-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy pathinstall.sh
More file actions
179 lines (151 loc) · 5.1 KB
/
Copy pathinstall.sh
File metadata and controls
179 lines (151 loc) · 5.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
#!/bin/sh
# Preflight CLI Installer
# Usage: curl -sSL https://preflight.sh/install.sh | sh
set -e
REPO="preflightsh/preflight"
INSTALL_DIR="/usr/local/bin"
BINARY_NAME="preflight"
# Optional: pin a specific release by setting PREFLIGHT_VERSION (e.g. v0.15.1).
PREFLIGHT_VERSION="${PREFLIGHT_VERSION:-}"
# Colors
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
NC='\033[0m' # No Color
info() {
printf "${GREEN}[INFO]${NC} %s\n" "$1"
}
warn() {
printf "${YELLOW}[WARN]${NC} %s\n" "$1"
}
error() {
printf "${RED}[ERROR]${NC} %s\n" "$1"
exit 1
}
# Detect OS
detect_os() {
case "$(uname -s)" in
Linux*) echo "linux";;
Darwin*) echo "darwin";;
MINGW*|MSYS*|CYGWIN*) echo "windows";;
*) error "Unsupported operating system: $(uname -s)";;
esac
}
# Detect architecture
detect_arch() {
case "$(uname -m)" in
x86_64|amd64) echo "amd64";;
arm64|aarch64) echo "arm64";;
*) error "Unsupported architecture: $(uname -m)";;
esac
}
# Get latest version from GitHub
get_latest_version() {
curl -sSL "https://api.github.com/repos/${REPO}/releases/latest" | \
grep '"tag_name":' | \
sed -E 's/.*"([^"]+)".*/\1/'
}
# Download and install
install() {
OS=$(detect_os)
ARCH=$(detect_arch)
info "Detected OS: ${OS}, Arch: ${ARCH}"
if [ -n "$PREFLIGHT_VERSION" ]; then
VERSION="$PREFLIGHT_VERSION"
info "Using pinned version: ${VERSION}"
else
VERSION=$(get_latest_version)
if [ -z "$VERSION" ]; then
error "Could not determine latest version"
fi
info "Latest version: ${VERSION}"
fi
# The version string ends up in URLs and the archive filename; reject
# anything that isn't a plain semver tag so a malformed or hostile API
# response can't smuggle paths or shell metacharacters into them.
case "$VERSION" in
v[0-9]*.[0-9]*.[0-9]* | [0-9]*.[0-9]*.[0-9]*) ;;
*) error "Unexpected version format: ${VERSION}";;
esac
case "$VERSION" in
*[!A-Za-z0-9.-]*) error "Unexpected version format: ${VERSION}";;
esac
# Build download URL
FILENAME="preflight_${VERSION#v}_${OS}_${ARCH}.tar.gz"
if [ "$OS" = "windows" ]; then
FILENAME="preflight_${VERSION#v}_${OS}_${ARCH}.zip"
fi
DOWNLOAD_URL="https://github.com/${REPO}/releases/download/${VERSION}/${FILENAME}"
info "Downloading from: ${DOWNLOAD_URL}"
# Create temp directory
TMP_DIR=$(mktemp -d)
trap 'rm -rf "$TMP_DIR"' EXIT
# Download binary and checksums (checksums are mandatory).
curl -fsSL "${DOWNLOAD_URL}" -o "${TMP_DIR}/${FILENAME}"
CHECKSUMS_URL="https://github.com/${REPO}/releases/download/${VERSION}/checksums.txt"
curl -fsSL "${CHECKSUMS_URL}" -o "${TMP_DIR}/checksums.txt" \
|| error "Could not download checksums file from ${CHECKSUMS_URL}"
# Verify checksum (hard fail if anything is missing).
cd "${TMP_DIR}"
expected=$(grep -F "${FILENAME}" checksums.txt | awk '{print $1}' | head -n 1)
if [ -z "$expected" ]; then
error "No checksum entry for ${FILENAME} in checksums.txt"
fi
case "$expected" in
*[!a-f0-9]*) error "Malformed checksum entry for ${FILENAME}";;
esac
if [ "${#expected}" -ne 64 ]; then
error "Malformed checksum entry for ${FILENAME}"
fi
if command -v sha256sum >/dev/null 2>&1; then
actual=$(sha256sum "${FILENAME}" | awk '{print $1}')
elif command -v shasum >/dev/null 2>&1; then
actual=$(shasum -a 256 "${FILENAME}" | awk '{print $1}')
else
error "sha256sum or shasum is required to verify the download"
fi
if [ "$actual" != "$expected" ]; then
error "Checksum verification failed! Expected: ${expected}, Got: ${actual}"
fi
info "Checksum verified"
# Extract
cd "${TMP_DIR}"
if [ "$OS" = "windows" ]; then
unzip -q "${FILENAME}"
else
tar -xzf "${FILENAME}"
fi
# Set the mode while we still own the file. When the temp dir is on a
# different filesystem (tmpfs), a sudo mv copies and the result is
# root-owned, so a chmod after the move fails and set -e aborts the
# script after the install already succeeded.
chmod +x "${BINARY_NAME}"
# Install
if [ -w "${INSTALL_DIR}" ]; then
mv "${BINARY_NAME}" "${INSTALL_DIR}/${BINARY_NAME}"
else
info "Requesting sudo access to install to ${INSTALL_DIR}"
sudo mv "${BINARY_NAME}" "${INSTALL_DIR}/${BINARY_NAME}"
fi
info "Installed ${BINARY_NAME} to ${INSTALL_DIR}/${BINARY_NAME}"
info "Run 'preflight --help' to get started"
}
# Main
main() {
echo ""
echo " ✈️ Preflight CLI Installer"
echo ""
# Check for required tools
command -v curl >/dev/null 2>&1 || error "curl is required but not installed"
command -v tar >/dev/null 2>&1 || error "tar is required but not installed"
install
echo ""
printf "${GREEN}Installation complete!${NC}\n"
echo ""
echo " Get started:"
echo " cd your-project"
echo " preflight init"
echo " preflight scan"
echo ""
}
main