Wid: My package manager project
Hi guys,
This is my package manager project. Wid, as the name implies is a Windows Downloader. My project is open-source and GPL v3 license. You can figure out the rest by experimenting. You can learn the commands by entering the “wid” command into cmd.
Repo: https://github.com/ZeSystem-Inc/wid Releases: https://github.com/ZeSystem-Inc/wid/releases


Some feedback:
You have effectively hardcoded the list of software you support, ideally you should be able to dynamically update the list, otherwise you have no way to revoke or update versions if required. And if its hardcoded, why bother network requesting for it, just build it into the binary. Would be a little larger binary, but even faster.
Meaningless, there is no dependency resolution because thats done for you by the installers.
The task you are doing is entirely IO bound, rusts performance is irrelevant.
Actually, it’s not static. I’m updating the package list.
It is static. Please stop, it’s embarrassing.
The URL is static. The content is dynamic because I update the Gist. That’s how Gist works.
And it’s a very bad and dangerous idea, I’ll leave it as an exercice to the reader.
Updating the gist gives a new URL no?
I think you should use wid. I already use my own download tool. It’s better than winget, choco, and ninite.
Better is a wild claim.
You’re right, gists do seem to update with the static url, however that isnt necessarily better, it now means your gist is effectively under your control, and you can replace the installers with malware packed ones. Operating a software repository/installer requires that people trust you, and that is basically impossible for a no-name dev with no history.
You ideally should be doing checksum checks as well.
I use official links and check versions.
Sure, you might today, but tomorrow? How can anyone trust that you wont start serving malicious links?
It’s open source. Anyone can audit it. You can create your own sources.list, but if you distribute it, you must open the code. Also, “wid info <package_name>” shows the exact URL it downloads from. Example: wid info llvm shows the official GitHub release link.
Thats how it works in theory, but in practice it comes down to trust more than anything else.
Its more effort to read and validate your list than it is to just go and download the installer directly. So you need people to trust you.
No, when I edit the gist, the URL doesn’t change. There are 32 packages right now. I’ve just added Epic Games. I use GitHub Gist.
Actually, I have a Gist for this that you can use. I update the Gist from time to time. In fact, the
sources.listfile can be customized specifically.The point is that you pinned a specific commit instead of a branch like
mainAnd yeah calling dependency resolution fragile is weird. It is not an actual package manager, just a download tool.
I already use tags for releases. The commit hash is for development. You can check the releases page.