The shortest route on a Linux host: SOW ships in the Pigsty infra repository, so sow installs and upgrades with everything else the box already gets from APT or YUM. Mainland China is served by the repo.pigsty.cc mirror.
sudo tee /etc/apt/sources.list.d/pigsty-infra.list > /dev/null <<'EOF'
deb [trusted=yes] https://repo.pigsty.io/apt/infra generic main
EOF
sudo apt update
sudo apt install -y sow
sudo tee /etc/yum.repos.d/pigsty-infra.repo > /dev/null <<'EOF'
[pigsty-infra]
name=Pigsty Infra for $basearch
baseurl=https://repo.pigsty.io/yum/infra/$basearch
enabled=1
gpgcheck=0
module_hotfixes=1
EOF
sudo dnf makecache
sudo dnf install -y sow
# Same paths, different host: repo.pigsty.io -> repo.pigsty.cc
# APT
sudo sed -i 's|repo.pigsty.io|repo.pigsty.cc|' /etc/apt/sources.list.d/pigsty-infra.list
sudo apt update
# YUM
sudo sed -i 's|repo.pigsty.io|repo.pigsty.cc|' /etc/yum.repos.d/pigsty-infra.repo
sudo dnf makecache
Pinned native packages for an offline or promotion-gated pipeline. They carry the 1PGSTY release suffix, install the executable at /usr/bin/sow, and ship the Apache-2.0 licence and third-party notices.
RPM / DEB
ARCH=$(uname -m)
curl -fLO "https://github.com/pgsty/sow/releases/download/v0.5.0/sow-0.5.0-1PGSTY.$ARCH.rpm"
sudo rpm -Uvh "sow-0.5.0-1PGSTY.$ARCH.rpm"
ARCH=$(dpkg --print-architecture)
curl -fLO "https://github.com/pgsty/sow/releases/download/v0.5.0/sow_0.5.0-1PGSTY_$ARCH.deb"
sudo apt install "./sow_0.5.0-1PGSTY_$ARCH.deb"
Installer-free binaries for Linux and macOS on amd64 and arm64, for CI, for macOS workstations, and for hosts where you own the install path. Each archive holds the sow executable, README.md, CHANGELOG.md, the Apache-2.0 LICENSE, and THIRD_PARTY_NOTICES. Windows is not a release target.
# Swap linux_amd64 for linux_arm64, darwin_amd64, or darwin_arm64.
curl -fLO https://github.com/pgsty/sow/releases/download/v0.5.0/sow_0.5.0_linux_amd64.tar.gz
tar -xzf sow_0.5.0_linux_amd64.tar.gz
sudo install -m 0755 sow /usr/local/bin/sow
sow version
curl -fLO https://github.com/pgsty/sow/releases/download/v0.5.0/sow_0.5.0_darwin_arm64.tar.gz
tar -xzf sow_0.5.0_darwin_arm64.tar.gz
mkdir -p ~/.local/bin
install -m 0755 sow ~/.local/bin/sow
sow help
Build the tag yourself. The module declares Go 1.27.1, metadata generation needs no C toolchain, and these are the flags the release pipeline uses, so a source build reports the same product version as the published one.
Source
git clone https://github.com/pgsty/sow.git
cd sow
git checkout v0.5.0
CGO_ENABLED=0 go build -trimpath \
-ldflags="-s -w -X github.com/pgsty/sow/internal/v2cli.Version=0.5.0" \
-o sow ./cmd/sow
sudo install -m 0755 sow /usr/local/bin/sow
The release’s SHA256SUMS lists the exact SHA-256 digest of each archive, RPM, and DEB. Download it alongside your artifact and verify the matching entry before installation. Keep the file name and release version together.
SHA256SUMS
ASSET=sow_0.5.0_linux_amd64.tar.gz
curl -fLO https://github.com/pgsty/sow/releases/download/v0.5.0/SHA256SUMS
# Linux
grep " $ASSET$" SHA256SUMS | sha256sum -c -
# macOS
grep " $ASSET$" SHA256SUMS | shasum -a 256 -c -