steamship 0.8.1

Install

steamship is one binary for Windows, Linux and macOS. Install it with your package manager, or download a release and check its signature yourself. Either way, it sets up the steamcmd it needs the first time it runs.

Homebrew

On macOS and Linux:

brew tap aureliolo/steamship https://github.com/Aureliolo/steamship
brew install aureliolo/steamship/steamship

Scoop

On Windows, straight from the latest release:

scoop install https://github.com/Aureliolo/steamship/releases/latest/download/steamship.json

or with this repository as a bucket, which scoop update then follows:

scoop bucket add aureliolo https://github.com/Aureliolo/steamship
scoop install aureliolo/steamship

winget

On Windows:

winget install Aureliolo.steamship

Homebrew, Scoop and winget install the release's archive only if it matches the SHA-256 the release is signed over.

Debian, Ubuntu and Fedora

On x86-64 Linux, the release's .deb or .rpm:

# Debian and Ubuntu
curl -fLO https://github.com/Aureliolo/steamship/releases/download/v0.8.1/steamship_0.8.1-1_amd64.deb
sudo apt install ./steamship_0.8.1-1_amd64.deb
# Fedora
sudo dnf install https://github.com/Aureliolo/steamship/releases/download/v0.8.1/steamship-0.8.1-1.x86_64.rpm

Each brings the 32-bit C libraries Valve's steamcmd for Linux loads and the certificates it checks Steam against, and carries a man page per command and tab completion for bash, zsh and fish. Check one as Verifying a download shows, with the package's name in place of the archive's.

Installed any other way on Linux, steamship needs those too: lib32gcc-s1 and ca-certificates on Debian and Ubuntu, glibc.i686, libgcc.i686 and ca-certificates on Fedora, lib32-gcc-libs and ca-certificates on Arch. Most systems have the certificates already; a minimal container may not.

Cargo

Anywhere Rust runs, built from source in a few minutes:

cargo install --locked steamship

With cargo-binstall, a Cargo add-on installed separately, the release's own archive instead, in seconds:

cargo binstall steamship

A release archive

Each release carries an archive for each system, with its checksum and signature. The Linux binary is linked statically, so it runs on any x86-64 Linux, whatever its glibc. These are steamship 0.8.1's:

SystemArchive
Linux x86-64steamship-0.8.1-x86_64-linux-musl.tar.gz
macOS Apple siliconsteamship-0.8.1-aarch64-apple-darwin.tar.gz
macOS Intelsteamship-0.8.1-x86_64-apple-darwin.tar.gz
Windows x86-64steamship-0.8.1-x86_64-pc-windows-msvc.zip
Windows on Armsteamship-0.8.1-aarch64-pc-windows-msvc.zip

From a terminal, the Linux one with curl, wget or the GitHub command line:

curl -fLO https://github.com/Aureliolo/steamship/releases/download/v0.8.1/steamship-0.8.1-x86_64-linux-musl.tar.gz
wget https://github.com/Aureliolo/steamship/releases/download/v0.8.1/steamship-0.8.1-x86_64-linux-musl.tar.gz
gh release download v0.8.1 --repo Aureliolo/steamship --pattern '*linux-musl*'

Check it, then put steamship on your PATH.

Verifying a download

with the GitHub command line, gh
VERSION=X.Y.Z
ARCHIVE=steamship-${VERSION}-x86_64-linux-musl.tar.gz
gh release download "v${VERSION}" --repo Aureliolo/steamship
sha256sum -c "${ARCHIVE}.sha256"
gh attestation verify "${ARCHIVE}" --repo Aureliolo/steamship \
  --bundle "steamship-${VERSION}.intoto.jsonl" \
  --signer-workflow Aureliolo/steamship/.github/workflows/release-build.yml \
  --source-ref "refs/tags/v${VERSION}" \
  --deny-self-hosted-runners

The checksum proves the bytes are the ones the release lists. The attestation proves GitHub Actions built them from this repository, by the steps in release-build.yml at that tag, on a GitHub-hosted runner, which a checksum cannot: a checksum made beside a tampered archive agrees with it perfectly. Every release also carries an SPDX SBOM of its five binaries, attested against each archive in the same file.

Tab completion

Homebrew installs tab completion for bash, zsh and fish, and man steamship. Anywhere else, steamship prints it for your shell to load:

steamship completions bash > ~/.local/share/bash-completion/completions/steamship
steamship completions zsh > "${fpath[1]}/_steamship"
steamship completions fish > ~/.config/fish/completions/steamship.fish
steamship completions powershell >> $PROFILE

Each release archive also carries them in completions/, and a man page for every command in man/.

Upgrading

Upgrade the way you installed:

brew upgrade steamship
scoop update steamship
winget upgrade Aureliolo.steamship
cargo install --locked steamship
cargo binstall steamship

or download the archive from the latest release again. Once a day, at a terminal, steamship asks GitHub whether a newer release is out; when one is, it says so after the command, with the command that upgrades the way you installed. It never asks in CI, or with STEAMSHIP_NO_UPDATE_CHECK set.

steamcmd

steamship runs Valve's own steamcmd, and installs it itself. The first login or upload fetches it from Valve's signed package manifest at the version this steamship release pins, checks every package's SHA-256, and on Windows Valve's code signature too. steamcmd is kept from updating itself, and its files are checked again after every run: one that changed stops steamship with exit code 4.

steamship install does it ahead of time, as in CI, and verifies an install that is already there.

Valve keeps old steamcmd builds on its CDN for years, then deletes them. An install already made keeps working after that; a new one fails, saying that Valve no longer serves the pinned steamcmd and how to upgrade to a steamship that pins one it does.

steamcmd, its login token and the build output live in steamship's home, a per-user folder unless STEAMSHIP_HOME names another. The token can do everything the build account may, so treat that folder like a password.