Arch Linux yay¶
- ID
yay- Home page
- Upstream stars
⭐ 13,674
- Last commit
2026-08-07
- Version requirement
>= 11
- Cooldown
✓
- Platforms
🅱️ BSD · 🐧 Linux · ⨂ Unix
- Operations
installed·outdated·orphans·search·install·upgrade·upgrade_all·remove·sync·cleanup·doctor- purl types
pkg:alpm·pkg:yay- CLI name
yay- Every call
yay --noconfirm --color never <command>- Issues and PRs
- Source
AUR helper wrapping pacman, driven through the yay binary.
Inherits every operation, parser and forced argument from Pacman; the
binary, version probe and the release-age cooldown below are what differ. Its
own --query --upgrades reports AUR updates on top of the official
repositories.
Unlike pacman, the helper must run as the regular user: yay warns under
root (Avoid running yay as root/sudo.) and any AUR build then dies in
makepkg, which refuses to run as root. yay drives sudo itself for the
privileged steps (its --sudo, --sudoflags and --sudoloop options),
so mpm never wraps it in sudo. That also keeps the injected
XDG_CONFIG_HOME cooldown overlay below visible to yay, where a sudo
wrap would have reset the environment.
Note
yay exposes no release-age flag, so mpm enforces the supply-chain
cooldown by
overlaying a generated init.lua through a private XDG_CONFIG_HOME (see
Yay.cooldown_env()). This needs yay >= 13.0.0, when the Lua
UpgradeSelect/AURPreInstall hooks landed; an older yay stays a usable
manager but cannot honor a cooldown. The upstream request for a less invasive
injection point is Jguer/yay#2883.
What mpm adds to yay¶
Through mpm, yay gains:
a one-command
cleanup --orphansthat removes every orphaned dependency at once--extendedsearch, to match against package descriptions
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover yay alongside pacaur, pacman, pamac, paru and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your yay commands, in mpm¶
You already know yay: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Search for a package |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
|
|
Remove a package |
|
|
List orphaned dependencies |
|
|
Clear caches |
|
|
Run health checks |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
extended search backfilled by |
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
Selecting and configuring yay¶
Deselect yay for a single run with --no-yay, or persist the choice in your configuration:
[mpm]
yay = false
The arguments and environment variables listed in the box atop this page are forced on every yay call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Keep it enabled but tune how mpm drives it with a per-manager override:
[mpm.managers.yay]
timeout = 900
mpm config-template yay prints every overridable attribute as a ready-to-paste block.
Recipes¶
A few jobs you would otherwise script around yay, one mpm command each:
Snapshot and clone a machine:
mpm --yay dump yay.toml, thenmpm restore yay.tomlon the next one.Export a compliance SBOM:
mpm --yay sbom(CycloneDX by default,--spdxfor SPDX).Gate CI on health:
mpm --yay doctorrelays Arch Linux yay’s own diagnosis and exits non-zero on trouble.
Privilege escalation¶
Arch Linux yay runs sudo from inside its own commands: mpm never wraps it, keeps an already-warm credential cache alive for those internal escalations, and warns when a mutating call goes silent on a terminal with a cold cache, since a password prompt may be hiding in the stream.
See privilege escalation for the full policy.
Concurrency¶
mpm never runs yay at the same time as pacaur, pacman, pamac, paru, pikaur or trizen: they all reach the pacman database (/var/lib/pacman/db.lck), and two of them mutating at once fail to init their transaction. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.
Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.
Cooldown¶
mpm natively enforces its release-age cooldown on Arch Linux yay, injecting the XDG_CONFIG_HOME environment variable on every call. Point it at a window (mpm --cooldown 7 --yay upgrade --all) to skip anything published in the last 7 days: a guard against a compromised or yanked fresh release landing before anyone notices.
Status: ✅ Enforced (yay ≥ 13.0)
Mechanism: generated
init.luaoverlay viaXDG_CONFIG_HOME(UpgradeSelect+AURPreInstallhooks)Reference: Jguer/yay#2883
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: AUR
Retraction: None at the version level: an AUR package is a git repository with no per-version artifact to withdraw, so remediation is a maintainer push or deletion of the whole package
Publish date: ✅ server-set
LastModified, the push timestampmpm’syayoverlay gates on. Git commit dates are client-set (GIT_COMMITTER_DATE), forgeable, and never consulted
Version probe¶
The version is probed by running:
$ yay --version
yay v11.1.2 - libalpm v13.0.1
and extracted with:
r"yay\s+v(?P<version>\S+)"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0.dev0(unreleased)Stop running the AUR helpers concurrently with
pacmanand with each other. All of them drive the same pacman database, either by shelling out tosudo pacmanor, forpamac, through Manjaro’s ownlibalpmbinding, so two mutating at once failed to init their transaction.
7.4.0(2026-07-25)The AUR helpers are no longer wrapped in
sudo: they refuse or break under root (makepkgrejects root builds, paru aborts AUR transactions, pacaur aborts its sync operations) and escalate through their own internalsudo pacmancalls, whichmpmnow tracks with theinternal_sudomarker (warm credential-cache keepalive, hidden-prompt watchdog). This also lets yay’s cooldown environment overlay reach the process, where thesudowrap used to strip it.
7.1.0(2026-07-07)Honor
--cooldownby overlaying a generatedinit.luathrough a privateXDG_CONFIG_HOME, holding back AUR upgrades and installs newer than the release-age floor while preserving the user’s own yay config. Requires yay13.0.0for its Lua hooks.
6.2.0(2026-03-25)Add
--color neveroption to all invocations.
5.3.0(2022-06-25)Run
install,upgrade,removeandcleanupoperations withsudo.
5.2.0(2022-06-16)Add
yaysupport. Refs #527.