conan@1 (deprecated)
Disable date: 2026-10-27
Install command:
brew install conan@1Distributed, open source, package manager for C/C++
License: MIT
Development: Pull requests
Formula JSON API: /api/formula/conan@1.json
Formula code: conan@1.rb on GitHub
Bottle (binary package) installation support provided for:
| macOS on Apple Silicon |
tahoe | ✅ |
|---|---|---|
| sequoia | ✅ | |
| sonoma | ✅ | |
| ventura | ✅ | |
| macOS on Intel |
sonoma | ✅ |
| ventura | ✅ | |
| Linux | ARM64 | ✅ |
| x86_64 | ✅ | |
Current versions:
| stable | ✅ | 1.66.0 |
Revision: 3
Keg-only
Depends on:
| certifi | 2026.7.22 | Mozilla CA bundle for Python |
| libyaml | 0.2.5 | YAML Parser |
| python@3.12 | 3.12.14 | Interpreted, interactive, object-oriented programming language |
Depends on when building from source:
| pkgconf | 3.0.6 | Package compiler and linker metadata toolkit |
Known vulnerabilities in the current version:
| PYSEC-2025-183 (high) | |
| GHSA-pq67-6m6q-mj2v (medium) | urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation |
| GHSA-gm62-xv2j-4w53 | urllib3 allows an unbounded number of links in the decompression chain |
| GHSA-2xpw-w6gg-jr37 | urllib3 streaming API improperly handles highly compressed data |
| GHSA-38jv-5279-wg99 (high) | Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) |
| GHSA-gc5v-m9x4-r6x2 (medium) | Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function |
| GHSA-752w-5fwx-jx9f (high) | PyJWT accepts unknown `crit` header extensions |
| GHSA-qccp-gfcp-xxvc (medium) | urllib3: Sensitive headers forwarded across origins in proxied low-level redirects |
| GHSA-5239-wwwm-4pmq (low) | Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching |
| GHSA-65pc-fj4g-8rjx (medium) | Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() ... |
| GHSA-993g-76c3-p5m4 (medium) | PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file:... |
| GHSA-jq35-7prp-9v3f (medium) | PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys |
| GHSA-fhv5-28vv-h8m8 (low) | PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) |
| GHSA-w7vc-732c-9m39 (medium) | PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=fals... |
| GHSA-xgmm-8j9v-c9wx (high) | PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are... |
Data from Homebrew/advisory-database. Run brew vulns conan@1 for a live check.
Analytics:
| 30 days | 90 days | 365 days | |
|---|---|---|---|
| Installs | 299 | 390 | 1,708 |
Installs (--HEAD) | 0 | 0 | 1 |
| Installs on Request | 299 | 390 | 1,708 |
Installs on Request (--HEAD) | 0 | 0 | 1 |
| Build Errors | 0 |