Install the Sume CLI in CI: checksums and pinned release tags

The hosted installer verifies checksums.txt and will not overwrite another sume on PATH. To pin, swap latest for a release tag such as v0.1.6.

4 min readSume
All posts

Use the direct GitHub release binary URL with a tag, such as v0.1.6, instead of latest, so CI installs the same build every run. The hosted installer verifies against checksums.txt; the docs describe the pinned form only for the direct binary fallback.

Everything here is from Install and update, read 2026-09-30.

What does the hosted installer do?

curl https://cli.sume.com/install -fsS | bash downloads the latest release binary for your OS and architecture, verifies it against checksums.txt, and installs sume under ~/.sume-com/bin. It does not silently overwrite a different sume already on your PATH.

Which binary names exist?

Release assets are named per platform, with checksums.txt attached to each GitHub Release.

Release assets from Install and update, read 2026-09-30
PlatformAsset
macOS arm64sume-darwin-arm64
macOS x64sume-darwin-x64
Linux arm64sume-linux-arm64
Linux x64sume-linux-x64
Windows x64sume-windows-x64.exe

How do I pin a version?

Replace latest in the release URL with the tag. Compare the file against checksums.txt from the same release yourself, since the manual path does not run the installer.

OS="$(uname -s | tr '[:upper:]' '[:lower:]')"
ARCH="$(uname -m | sed 's/x86_64/x64/;s/aarch64/arm64/')"
curl -fsSL "https://github.com/sumelabs/cli/releases/download/v0.1.6/sume-${OS}-${ARCH}" -o /tmp/sume
chmod +x /tmp/sume

Should CI use the hosted installer or the binary?

The installer always fetches the latest release, so a pipeline that must not change between runs should use the tagged binary URL. For local machines the hosted installer is the documented recommended path, and it protects an existing sume on your PATH from being overwritten. Windows users run the PowerShell installer from the same page.

What should CI verify after installing?

Run sume version and sume doctor --agent --json. Provide credentials through SUME_API_KEY from a secret manager; the docs call manual keys the CI and server option, not the first-run path for local users, who should run sume login.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume