.0.6 Package compiler and linker metadata toolkit

Known vulnerabilities in the current version:

PYSEC-2025-183 (high)
GHSA-pq67-6m6q-mj2v (medium) urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
GHSA-gm62-xv2j-4w53 urllib3 allows an unbounded number of links in the decompression chain
GHSA-2xpw-w6gg-jr37 urllib3 streaming API improperly handles highly compressed data
GHSA-38jv-5279-wg99 (high) Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
GHSA-gc5v-m9x4-r6x2 (medium) Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
GHSA-752w-5fwx-jx9f (high) PyJWT accepts unknown `crit` header extensions
GHSA-qccp-gfcp-xxvc (medium) urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
GHSA-5239-wwwm-4pmq (low) Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
GHSA-65pc-fj4g-8rjx (medium) Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() ...
GHSA-993g-76c3-p5m4 (medium) PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file:...
GHSA-jq35-7prp-9v3f (medium) PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
GHSA-fhv5-28vv-h8m8 (low) PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
GHSA-w7vc-732c-9m39 (medium) PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=fals...
GHSA-xgmm-8j9v-c9wx (high) PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are...

Data from Homebrew/advisory-database. Run brew vulns conan@1 for a live check.

Analytics:

30 days90 days365 days
Installs2993901,708
Installs (--HEAD)001
Installs on Request2993901,708
Installs on Request (--HEAD)001
Build Errors0