Automating updates to WinGet?

We had a friendly nudge in an issue on Grype today, asking for an update to the Anchore.Grype package in WinGet.

I took a look at previous updates to Anchore.Grype, and discovered Komac, which is a wonderful tool for administering packages in WinGet. It even has a macOS binary!

So I updated the Microsoft WinGet package using Komac on my work Apple Silicon Mac. It’s like cats and dogs living together!

While there, I also submitted a new package request for Syft in WinGet too!

Should we make this (WinGet publishing) part of the release process for Syft and Grype?

Also, I added an issue for Grant, because we don’t have Windows builds there (which WinGet (and thus Komac) relies on)