Open Source · Apache-2.0

The package manager
C++ deserves

Cargo-inspired. Git-native. Module-first.
Built for C++20 and beyond.

$ git clone https://github.com/satishbabariya/cmod.git && cd cmod && cargo build --release
terminal
# Create a new project
$ cmod init my_project
$ cd my_project

# Add dependencies — straight from Git
$ cmod add github.com/fmtlib/fmt@10.0
$ cmod add github.com/nlohmann/json@3.11

# Build and run
$ cmod build
  Resolving dependencies...
  Compiling fmt v10.2.1
  Compiling json v3.11.3
  Compiling my_project v0.1.0
  Finished in 2.4s

$ cmod run
  Hello, modern C++!
30+
CLI Commands
780+
Passing Tests
8
Focused Crates
21
Design RFCs

Everything you need.
Nothing you don't.

cmod handles dependencies, builds, caching, and security in a single, integrated tool.

Git Is Your Registry

Dependencies are Git URLs. Publishing is pushing a tag. No accounts, no approval queues, no vendor lock-in. Your repository is your package.

Modules First

Native support for C++20 modules, partitions, and BMIs. Automatic dependency discovery via clang-scan-deps. Modules compile once, not thousands of times.

Deterministic Builds

Mandatory lockfiles pin exact Git commits and toolchain versions. Build with --locked and get the same result every time, everywhere.

Fast Incremental Builds

Content-addressed caching with SHA-256 keys. Cached BMIs skip redundant work. Parallel compilation via topological sort of the module graph.

Workspace Support

Monorepo management with unified dependency resolution. Cross-member builds share BMIs and object files. One command builds everything.

Security Built In

Hash verification, trust-on-first-use, signature checking, SBOM generation, and dependency auditing. Supply chain security from day one.

IDE Integration

First-class extensions for VS Code and CLion/IntelliJ. LSP-powered diagnostics, module graph visualization, dependency tree, and build status — all built in.

Remote Cache

HTTP-based remote cache protocol for sharing build artifacts across your team. Push and pull BMIs and object files to eliminate redundant compilation.

Simple, readable config

One TOML file. No DSL to learn. No Python classes. No Starlark rules.

cmod.toml
[package]
name = "my_project"
version = "1.0.0"
edition = "2024"
license = "MIT"

[module]
name = "com.github.yourname.my_project"
root = "src/my_project.cppm"

[dependencies]
"github.com/fmtlib/fmt" = ">=10.0"
"github.com/nlohmann/json" = "^3.11"

[toolchain]
compiler = "clang"
std = "c++23"

[build]
type = "binary"

How cmod stacks up

An honest comparison with existing C++ tools.

Feature cmod CMake Conan vcpkg Bazel
C++20 Modules Native Experimental No Partial Partial
Package Management Built-in (Git) None Registry Registry Rules
Mandatory Lockfile Yes No Optional Partial Implicit
Config Format TOML CMake DSL Python JSON Starlark
Dependency Source Git URLs Manual Central server Central repo HTTP archives
Security Built-in Yes No Partial Partial Hermetic
Workspace / Monorepo Native Subdirectories No No Native
IDE Extensions VS Code + CLion CMake Tools No No Plugin
Setup Complexity Low Medium Medium-High Medium High

Read the detailed comparison →

Built in Rust. Modular by design.

8 focused crates plus IDE extensions for VS Code and CLion. Clean dependency flow from CLI down to core.

cmod-cli
↓
cmod-resolver
cmod-build
cmod-workspace
↓
cmod-cache
cmod-security
cmod-lsp
↓
cmod-core
↑
VS Code Extension
CLion Plugin
data flow
# Resolution
cmod.toml → dependency graph → cmod.lock

# Build
lockfile → module DAG → Clang invocations → artifacts

# Cache
SHA-256 key → local cache → remote cache (HTTP REST)

Where we are. Where we're going.

Phase 0
Foundations
cmod.toml parser, Git resolver, lockfile generation, CLI framework with 30+ commands
Complete
Phase 1
Build Orchestration
LLVM/Clang backend, module DAG construction, build plan IR, parallel execution
Complete
Phase 2
Scale
Workspace manager, local artifact cache, content-addressed cache keys
Complete
Phase 3
Distributed
Remote cache protocol (HTTP REST), BMI distribution, distributed build workers with work stealing
Complete
Phase 4
Security
Cryptographic signing (PGP/SSH/Sigstore), dependency auditing, SBOM generation, policy enforcement
Complete
Phase 5
Ecosystem
LSP server, plugin sandboxing, module registry, feature resolution, conditional dependencies
Complete
Phase 6
IDE & Developer Experience
VS Code extension, CLion/IntelliJ plugin, module graph visualization, format/lint-on-save, binary publishing
Complete

Ready to try modern C++ tooling?

Get started in under a minute. No accounts, no configuration files to write, no ceremony.

$ cmod init my_project && cd my_project && cmod build