Back to Skills

flox-publish

Use for publishing user packages to flox for use in Flox environments. Use for package distribution and sharing of builds defined in a flox environment.

6starsUpdated 3/10/2026

Security Assessment

Medium Risk(50/100)

Detected risks:

Remote Code Execution([SKILL.md] curl -fsSL https://downloads.flox.dev/by-env/stable/install | bash)
Security Score50/100

About flox-publish

The `flox-publish` skill provides a streamlined method for publishing software packages to the Flox ecosystem, enabling developers to distribute pre-built binaries rather than source code. It addresses the common challenge of separating development and runtime environments, ensuring that consumers of a package can use it without requiring access to build tools or the original source code. By automating the publication process and integrating with version-controlled environments, `flox-publish` simplifies package sharing, reduces errors related to environment setup, and ensures reproducible builds across different projects and teams.

Key features of `flox-publish` include support for publishing single or multiple packages, targeting either personal namespaces or organization-wide catalogs, and enforcing build validation to guarantee consistency. The skill works with `.flox/env/manifest.toml` files to define dependencies and build instructions, automatically uploading compiled binaries and package metadata to the Flox catalog. Users can authenticate via `flox auth login`, perform clean builds, and manage packages using commands like `flox publish`, `flox search`, `flox show`, and `flox install`. Published packages include all necessary runtime dependencies, version information, and artifacts generated in the build process, ensuring smooth installation and usage in other environments.

`flox-publish` is ideal for developers, DevOps engineers, and teams who need to distribute software internally or to a wider community without exposing source code. It is particularly useful for managing complex environments where multiple projects rely on the same binaries, or where reproducibility and consistency are critical. Personal namespaces allow for safe testing of packages, while organization catalogs enable shared access across teams, making it suitable for both individual contributors and collaborative workflows in production and development environments.

FAQ

How do I publish a single package using flox-publish?

Run `flox publish <package_name>` to publish a specific package. Ensure you have authenticated using `flox auth login` and that the package is defined in the `[build]` section or `.flox/pkgs/`.

Can I publish packages to an organization namespace?

Yes. Use `flox publish -o <organization_name> <package_name>` to publish a package to an organization catalog. Organization members can then install the package.

Do published packages include source code?

No. Only compiled binaries and artifacts in `$out/`, runtime dependencies, and package metadata are published. Source code is not included.

What prerequisites must be met before publishing?

The environment must be in a Git repository with a clean working tree, the current commit pushed to remote, at least one package installed, and all build files tracked by Git.

Can I test packages before publishing to the organization catalog?

Yes. Use your personal namespace with `flox publish -o <personal_handle> <package_name>` to test packages privately before sharing them with an organization.

Install flox-publish

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill