"curl -sL https://asciinema.org/install | sh"
Still a cool product!
"curl -sL https://asciinema.org/install | sh"
Still a cool product!
At the moment there are native packages for Ubuntu/Debian (ppa) and Fedora/CentOS (in core repo). There's also homebrew package and Arch Linux one (aur). There are 2 nice guys who maintain the first two packages, doing great job, but it always takes time until the packages are ready (we're all doing it in our spare time, and there's process, especially Fedora case, which you can't skip). I maintain Arch Linux one (while not using Arch for more than few years now) but this one's usually ready on the release day.
There are no packages for other distros, but we'll never be able to provide ones for all distros (unless we're very popular project with lots of contributors). That's fine.
But there are also situations like this: https://bugs.gentoo.org/show_bug.cgi?id=532918 Let's not get into "Go packaging" discussion again, but what you can see in the mentioned Gentoo thread there's always some problem (no vendoring is bad, vendoring is bad). Sure, these guys do this too in their spare time and they don't owe me anything.
But when seeing this I'm like "oh boy, packaging is hard, I don't have time for dealing with this". So time (or lack of thereof) is one thing. Next thing is: "apt-get install asciinema" or "brew install asciinema" is awesome because it uses your software package manager and it's a single command. For all other distros (and people wanting new version right now) you can curl/sh which is equally easy. "First download this script, then review it, then run it" is not that hard but most people wouldn't review the script anyway, and those who would are the ones who are doing that now anyway. curl/sh sucks on many fronts but I made sure the script doesn't get executed when partially downloaded and it's not "| sudo sh".
I'm thinking about using one of these services which auto-build deb/rpm, they host them as apt/yum repos etc. There are few of them out there so if anyone can point me to any "proven/reliable" one I'd appreciate that. Any suggestions on the topic are welcome!
https://github.com/jordansissel/fpm
I didn't use the build system heavily and it may be more overhead than you'd like but I thought it was a pretty neat way of doing things. Repo is here:
Once you agree to install software, it had local access with your accounts privileges.
and SSL has nothing to do with it. packages are not cryptographically signed either and once on the system can easily become root.
{ # Prevent execution if this script was only partially downloaded
# installation code here
} # End of wrapping
I'm not sure if this is a bulletproof solution.Put it in ~/opt with xstow, and add ~/opt/bin to your path, ~/opt/man to your man-path, ~/opt/include, ~/opt/lib... to the various paths.
In this case, it seems like a lot of effort to get a tgz-archive just to download a single executable. I gather it's distributed as an archive in order for the Changelog, Readme and License to be available -- but as it's all downloaded from github anyway, it's hard to see why that really matters (rather than just have -h spit out a link or two).
As, if you're using a normal, full-featured web browser, there's no way of knowing if what you select, is what you copy and then paste -- it would probably be better to just link directly to the latest binary release for the various platforms (linux32, linux64, linux-arm, OSX 32bit, OSX 64bit) -- and let the user save the binary somewhere.
Limit the "command line instructions" to:
go get github.com/asciinema/asciinema
rather than fighting idiomatic go practices.If you really want to be clever, why not just use 0install?
hashpipe does exactly that:
Eh? Both debs and rpms can be signed with GPG keys.
rm -rf /$INSTALLER_TEMP_DIRSeriously - you pretty much just have to make a .dep and a .rpm and you're covered. Is that so hard?
Author already did that [1] and has both .deb and .rpm: