conan@1 (deprecated)

Disable date: 2026-10-27

Install command:
brew install conan@1

Distributed, open source, package manager for C/C++

https://conan.io

License: MIT

Development: Pull requests

Formula JSON API: /api/formula/conan@1.json

Formula code: conan@1.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
golden gate ✅
tahoe ✅
sequoia ✅
sonoma ✅
ventura ✅
macOS on
Intel
sonoma ✅
ventura ✅
Linux ARM64 ✅
x86_64 ✅

Current versions:

stable ✅ 1.66.0

Revision: 3

Keg-only because this is an alternate version of another formula.

Depends on:

certifi 2026.7.22 Mozilla CA bundle for Python
libyaml 0.2.5 YAML Parser
python@3.12 3.12.15 Interpreted, interactive, object-oriented programming language

Depends on when building from source:

pkgconf 3.0.7 Package compiler and linker metadata toolkit

Binaries: conan, conan_build_info, conan_server

Known vulnerabilities in the current version:

PYSEC-2025-183 (high)
GHSA-pq67-6m6q-mj2v (medium) urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
GHSA-gm62-xv2j-4w53 urllib3 allows an unbounded number of links in the decompression chain
GHSA-2xpw-w6gg-jr37 urllib3 streaming API improperly handles highly compressed data
GHSA-2gx3-rcp4-g85q (medium) PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete...
GHSA-42vr-xj54-vc7v (medium) PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_sign...
GHSA-9v7f-9g4p-ffgj (high) PyJWT: PyJWKClient follows redirects when fetching JWKS
GHSA-ffc3-869f-jxw9 (critical) PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/as...
GHSA-hxm8-2xgr-2p9m (medium) PyJWT: Non-canonical signature segments enable raw-token revocation bypass
GHSA-jwrc-g2q2-pq5p (medium) PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
GHSA-p4g4-x82p-q773 (high) PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
GHSA-w6j9-cwv2-h6wq (medium) PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
GHSA-38jv-5279-wg99 (high) Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
GHSA-gc5v-m9x4-r6x2 (medium) Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
GHSA-752w-5fwx-jx9f (high) PyJWT accepts unknown `crit` header extensions
GHSA-qccp-gfcp-xxvc (medium) urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
GHSA-5239-wwwm-4pmq (low) Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
GHSA-65pc-fj4g-8rjx (medium) Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() ...
GHSA-993g-76c3-p5m4 (medium) PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file:...
GHSA-jq35-7prp-9v3f (medium) PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
GHSA-fhv5-28vv-h8m8 (low) PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
GHSA-w7vc-732c-9m39 (medium) PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=fals...
GHSA-xgmm-8j9v-c9wx (high) PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are...
GHSA-8988-9cw3-xx77 urllib3: HTTPS proxy TLS configuration may be ignored or overridden
GHSA-vxq7-64xx-v4gw urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

Data from Homebrew/advisory-database. Run brew vulns conan@1 for a live check.

Analytics:

30 days90 days365 days
Installs544021,633
Installs on Request544021,633
Build Errors0