sudo icon indicating copy to clipboard operation
sudo copied to clipboard

Publish winget / MSI installer

Open floh96 opened this issue 1 year ago • 8 comments

Description of the new feature / enhancement

Please consider publishing sudo as an msi installer.

Scenario when this would be used?

Currently, Sudo is published through windows, and therefore it is taking months before non insider users are getting an update.

Supporting information

No response

floh96 avatar Feb 16 '24 12:02 floh96

We're working this out presently. Especially once the code is here on GitHub, there's no reason we can't just have a zip release here, so we may as well publish to winget too.

zadjii-msft avatar Feb 19 '24 16:02 zadjii-msft

Would this also mean that win10 users could benefit from this? I have several reasons as to why I'd rather not upgrade to win11 at the time and my computer at work also is locked to win10. But this would significantly help me in scenarios like this: https://github.com/microsoft/winget-cli/issues/2999#issuecomment-1958738757 Thanks!

IngwiePhoenix avatar Feb 22 '24 05:02 IngwiePhoenix

alternatively, open source the sudo code?

Kreijstal avatar Mar 05 '24 09:03 Kreijstal

@Kreijstal I mean, yea, that's the plan 😉

zadjii-msft avatar Mar 05 '24 11:03 zadjii-msft

You can download Sudo from here, it doesn't have an installer yet, but I'm working on it.

LeonardoIz avatar Jun 29 '24 19:06 LeonardoIz

Okay I definitely get that it's valuable - but I'm gonna go ahead and delete links to 3p builds of sudo. Sorry, I just think it's a terrible idea to have folks downloading builds from potentially untrusted third parties. Seems like a recipe for a supply chain vulnerability.

I'm back from vacation this week. Getting officially signed installers up on our releases page and winget is my priority this month.

zadjii-msft avatar Jul 01 '24 11:07 zadjii-msft

Okay I definitely get that it's valuable - but I'm gonna go ahead and delete links to 3p builds of sudo. Sorry, I just think it's a terrible idea to have folks downloading builds from potentially untrusted third parties. Seems like a recipe for a supply chain vulnerability.

I'm back from vacation this week. Getting officially signed installers up on our releases page and winget is my priority this month.

I understand why you say that, but the code is not modified, it is compiled by cloning the original repository, you can check the workflow file in my repository

LeonardoIz avatar Jul 01 '24 12:07 LeonardoIz