Skip to content
v2.6.0 Release notes

A Node.js package manager

aube works with supported npm, pnpm, Yarn, and Bun lockfiles and shares installed packages across projects. Run scripts with aubr to install missing or stale dependencies before the script starts.

mise use -g aube
~/your-projectterminal

$ aubr build

Dependencies changed. Installing first…

✓ Dependencies ready

$ vite build

✓ Build complete

$ aubr build

Dependencies unchanged. Straight to your script.

$ vite build

✓ Build complete

Illustrative output showing the install check before each script run.

Migration guides

Run scripts and tools

Lockfile compatibility

aube reads and writes supported pnpm, npm, Yarn, and Bun lockfiles in place. Try it locally, review the diff, and run your tests before switching the team.

Check format compatibility

Shared package storage

Package files live in a content-addressable store. The global virtual store also shares package directory trees across local projects and worktrees.

Understand the store

Dependency build permissions

Dependency scripts need project approval or built-in trust. Explicit denies win. Optional build jails restrict approved scripts, with enforcement that depends on your OS.

Review dependency builds

Package security checks

aube checks publishing evidence, release age, and known malicious packages when selecting versions. Each check has documented defaults and exceptions.

Read the security model

Install benchmarks

Warm cache, committed lockfile, no node_modules. These are recorded results for the same fixture using each tool’s default install model.

All scenarios and methodology

Warm install · seconds · lower is better

aube0.33 s
bun0.80 s
pnpm0.61 s
npm5.71 s

aube’s global virtual store is enabled; pnpm’s is at its default of off.

MIT LicensejdxCopyright © 2026 jdx.dev