About this project
cargo-binstall provides a low-complexity mechanism for installing Rust binaries as an alternative to building from source via `cargo install` or manually downloading packages. It is designed to work with existing CI artifacts and infrastructure with minimal overhead for package maintainers.
How it works: Binstall fetches crate information from crates.io, searches the linked repository for matching releases and artifacts, falls back to the quickinstall third-party artifact host, tries alternate targets as supported, and finally falls back to `cargo install` as a last resort.
Usage is similar to cargo install. For example, `cargo binstall radio-sx128x@0.14.1-alpha.5` resolves the package, downloads the binary from GitHub, lists the binaries to install, and asks for confirmation. For unattended use such as CI, the `--no-confirm` flag is available. Additional options are shown via `cargo binstall --help`.
Installation options include one-line scripts for Linux and macOS, Homebrew, a PowerShell one-liner for Windows, manual download of platform-specific archives (Linux x86_64/armv7/arm64, macOS Intel/Apple Silicon/Universal, Windows x86_64/aarch64), building from source with `cargo install cargo-binstall --locked`, and a first-party GitHub Action. The project also recommends the third-party taiki-e/install-action.
Companion tools mentioned include cargo-update, which updates all tools and uses Binstall when present, and cargo-run-bin, which scopes tools to a project and controls versions in Cargo.toml.
For unsupported crates, users can manually specify `pkg-url`, `bin-dir`, and `pkg-fmt` at the command line. Maintainers can add explicit Binstall metadata to Cargo.toml to locate the appropriate binary package for a given version and target.
Signatures: there is initial, limited support for maintainers to specify a signing public key and where to find package signatures. With this enabled, Binstall downloads and verifies signatures. `--only-signed` refuses unsigned packages, while `--skip-signatures` disables checking or downloading signatures.
Security notes: metadata is pulled from crates.io over HTTPS and the crate tar checksum is verified; HTTPS with TLS >= 1.2 is enforced for package file downloads. Unlike a `curl | sh` script, Binstall does not run arbitrary code, though the crate being installed could itself be malicious.
Telemetry: some installation strategies may collect anonymized usage statistics by default. When the quickinstall artifact host is used, the crate name, version, target platform triple, and user agent are sent to endpoints under the cargo-quickinstall-stats-server URL. Aggregated data is publicly accessible. Opt-out methods include the `--disable-telemetry` flag, the `BINSTALL_DISABLE_TELEMETRY` environment variable, disabling the quickinstall strategy, or adding `quick-install` to the `disabled-strategies` configuration key in crate metadata.
Debug symbols: extra pre-built packages with a `.full` suffix contain split debuginfo, documentation files, and extra binaries such as the `detect-wasi` utility.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.