Skip to content

Installation

gotpm ships as a single static binary. There is no runtime to install and no Go toolchain needed unless you build it yourself.

Unix

Homebrew:

# Short form
brew install npikall/tap/gotpm

# Long form
brew tap npikall/tap && brew install gotpm

Shell:

curl -sSfL https://github.com/npikall/gotpm/releases/latest/download/install.sh | sh

Windows

powershell -ExecutionPolicy ByPass -c "irm https://github.com/npikall/gotpm/releases/latest/download/install.ps1 | iex"

Install with Go

go install github.com/npikall/gotpm@latest

Download Binary

Download the Binary from GitHub Releases and place it in your $PATH

Verify a Release

Every release's checksums.txt is signed keylessly with cosign, tying it to the exact release.yml GitHub Actions run that built it. Verify a downloaded binary against it:

# Download checksums.txt and its signature bundle alongside the binary, then:
cosign verify-blob \
  --bundle checksums.txt.sigstore.json \
  --certificate-identity-regexp "^https://github.com/npikall/gotpm/\.github/workflows/release\.yml@refs/tags/.*$" \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  checksums.txt

# Then confirm the binary matches the (now-verified) checksum:
sha256sum -c checksums.txt --ignore-missing

Build from Source

git clone https://github.com/npikall/gotpm.git
cd gotpm
task install # or read the Taskfile.yml to do build and install manually

Verifying the install

$ gotpm self version

gotpm self update fetches the latest release from GitHub and replaces the running binary in place — useful when you installed from the shell script or a release download. Package-manager installs are better updated through the package manager that placed them.

Where gotpm puts things

Nothing is written until a command needs it. gotpm locate prints every path gotpm reads or writes, including the ones that do not exist yet:

$ gotpm locate

The one that matters most is packages: the package directory the Typst compiler resolves imports from. It is shared with Typst itself and with anything else that installs there.

Shell completion

Cobra's completion command is available for the common shells:

$ gotpm completion zsh > "${fpath[1]}/_gotpm"
$ gotpm completion bash > /etc/bash_completion.d/gotpm
$ gotpm completion fish > ~/.config/fish/completions/gotpm.fish