The format is really simple and powerful.
https://github.com/Homebrew/homebrew/blob/master/Library/For...
More complex example:
https://github.com/Homebrew/homebrew/blob/6a72fa26aa49ee5c2b...
Edit:
If that's the only reason you can't use homebrew just, you can just tap another cask with it in there(or whatever they are calling that process).
I try to not muck around with the base installs too much - it makes it too difficult to migrate between machines.
[1] http://brew.sh
Homebrew actually merged in 4 unique bash patches in 6 days after Shellshock broke as well, and forced all users to recompile to ensure that hole was closed on our end. The author of this article would have probably been best checking both MacPorts and Homebrew, and potentially Fink as well.
Another nice thing is they try to use the already by-default system-installed versions of libraries whenever possible -- pretty much the first thing that happens when you install any macport is it installs a gazillion dependencies that just mirror what's already on the system. (Or at least it used to be this way; keep in mind my macports knowledge is out of date!)
I also really like that in brew formulas are just ruby files, the package update mechanism is just git pull. It's also super-easy to add your own packages, and tap 3rd party sources for packages.
I do run into trouble sometimes, but it's usually easy to fix, and it happens less often than with other package managers I've used over the years.
(Sort of a taste of why it's nice: Simple things you're likely to want to do are simple:
Q. What packages do I have installed? A. "brew list"
Q. What packages are out of date? A "brew outdated"
Q. What's the homepage of package Foo? A. "brew home foo" (opens in browser)
Q. I need to modify the formula for Foo... A. "brew edit foo"
Etc.)
I wish more systems utilized FS tricks instead of proprietary DB's / manifests etc.