Skip to content

pkg 0.2.0-alpha.3

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 29 Sep 09:47
· 38 commits to main since this release
Immutable release. Only release title and notes can be modified.
v0.2.0-alpha.3
745602d

An alpha release with a Rust-generated Homebrew Cask catalog and local public tap support. Nix builds and installs the packages. No Homebrew installation is required.

Changes

  • Replace the small hand-written cask source with a generated, pinned catalog. Generic builders support eligible apps, archives, binaries, manual pages, shell completions, and direct Linux AppImages.
  • Add pkg tap add, list, update, and remove for public GitHub cask taps. The first import needs source approval. Pinned Ruby runs only during explicit imports, inside a checked Nix build sandbox.
  • Convert saved tap metadata into local Nix flakes. Package install, upgrade, history, rollback, and removal use the normal Nix profile lifecycle.
  • Add source-qualified package IDs such as cask:goreleaser/tap/mcp. Duplicate bare names produce an explicit choice instead of selecting a source silently.
  • Reject unsafe source archives, fetch destinations, payload paths, and unsupported install actions. Failed updates preserve the previous saved catalog.
  • Remove duplicate plans and raw test logs from the feature PR. Retain the verification summary and links to the recorded evidence.

Delivered in #81 and #82.

Requirements and limits

  • Supported clients: x86_64 Linux with glibc 2.35 or later, and Apple silicon macOS. Install Nix separately.
  • Public tap imports require a working strict Nix sandbox. The client checks isolation and refuses an unsafe daemon. On macOS, the daemon also needs a private build TMPDIR. The client does not change daemon settings. See the sandbox prerequisites.
  • Catalog schema 3 and source-qualified identities are a breaking change. Schema 2 catalogs are not supported by this client.
  • Support depends on each cask's metadata and payload. Formula dependencies, cask dependencies, services, drivers, fonts, and privileged/scripted installers are excluded. A metadata eligibility result is not a promise that the application will build or run.
  • Tap approval permits the source import. It does not certify the application or sandbox it after launch. Linux AppImage checks were headless; no GUI or hardware verification is claimed.

Verification

Before merge, tests covered seven public taps with 30 casks on each supported platform. Linux tests downloaded five payloads for four applications from three taps and checked real commands, upgrade, and rollback. The final independent Linux pass included 192 Rust tests, 57 fetch tests, 51 plan checks, 9 reader checks, and 762 adversarial checks. See the verification record for exact scope and limits.

The release archives also passed native version, command help, completion, file layout, license, and checksum checks on macOS and Linux. The Linux binary needs no glibc symbol newer than 2.34 (the supported baseline remains 2.35). The shipped Linux client imported goreleaser/tap at 77e442b6000587bf57e543081e95fd908b918bd7, found six eligible records, queried one package, and removed the source without downloading application payloads.

After publication, the exact tag-pinned public installer passed on both supported systems in temporary paths containing spaces. Installed client and completion bytes matched the verified release archives.

Install

Download the installer for this exact release, then run it:

curl -fsSL https://raw.githubusercontent.com/spa5k/pkg/v0.2.0-alpha.3/install.sh -o pkg-install.sh
sh pkg-install.sh

The installer verifies the client archive against SHA256SUMS. It installs the client and shell completions under ~/.local. It does not install Nix.

Installation guide · Commands · Cask and tap support