@graham.systems /dist-town/cli
0.5.0
all artifacts verified
dist-town/cli 0.5.0
One new command, and it's the point of the whole thing.
disttown update
The CLI now updates itself — and it does it without touching a single
dist.town service. It resolves its publisher's identity, follows the
latest pointer in their repo, fetches the release record, downloads
the artifact for your platform, and verifies it against the digest in
the signed record. If dist.town went dark tomorrow, this command would
not notice.
Before replacing anything, it tells you where the update comes from —
publisher handle and DID, version, publication time, digest — and asks.
--yes consents for automation; --check reports without acting
(exit 2 when an update is available, for scripts); --channel beta
follows a channel instead of latest.
Some behavior worth knowing:
- A yanked release is never installed. If
latestpoints at one, the updater reports no update and stays put. - If the publisher rolls
latestback to an earlier release, the updater says so plainly — a rollback is followed with your consent, never silently. - Package-managed installs (nix store, system paths) are left alone, with a pointer to the right tool.
Also
publishand the lifecycle verbs no longer write a pointer update when the pointer already targets the release — a no-op record update turned out to be something firehose consumers can choke on.
Artifacts
- disttown-linux-amd64.tar.gz
sha-256
f4eabd897f6c0ac5658ca00801e7cd51de70e0a1cf1549af42b35dcc873fee4b - disttown-linux-arm64.tar.gz
sha-256
24d840e2a153c3eb0a8d73b312ebc01d2fde72f1d6f1959cb20ab832c5e4de7c - disttown-darwin-amd64.tar.gz
sha-256
e17954b6f337c284d74401d74d55eb27a7175bd169e2ad9f3bf2439a59aa52a0 - disttown-darwin-arm64.tar.gz
sha-256
c55182dab9aefa36a994c41e38d052629ebc17333bc309f62f51a7f53f2279a8 - disttown-windows-amd64.zip
sha-256
7c320563713146d0486da8b688a3058ad18f8555b26e76ddc55f822c281bbc8a - disttown-windows-arm64.zip
sha-256
4a533cfc98b0a6b552875bd8053a25689371c41bead05e93c2a025307b58adfa