mirror of
https://github.com/buckit-io/buckit.git
synced 2026-09-11 21:39:03 +00:00
0801e31164
install-linux-binary.sh and install-mac.sh were 443 lines that differed in three places: the OS check and architecture allowlist, the platform token in the pointer URL and asset name, and clearing the macOS quarantine attribute. The other ~190 lines were identical. That duplication already cost something. Hardening the installers meant applying five fixes twice, by hand, in parallel -- pin-bypass path traversal, pipeline masking, digest normalisation, directory destination, and the cross-origin digest check. The next fix would have had the same shape, and eventually one would land in only one file. Merge them into install-binary.sh, which detects Linux or macOS and validates the architecture against what is published for that platform: Linux ships amd64 and arm64, macOS ships Apple Silicon only. The release workflow publishes it under the old names as well, so URLs already in the wild, in the docs, and in the blog post keep working and pick up the merged behaviour on every release. Nothing needs to change on the reader's side, and there is no window where a documented command 404s. Two benign consequences: install-mac.sh now also works on Linux and install-linux-binary.sh on macOS, and error messages self-identify as install-binary.sh whichever URL was fetched.