7 ms·
Gah – CLI to install software from GitHub Releases
- deleted 2y ago[deleted]
- hiatus 2y agoShould probably include "Show HN" in the title
- marverix 2y agoSorry, I will do it next time. Thank you for the comment.
- Clement_Nerma 2y agoNice! Shameless plug, I've made a similar tool recently, which uses a manifest file instead: https://github.com/ClementNerma/Fetchy https://github.com/ClementNerma/Fetchy
- marverix 2y agoFetchy is really nice! I really like the how smooth it looks in demo. Only thing that I don't like is the manifest file. Personally, I would be too lazy to create one. But I find use case for it for organizations, when you want to keep it as a code in repo, which pre-defined versions for whole organization. If, for example, you would be able to tell fetchy to use remote manifest that would be a game changer for organizations.
- Clement_Nerma 2y agoYes, Fetchy is only the base block, and I don't expect anyone to actually build their own repository. You can actually use the example one which contains a few common tools.
- darren0 2y agoSeems very similar to https://dist.sh/ https://dist.sh/ but distillery seems a bit more robust.
- drewbitt 2y agoubi https://github.com/houseabsolute/ubi https://github.com/houseabsolute/ubi is the one I know, as it is available in mise https://mise.jdx.dev/dev-tools/backends/ubi.html https://mise.jdx.dev/dev-tools/backends/ubi.html
- ekristen 2y agodist author here. since darren0 was so kind to reference my tool, I'll just add dist is written in go, is cross platform, can handle github, gitlab, homebrew packages (with caveats), and a few others and you can create custom aliases as well. there are a few additional features in the works right now. also supports signature and checksum verification if available.
- jhvkjhk 2y agoThere's also https://github.com/zyedidia/eget https://github.com/zyedidia/eget, which is also written in Go.
- 2y ago
- westurner 2y agoSoftware installers should check hashes and signatures before installing anything. Doesn't GitHub support package repositories for signed packages? https://slsa.dev/get-started https://slsa.dev/get-started explains about verifiable build provenance attestations: > SLSA 2 > To achieve SLSA 2, the goals are to: > - Run your build on a hosted platform that generates and signs provenance > - Publish the provenance to allow downstream users to verify > [...] > SLSA 3 > To achieve SLSA 3, you must: > - Run your build on a hosted platform that generates and signs provenance > - Ensure that build runs cannot influence each other > - Produce signed provenance that can be verified as authentic And: > For now, the convention is to keep the provenance attestation with your artifact. Though Sigstore is becoming more and more popular, the format of the provenance is currently tool-specific.
- nikolay 2y agoThat's what' Aqua [0] does plus more! [0]: https://aquaproj.github.io/ https://aquaproj.github.io/
- westurner 2y agoFrom https://aquaproj.github.io/ https://aquaproj.github.io/ : > aqua installs tools securely. aqua supports Checksum Verification, Policy as Code, Cosign and SLSA Provenance, GitHub Artifact Attestations, and Minisign. Please see Security.
- johnisgood 2y ago> gah is an GitHub Releases app installer, that does not require sudo ?. I am sure it does if installed to /usr or /usr/local. If installed to ~/.local, then obviously no root required. How is this a feature? Do alternatives not allow installing to custom destination path?
- combiBean 2y agoThis seems to be similar to eget: https://github.com/zyedidia/eget https://github.com/zyedidia/eget eget was developed by the same person like the micro terminal text editor.
- nikolay 2y agoI've been using Aqua [0] and I'm super happy with it! [0]: https://aquaproj.github.io/ https://aquaproj.github.io/
- cyansmoker 2y agoThis is so funny and also a commentary on my inability to perform searches in github I guess. A month ago I was looking for something like this, so I created https://github.com/fusion/gogo https://github.com/fusion/gogo Now this thread is revealing an abundance of alternate tools. I'm considering creating a "list of fetching tools" just to help folks find the one they want, since some features described here are very interesting.