sail

Install command:
brew install sail

CLI toolkit to provision and deploy WordPress applications to DigitalOcean

https://sailed.io

License: GPL-3.0-only

Development: Pull requests

Formula JSON API: /api/formula/sail.json

Formula code: sail.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
tahoe
sequoia
sonoma
macOS on
Intel
sonoma
Linux ARM64
x86_64

Current versions:

stable 0.10.9

Revision: 2

Depends on:

certifi 2026.7.22 Mozilla CA bundle for Python
cryptography 50.0.0 Cryptographic recipes and primitives for Python
libsodium 1.0.22 NaCl networking and cryptography library
libyaml 0.2.5 YAML Parser
python@3.14 3.14.7 Interpreted, interactive, object-oriented programming language

Depends on when building from source:

pkgconf 3.0.5 Package compiler and linker metadata toolkit
rust 1.98.0 Safe, concurrent, practical language

Known vulnerabilities in the current version:

GHSA-9hjg-9r4m-mvj7 (medium) Requests vulnerable to .netrc credentials leak via malicious URLs
GHSA-gmj6-6f8f-6699 (high) Jinja has a sandbox breakout through malicious filenames
GHSA-q2x7-8rv6-6q7h (high) Jinja has a sandbox breakout through indirect reference to format method
GHSA-cpwx-vrp4-4pq7 Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
GHSA-w853-jp5j-5j7f (medium) filelock has a TOCTOU race condition which allows symlink attacks during lock file creation
GHSA-mrfv-m5wm-5w6w (medium) libsodium has Incomplete List of Disallowed Inputs
GHSA-38jv-5279-wg99 (high) Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
GHSA-qmgc-5h2g-mvrw (medium) filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock
GHSA-gc5v-m9x4-r6x2 (medium) Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
GHSA-r374-rxx8-8654 (low) Paramiko rsakey.py allows the SHA-1 algorithm
GHSA-qccp-gfcp-xxvc (medium) urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
GHSA-mf9v-mfxr-j63j (high) urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
GHSA-65pc-fj4g-8rjx (medium) Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() ...
PYSEC-2026-2132 (high)

Data from Homebrew/advisory-database. Run brew vulns sail for a live check.

Analytics:

30 days90 days365 days
Installs2058289
Installs on Request2058289
Build Errors0