# Verified 2026-09-18 against the real repo: anthropics/claude-code does not # publish GitHub build-provenance attestations (the attestations API 404s # for a fresh release asset) — tier 4, same-origin checksum only, not tier # 2. Motivation: track the fast-moving Claude Code CLI directly from # upstream releases rather than npm/curl|sh. # # Releases ship a combined `SHASUMS256.txt` (one line per platform asset, # same ` ` shape as scaleway-cli's `SHA256SUMS`) plus a # detached `SHASUMS256.txt.sig` PGP signature over that checksum file — # stronger than plain same-origin-sha256 (closer to tier 1, pinned-key # signature) but pkgwatch doesn't implement PGP/minisign verification yet # (see SPEC.md > Status: tier-1 `minisign` method not yet implemented). # Revisit and upgrade this package's tier once that lands. # # Release tags are static per-platform filenames (no version embedded), so # no `{version}` placeholder is needed, same as uv's config. Tracking the # glibc x86_64 Linux build (`claude-linux-x64.tar.gz`), not the musl # variant, to match this machine. # # Archive shape doesn't match uv's or scaleway-cli's: the tarball extracts a # bare `claude` file with no wrapping directory (confirmed via `tar tzvf` # against the real v2.1.276 asset) — hence archive_binary_path below (see # builder.rs's third shape). binary_name is also set explicitly to `claude` # (the real upstream command name, not the `claude-code` package name) so # the installed binary matches what this box already invokes as `claude` # (see /opt/claude-code/bin/claude). [package.claude-code] repo = "anthropics/claude-code" asset_pattern = "claude-linux-x64.tar.gz" binary_name = "claude" archive_binary_path = "claude" [package.claude-code.verification] method = "same-origin-sha256" checksum_asset_pattern = "SHASUMS256.txt" [package.claude-code.sanity_check] command = "claude --version" version_regex = '(\d+\.\d+\.\d+) \(Claude Code\)' # The previously-installed AUR package (claude-code 2.1.273-1) shipped these # via a /usr/bin/claude wrapper around the real /opt/claude-code/bin/claude # binary — almost certainly to stop Claude Code's own self-updater from # fighting with a package manager already managing it, which applies just # as much here. builder.rs replicates that wrapper when `env` is set: real # binary under /usr/lib/claude-code/, generated /usr/bin/claude wrapper. [package.claude-code.env] DISABLE_UPDATES = "1" DISABLE_INSTALLATION_CHECKS = "1"