sail
Install command:
brew install sailCLI toolkit to provision and deploy WordPress applications to DigitalOcean
License: GPL-3.0-only
Development: Pull requests
Formula JSON API: /api/formula/sail.json
Formula code: sail.rb on GitHub
Bottle (binary package) installation support provided for:
| macOS on Apple Silicon |
tahoe | ✅ |
|---|---|---|
| sequoia | ✅ | |
| sonoma | ✅ | |
| macOS on Intel |
sonoma | ✅ |
| Linux | ARM64 | ✅ |
| x86_64 | ✅ | |
Current versions:
| stable | ✅ | 0.10.9 |
Revision: 2
Depends on:
| certifi | 2026.7.22 | Mozilla CA bundle for Python |
| cryptography | 50.0.0 | Cryptographic recipes and primitives for Python |
| libsodium | 1.0.22 | NaCl networking and cryptography library |
| libyaml | 0.2.5 | YAML Parser |
| python@3.14 | 3.14.7 | Interpreted, interactive, object-oriented programming language |
Depends on when building from source:
| pkgconf | 3.0.5 | Package compiler and linker metadata toolkit |
| rust | 1.98.0 | Safe, concurrent, practical language |
Known vulnerabilities in the current version:
| GHSA-9hjg-9r4m-mvj7 (medium) | Requests vulnerable to .netrc credentials leak via malicious URLs |
| GHSA-gmj6-6f8f-6699 (high) | Jinja has a sandbox breakout through malicious filenames |
| GHSA-q2x7-8rv6-6q7h (high) | Jinja has a sandbox breakout through indirect reference to format method |
| GHSA-cpwx-vrp4-4pq7 | Jinja2 vulnerable to sandbox breakout through attr filter selecting format method |
| GHSA-w853-jp5j-5j7f (medium) | filelock has a TOCTOU race condition which allows symlink attacks during lock file creation |
| GHSA-mrfv-m5wm-5w6w (medium) | libsodium has Incomplete List of Disallowed Inputs |
| GHSA-38jv-5279-wg99 (high) | Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) |
| GHSA-qmgc-5h2g-mvrw (medium) | filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock |
| GHSA-gc5v-m9x4-r6x2 (medium) | Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function |
| GHSA-r374-rxx8-8654 (low) | Paramiko rsakey.py allows the SHA-1 algorithm |
| GHSA-qccp-gfcp-xxvc (medium) | urllib3: Sensitive headers forwarded across origins in proxied low-level redirects |
| GHSA-mf9v-mfxr-j63j (high) | urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API |
| GHSA-65pc-fj4g-8rjx (medium) | Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() ... |
| PYSEC-2026-2132 (high) |
Data from Homebrew/advisory-database. Run brew vulns sail for a live check.
Analytics:
| 30 days | 90 days | 365 days | |
|---|---|---|---|
| Installs | 20 | 58 | 289 |
| Installs on Request | 20 | 58 | 289 |
| Build Errors | 0 |