Expand description
isb update: replace the running isb with a release from GitHub.
The release’s SHA256SUMS must carry a signature (SHA256SUMS.sig) by a
release key compiled into isb; the tarball for this build’s target is then
checked against it, unpacked next to the running binary (so the final
rename stays on one filesystem and is atomic), smoke-tested with
--version, and renamed over it. A binary a package manager owns is left
to that manager: replacing it underneath mise, cargo, npm or pip leaves
their records lying about what is installed. mise installs are
deprecated: mise does not check the release signature, so isb points them
at INSTALL_COMMAND instead.
Enums§
- Manager
- A package manager that owns an installed isb.
Constants§
- CURRENT
- The version of this build.
- INSTALL_
COMMAND - The installer: it checks the release signature as
isb updatedoes and installs to~/.local/bin, whereisb updatekeeps isb current. - RELEASE_
KEYS - Ed25519 public keys (hex) that sign each release’s SHA256SUMS. The signature is SHA256SUMS.sig, 64 raw bytes; the private key is the repo secret ISB_RELEASE_SIGNING_KEY (master copy in the maintainers’ vault). A list, so a new key can ship in a release before the old one retires.
Functions§
- current_
exe - The running binary’s real path (symlinks resolved, so the file replaced is the one that runs, not the link to it).
- host_
target - The release target this build matches, as the release assets name it.
- install
- Download
versionfortargetand atomically replaceexewith it. - is_
newer - Whether
ais a newer version thanb. Versions are compared by their numericMAJOR.MINOR.PATCH; anything that does not parse is never newer. - latest_
version - The latest published release’s version, without the leading
v. - normalize
v1.2.3and1.2.3both mean1.2.3.- release_
asset - The release asset name (without
.tar.gz) for a version and target. - verify_
sums - Whether
sigis a release key’s signature ofsums.