Skip to content

Install-Module from nupkg file #24

Description

@Jaykul

It would be wonderful if PowerShell supported nupkg files natively (PowerShell/PowerShell#7259), but as a stop-gap (or perhaps, as part of the implementation of that), it would be really great if Install-Module had a parameter set where we just pass the path to a .nupkg file.

In fact, it would be great if you could associate powershell -c Install-Module "%1" -scope CurrentUser with the package extension, and people could then install modules on Windows by simply right-clicking and choosing Install as PowerShell Module...

NOTE: I think it would be important to also do PowerShell/PowerShellGet#794 while you were at it, to allow modules to more easily ship with multiple platform-specific implementations

Bonus points for making up your own file extension like .psmodule so we don't have the "Install as PowerShell Module" option on all our .nupkg files...

Activity

  1. edyoung commented on Oct 2, 2018

    @edyoung

    We'd need to work out how dependencies work (search same directory only?). Also Update-Module would not know where the nupkg originally came from - seems unavoidable.

  2. bormm commented on Jul 13, 2020

    @bormm

    I think this is really relevant also for offline scenarios. We have customers with secure internal networks without any internet. It is impossible to send them the nupkg or they just download them theyself from PSGallery and installing them manually.
    I do not see why dependency is an issue here: A dependency has to be fulfilled as before. If a dependency is not installed and can't be found in the configured repos, the installation fails and the customer has to install the dependency also manually.

  3. added this to the vNext milestone on Sep 4, 2020
  4. added a commit that references this issue on Sep 26, 2023
  5. jikuja commented on May 25, 2026

    @jikuja

    Can we get an update for this?

    I would like to do following:

    Save-PsResource -AsNupkg -name foo -SkipDependencyCheck
    # or download from guthub releases
    gh attestation verify foo*.nupkg --repo org/repo
    Install-PsResource -Nupkgpath  foo*.nupkg
    

    Alternative approaches:

    $temp = ([System.IO.Path]::GetRandomFileName())
    $temp_folder = Join-Path -Path ([System.IO.Path]::GetTempPath()) -ChildPath $temp
    New-Item -Path $temp_folder -ItemType Directory > $null
    Register-PSResourceRepository -Name $temp -Uri $temp_folder -Trusted
    Copy-Item -LiteralPath ./zoo/zoo.0.0.1.nupkg -Destination $temp_folder
    Find-PSResource -Repository $temp -Name zoo
    Install-PSResource -Repository $temp -Name zoo
    Unregister-PSResourceRepository -name $temp

    or https://gist.github.com/jborean93/e0cb0e3aabeaa1701e41f2304b023366#file-install-modulenupkg-ps1-L158

    both are IMO unacceptable of the goal is to mitigate some of the SCM security issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions