Add a self-update command for the standalone PHAR - #65
Merged
Conversation
WendellAdriel
marked this pull request as ready for review
August 11, 2026 11:45
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
Standalone PHAR users have no way to update cpx short of manually downloading the latest release, while Composer-managed installs already have
composer global update. This brings the standard self-update experience every PHAR-distributed CLI ships (Composer, Laravel Zero apps) to cpx.Solution
cpx self-updatefetches the latest GitHub release, verifies the downloaded PHAR against the sha256 digest the release API publishes, smoke-runs it with--version, and then swaps the running binary in place — an atomic rename on POSIX and a copy-over on Windows, with a backup restored if the swap fails. It follows the house conventions (--jsonenvelope, Prompts output, streams-based HTTP withGITHUB_TOKENsupport) and adds zero runtime dependencies. Composer-managed installs are updated too, with a note thatcomposer global update cpx/cpxmakes it stick.Examples