Skip to content

A curl installer: one line, no checkout, installs a release #114

Description

@Jing-yilin

Problem

The one-line install every low-friction tool in the survey has (uv, Bun, rustup, Deno, Ollama, OpenDesign) is missing. Today the nearest thing is two steps that need git and a checkout:

git clone https://github.com/ReScienceLab/super-prototyping.git ~/.super-prototyping
~/.super-prototyping/scripts/install-skills.sh

scripts/install-skills.sh then installs the toolkit from the checkout with uv or pipx, refuses if neither is present, and links skills/* into the product skill roots it finds. It cannot run from curl | sh because it needs $ROOT/tools on disk, and it installs whatever commit the clone is at rather than a release.

Alongside the Homebrew formula (#109), a curl installer is the second first-class channel: it covers Linux machines without Homebrew, macOS without Homebrew, WSL, and CI images, and it is the line the README leads with.

Proposal

A hosted install.sh at a stable URL, so the README line is:

curl -fsSL https://raw.githubusercontent.com/ReScienceLab/super-prototyping/main/install.sh | sh

(A short domain can front it later; the raw URL is enough to ship.)

What it does, in order:

  1. Detect OS and shell; refuse politely on Windows and point at A desktop shell, with a Homebrew cask and a winget id #111 (a install.ps1 comes with the desktop shell).
  2. Find or install uv. If uv is missing, run uv's own installer (https://astral.sh/uv/install.sh), which puts it in ~/.local/bin. Fall back to an existing pipx. Never sudo.
  3. Install the toolkit from the release tag's tarball, no PyPI, so there is no second registry to maintain: uv tool install "super-prototyping-tools @ https://github.com/ReScienceLab/super-prototyping/archive/refs/tags/<tag>.tar.gz#subdirectory=tools". The tag comes from the GitHub API (latest release), so the script installs a release rather than main and needs no git on the machine. --version <v> overrides.
  4. Fetch the canvas bundle for that version into $XDG_CACHE_HOME/super-prototyping/<version>/ and verify its sha256 against the .sha256 asset (Attach a prebuilt canvas bundle to every release #106). Skip when sp-canvas learns to fetch it itself (Run the canvas as a localhost app served by sp-canvas #108); until then this is what makes sp-canvas start work without Bun.
  5. Link the skills into every product skill root that exists (~/.codex/skills, ~/.codebuddy/skills, ~/.hermes/skills, ~/.pi/agent/skills, ~/.trae/skills, ~/.trae-cn/skills), from a copy of skills/ placed under $XDG_DATA_HOME/super-prototyping/<version>/, since there is no checkout to link to. Same rules as today: only touch a product that is installed, never overwrite a real directory. Claude Code keeps its marketplace command and the script says so at the end.
  6. Check PATH for ~/.local/bin and print the one line to add if it is missing.
  7. Print what was installed and where, and sp-canvas start as the next step.

Flags: --version, --tools-only, --dry-run (today's --list), --help. Idempotent: running it again upgrades or reports "already at ".

Practices to follow, from the installers surveyed

  • POSIX sh, not bash, since the URL says | sh; set -eu; every download over HTTPS with curl -fsSL and a wget fallback.
  • Download to a temp file and verify sha256 before touching anything under $HOME; never pipe a second download into sh from inside the script except uv's own installer, which is named in the output.
  • User directories only (~/.local/bin, XDG cache and data); honour SUPER_PROTOTYPING_HOME and the XDG_* variables; create directories at first write.
  • No prompts unless stdin is a TTY, so it works in CI and Dockerfiles.
  • The script is the same file for every release: it reads the version from the GitHub API, so nothing in it needs bumping.
  • scripts/install-skills.sh is retired into it, or reduced to a thin wrapper that runs the hosted script with --from-checkout for people hacking on the plugin.

Out of scope

Windows (install.ps1), a short vanity domain, and uninstall beyond sp-canvas clean (#108).

Context

Second channel next to Homebrew, ranked ahead of the tap by the maintainer. Depends on #106 (bundle and sha256 asset); becomes simpler after #108. PyPI (#107) was dropped to keep one release channel.

Sequence

#106 bundle → #114 curl installer → #108 localhost app → #109 Homebrew tap → #110 Linux → #111 desktop shell (only on demand). No PyPI: the toolkit installs from the release tag's tarball (#subdirectory=tools), so there is no second registry to maintain.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions