Install the Sume CLI in CI: checksums and pinned release tags
The hosted installer verifies checksums.txt and will not overwrite another sume on PATH. To pin, swap latest for a release tag such as v0.1.6.

Use the direct GitHub release binary URL with a tag, such as v0.1.6, instead of latest, so CI installs the same build every run. The hosted installer verifies against checksums.txt; the docs describe the pinned form only for the direct binary fallback.
Everything here is from Install and update, read 2026-09-30.
What does the hosted installer do?
curl https://cli.sume.com/install -fsS | bash downloads the latest release binary for your OS and architecture, verifies it against checksums.txt, and installs sume under ~/.sume-com/bin. It does not silently overwrite a different sume already on your PATH.
Which binary names exist?
Release assets are named per platform, with checksums.txt attached to each GitHub Release.
| Platform | Asset |
|---|---|
| macOS arm64 | sume-darwin-arm64 |
| macOS x64 | sume-darwin-x64 |
| Linux arm64 | sume-linux-arm64 |
| Linux x64 | sume-linux-x64 |
| Windows x64 | sume-windows-x64.exe |
How do I pin a version?
Replace latest in the release URL with the tag. Compare the file against checksums.txt from the same release yourself, since the manual path does not run the installer.
OS="$(uname -s | tr '[:upper:]' '[:lower:]')"
ARCH="$(uname -m | sed 's/x86_64/x64/;s/aarch64/arm64/')"
curl -fsSL "https://github.com/sumelabs/cli/releases/download/v0.1.6/sume-${OS}-${ARCH}" -o /tmp/sume
chmod +x /tmp/sumeShould CI use the hosted installer or the binary?
The installer always fetches the latest release, so a pipeline that must not change between runs should use the tagged binary URL. For local machines the hosted installer is the documented recommended path, and it protects an existing sume on your PATH from being overwritten. Windows users run the PowerShell installer from the same page.
What should CI verify after installing?
Run sume version and sume doctor --agent --json. Provide credentials through SUME_API_KEY from a secret manager; the docs call manual keys the CI and server option, not the first-run path for local users, who should run sume login.
Sources
Related posts
More in Developers
- sume jobs watch timed out: recover the job before you resubmit
A local wait that times out does not cancel a paid Sume job. Inspect it with jobs status, events and result, then download, instead of submitting again.
- sume/video-1.0 and /v1/models/sume/video-1.0/runs: what they are
Video 1.0 is a retiring alias for Video Router Auto. Two URLs take the same body, the public id is sume/video-1.0, and receipts report sume/auto.
- Join voiceover clips inside one timeline render with audio.parts
Timeline 1.0 takes up to 20 gapless audio.parts slices with source_in and duration. Skip the timeline-audio job when the join is only for one render.
- Timeline 1.0 limits: 200 slots, 1800 s, 20 audio parts, 8 fades
The numbers that cap one Timeline 1.0 render: 1 to 200 video slots, 1 to 1800 s of audio, 20 audio parts, 12-slot single strategy and 8 chained fades.
Written by Sume