Repository navigation
pkg 0.2.0-alpha.3
Pre-releaseAn alpha release with a Rust-generated Homebrew Cask catalog and local public tap support. Nix builds and installs the packages. No Homebrew installation is required.
Changes
- Replace the small hand-written cask source with a generated, pinned catalog. Generic builders support eligible apps, archives, binaries, manual pages, shell completions, and direct Linux AppImages.
- Add
pkg tap add,list,update, andremovefor public GitHub cask taps. The first import needs source approval. Pinned Ruby runs only during explicit imports, inside a checked Nix build sandbox. - Convert saved tap metadata into local Nix flakes. Package install, upgrade, history, rollback, and removal use the normal Nix profile lifecycle.
- Add source-qualified package IDs such as
cask:goreleaser/tap/mcp. Duplicate bare names produce an explicit choice instead of selecting a source silently. - Reject unsafe source archives, fetch destinations, payload paths, and unsupported install actions. Failed updates preserve the previous saved catalog.
- Remove duplicate plans and raw test logs from the feature PR. Retain the verification summary and links to the recorded evidence.
Requirements and limits
- Supported clients: x86_64 Linux with glibc 2.35 or later, and Apple silicon macOS. Install Nix separately.
- Public tap imports require a working strict Nix sandbox. The client checks isolation and refuses an unsafe daemon. On macOS, the daemon also needs a private build
TMPDIR. The client does not change daemon settings. See the sandbox prerequisites. - Catalog schema 3 and source-qualified identities are a breaking change. Schema 2 catalogs are not supported by this client.
- Support depends on each cask's metadata and payload. Formula dependencies, cask dependencies, services, drivers, fonts, and privileged/scripted installers are excluded. A metadata eligibility result is not a promise that the application will build or run.
- Tap approval permits the source import. It does not certify the application or sandbox it after launch. Linux AppImage checks were headless; no GUI or hardware verification is claimed.
Verification
Before merge, tests covered seven public taps with 30 casks on each supported platform. Linux tests downloaded five payloads for four applications from three taps and checked real commands, upgrade, and rollback. The final independent Linux pass included 192 Rust tests, 57 fetch tests, 51 plan checks, 9 reader checks, and 762 adversarial checks. See the verification record for exact scope and limits.
The release archives also passed native version, command help, completion, file layout, license, and checksum checks on macOS and Linux. The Linux binary needs no glibc symbol newer than 2.34 (the supported baseline remains 2.35). The shipped Linux client imported goreleaser/tap at 77e442b6000587bf57e543081e95fd908b918bd7, found six eligible records, queried one package, and removed the source without downloading application payloads.
After publication, the exact tag-pinned public installer passed on both supported systems in temporary paths containing spaces. Installed client and completion bytes matched the verified release archives.
Install
Download the installer for this exact release, then run it:
curl -fsSL https://raw.githubusercontent.com/spa5k/pkg/v0.2.0-alpha.3/install.sh -o pkg-install.sh
sh pkg-install.shThe installer verifies the client archive against SHA256SUMS. It installs the client and shell completions under ~/.local. It does not install Nix.