The config Command
xget config reads and writes configuration values from the command line, in the same spirit as git config.
Table of contents
- Example configuration
- Available settings - global section
- Available settings - repository sections
- Repository and global precedence
- Source profiles
xget supports a variety of configuration options to customize its behavior. You can configure xget using a configuration file, command-line arguments, or environment variables.
For backwards compatibility with eget, xget supports both TOML and YAML configuration files. The same options are available in either format and can be layered by CLI flags, per-repository settings, and global settings.
For information on where xget looks for configuration files, see the Configuration Loading and Precedence page.
Example configuration
TOML
[global]
quiet = false
show_hash = false
upgrade_only = true
source = "github"
ignore = ["~\\.sbom\\.json$"]
target = "./test"
["zyedidia/micro"]
upgrade_only = false
show_hash = true
asset_filters = ["static", ".tar.gz"]
ignore = ["not:arm64"]
target = "~/.local/bin/micro"
YAML
global:
quiet: false
show_hash: false
upgrade_only: true
source: GitHub
ignore:
- "~\\.sbom\\.json$"
target: "./test"
"zyedidia/micro":
upgrade_only: false
show_hash: true
asset_filters:
- "static"
- ".tar.gz"
ignore:
- "not:arm64"
target: "~/.local/bin/micro"
With the configuration above, the following command downloads the latest release of micro:
xget zyedidia/micro
Without the config, you would typically need a command like:
export XGET_GITHUB_TOKEN=ghp_1234567890 && \
xget zyedidia/micro --to ~/.local/bin/micro --sha256 --asset static --asset .tar.gz
Available settings - global section
github_tokenis supported for backwards compatibility witheget, but storing a plaintext token in a config file is not recommended. Prefer source-profiletoken_envvalues or an@/path/to/tokenfile reference. File references do not produce a warning. Suppress plaintext-token warnings globally withglobal.disable_token_warning = trueor per profile withsources.PROFILE.disable_token_warning = true.
| Setting | Related Flag | Description | Default |
|---|---|---|---|
github_token | N/A | GitHub API token or @ token-file reference to use for requests | "" |
disable_token_warning | N/A | Disable warnings for plaintext tokens stored anywhere in the config. | false |
config_merge | N/A | Merge lower-priority files when this is the highest-priority config; see loading and precedence. | true |
xget_update_check | N/A | Check for a newer xget release (at most once per day, and on xget upgrade / xget list --installed --check) and print a notice when one is available. Does not affect xget self-update. | true |
all | --all | Whether to extract all candidate files. | false |
download_only | --download-only | Stop after downloading the asset without extraction. | false |
download_source | --source | Download the source code for the repo instead of a release. | false |
file | --file | Glob to select files for extraction. | * |
ignore | --ignore | Asset matchers to exclude. | [] |
pre_release | --pre-release | Include pre-releases when fetching the latest version. | false |
quiet | --quiet | Print only essential output. | false |
show_hash | --sha256 | Show the SHA-256 hash of the downloaded asset. | false |
source | --provider | Named release source profile to use. | github |
system | --system | Target system to download for. | all |
target | --to | Directory to move downloaded files to after extraction. | . |
upgrade_only | --upgrade-only | Only download if the release is newer than the current installed version. | false |
disable_ssl | --disable-ssl | Disable SSL certificate verification for downloads. | false |
Available settings - repository sections
| Setting | Related Flag | Description | Default |
|---|---|---|---|
all | --all | Extract all candidate files. | false |
asset_filters | --asset | Array of asset matchers. | [] |
binary | --binary / --name | Output file name for a single extracted file; the extension is kept. | "" |
download_only | --download-only | Stop after downloading the asset without extraction. | false |
download_source | --source | Download the source code for the repo instead of a release. | false |
file | --file | Glob to select files for extraction. | * |
ignore | --ignore | Array of asset matchers to exclude. | [] |
pre_release | --pre-release | Include pre-releases when fetching the latest version. | global value |
quiet | --quiet | Print only essential output. | false |
show_hash | --sha256 | Show the SHA-256 hash of the downloaded asset. | false |
source | --provider | Named release source profile to use. | global value |
system | --system | Target system to download for. | all |
target | --to | Directory to move downloaded files to after extraction. | . |
upgrade_only | --upgrade-only | Only download if the release is newer than the current installed version. | false |
verify_sha256 | --verify-sha256 / --verify | Verify the asset hash against a provided hash. | "" |
disable_ssl | --disable-ssl | Disable SSL certificate verification for downloads. | false |
Repository and global precedence
The precedence order is:
- CLI flags.
- Repository section values (
"owner/repo"). - Global section values (
global). - Built-in defaults.
This means the same config file can set a default target for all repositories and then override it for a single repo in a more specific section.
Source profiles
The built-in github and gitlab profiles work without configuration. Named profiles allow separate accounts, tokens, and self-hosted domains:
[sources.work]
type = "github"
host = "github.example.com"
api_url = "https://github.example.com/api/v3"
token_env = ["WORK_GITHUB_TOKEN"]
disable_token_warning = false
Available keys are type, host, api_url, token_env, token, and disable_token_warning. Token environment variables are checked in order, followed by token; GitHub profiles then fall back to legacy global.github_token. Both token settings can use @/path/to/file to read the file contents as the token; file references do not produce a warning. Stored plaintext tokens produce a warning unless disable_token_warning = true is set globally or in that profile.
Select profiles with --provider, repository source, or global source, in that order. GitLab supports nested project paths such as group/subgroup/project. Normal installs use GitLab release asset links; --source downloads a source archive and keeps its existing meaning.
As a shorthand, prefix the repository with a profile name:
xget install gitlab:gitlab-org/cli
This is equivalent to xget install gitlab-org/cli --provider gitlab. Installed metadata records gitlab-org/cli as the package and gitlab as its source. Combining the shorthand with a different --provider value is an error.
[global]
target = "~/bin"
["zyedidia/micro"]
target = "~/.local/bin"
The equivalent YAML form is:
global:
target: "~/bin"
"zyedidia/micro":
target: "~/.local/bin"
For the file lookup order and environment-variable behavior, see Configuration Loading and Precedence.