Skip to content

Install script improvements #656

Description

@davidpanic

The current install script has bogus requirements of bash and shasum. Because of the way it is written the script runs fine with sh and sha1sum.

This should be fixed because some environments, for example the Alpine Linux docker image, do not have them.
If you are checking for curl and wget, you should also check for sha1sum (or better yet use sha256sum).

The hard requirement on bash is just unneeded.

The requirements can easily be bypassed by just faking the environment, proving my point:

cat <(echo "BASH_VERSION=fake; function shasum() { sha1sum $@; }") <(wget -O- https://carvel.dev/install.sh) | sh

Activity

  1. 100mik commented on Jun 19, 2023

    @100mik
    Contributor

    This would actually be true for all the tools so we should probably move this issue

  2. transferred this issue fromcarvel-dev/ytton Jun 19, 2023
  3. added
    enhancementThis issue is a feature request
    good first issueAn issue that will be a good candidate for a new contributor
    priority/awaiting-more-evidenceLowest priority. Possibly useful, but not yet enough support to actually get it done.
    and removed
    carvel triageThis issue has not yet been reviewed for validity
    on Jun 19, 2023
  4. 100mik commented on Jun 19, 2023

    @100mik
    Contributor

    Thanks for bringing this up! The ask is reasonable, but I believe we should see if folks run into this often.
    If this is a recurring pain point then we would be open to working towards a solution 🙏🏼

  5. moved this to Unprioritized in Carvelon Jun 20, 2023
  6. moved this from Unprioritized to Prioritized Backlog in Carvelon Jun 20, 2023
  7. added
    priority/important-longtermImportant over the long term, but may not be staffed and/or may need multiple releases to complete.
    and removed
    priority/awaiting-more-evidenceLowest priority. Possibly useful, but not yet enough support to actually get it done.
    on Jun 20, 2023
  8. Kiran-pro2001 commented on Apr 30, 2024

    @Kiran-pro2001

    Can I work on this project!

  9. praveenrewar commented on May 7, 2024

    @praveenrewar
    Member

    @Kiran-pro2001 Sure! Feel free to raise a PR.

  10. joaopapereira commented on May 24, 2024

    @joaopapereira
    Member

    As a matter of fact, the script is autogenerated from the template in https://github.com/carvel-dev/release-scripts/blob/main/scripts/install_sh/install.sh.txt, so any change should be done there.

  11. Ghanasree commented on Nov 8, 2024

    @Ghanasree

    Hey! Can I work on this Issue?

  12. joaopapereira commented on Nov 8, 2024

    @joaopapereira
    Member

    The PR #785 was created against this repo and I asked @Jenil1905 to create it in the https://github.com/carvel-dev/release-scripts repository. Was not sure if the answer was "no, I will not do it" or "no, I do not mind creating the PR in that repo" 😄
    Nevertheless I am open to any of you 2 to create a PR in that repository and I will review it.

  13. Watrdguy commented on Jul 26, 2025

    @Watrdguy

    carvel-dev/release-scripts#44
    Does this work? This is my first time contributing in a real project and I will be very interested in knowing my mistakes(which I am sure are many).

  14. Shruti2110-coder commented on Oct 10, 2025

    @Shruti2110-coder

    can i work on this issue

  15. Mishradity commented on Oct 12, 2025

    @Mishradity

    Can you assign this issue , i will try my best to fix this

  16. joaopapereira commented on Oct 13, 2025

    @joaopapereira
    Member

    Given that @Watrdguy can yll instead review carvel-dev/release-scripts#44 and validate it to make sure it works?

  17. AnupmaMishra12 commented on Dec 2, 2025

    @AnupmaMishra12

    can i work on this issue

  18. joaopapereira commented on Dec 4, 2025

    @joaopapereira
    Member

    Yes do not forget that the change needs to happen in the other repository

  19. Xynash commented on Feb 6, 2026

    @Xynash

    Hi, I checked the current install.sh.txt template. It looks like it’s already POSIX-compatible and supports sha1sum / sha256sum fallbacks. Please let me know if there’s any other portability issue I could help with.

  20. joaopapereira commented on Feb 7, 2026

    @joaopapereira
    Member

    I think that the main issue was that we had sha256sum there but if the way it works not is good I am ok closing this issue

  21. Divahar2507 commented on Sep 29, 2026

    @Divahar2507

    can i wrk on this project

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementThis issue is a feature requestgood first issueAn issue that will be a good candidate for a new contributorpriority/important-longtermImportant over the long term, but may not be staffed and/or may need multiple releases to complete.

    Type

    No type

    Projects

    • Status
      Prioritized Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions