# 0.153.0 for macOS: .pkg rather than .tar.gz

**URL:** <https://discourse.gohugo.io/t/0-153-0-for-macos-pkg-rather-than-tar-gz/56398>\
**Category:** support\
**Created:** [December 19, 2025, 4:50pm UTC](https://discourse.gohugo.io/t/0-153-0-for-macos-pkg-rather-than-tar-gz/56398 "2025-12-19T16:50:29Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bwintx](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/bwintx/32/10450_2.png) [@bwintx](https://discourse.gohugo.io/u/bwintx)\
**Post date:** [December 19, 2025, 4:50pm UTC](https://discourse.gohugo.io/t/0-153-0-for-macos-pkg-rather-than-tar-gz/56398/1 "2025-12-19T16:50:29Z")

</div>

I usually update my Mac’s Hugo Extended version through a shell script that looks for the appropriately named .tar.gz file — _e.g._, for 0.152.2, that was:

`hugo_extended_0.152.2_darwin-universal.tar.gz`

… but I see that, starting with 0.153.0, there instead is an actual `.pkg` file for normal macOS-style installation, apparently due to the resolution of [GH Issue #14135](https://github.com/gohugoio/hugo/issues/14135). Since Hugo is still a CLI app rather than GUI-based with (_e.g._) a “Check for Updates” menu item, what is a Best Practices way for us macOS users to handle version updates going forward? _(My GitHub Action for building my site won’t be affected because it’s still calling the Linux version.)_

---

<div class="post-metadata">

**Author:** ![ZhenShuo2021](https://avatars.discourse-cdn.com/v4/letter/z/59ef9b/32.png) [@ZhenShuo2021](https://discourse.gohugo.io/u/ZhenShuo2021)\
**Post date:** [December 19, 2025, 5:22pm UTC](https://discourse.gohugo.io/t/0-153-0-for-macos-pkg-rather-than-tar-gz/56398/2 "2025-12-19T17:22:11Z")

</div>

You could use [hvm](https://github.com/jmooring/hvm) to manage Hugo versions.

Personally, I prefer not to add another version manager, so I just [build Hugo from source](https://gohugo.io/installation/macos/#build-from-source) instead.

---

<div class="post-metadata">

**Author:** ![bep](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/bep/32/3332_2.png) [@bep](https://discourse.gohugo.io/u/bep)\
**Post date:** [December 19, 2025, 5:30pm UTC](https://discourse.gohugo.io/t/0-153-0-for-macos-pkg-rather-than-tar-gz/56398/3 "2025-12-19T17:30:42Z")

</div>

People have been asking for a signed and notarised MacOS for a long time, and since Apple has tighened the security on this (you need to manually go into the security prefs and whitelist any non-signed/notarised app, I decided it was time to do it right, and that meant either pkg or dmg, and pkg is much nicer. And I decided I didn’t want to build a double set.

Also, getting this signing/notariser thing set up was a project on its own. Jeez.

---

<div class="post-metadata">

**Author:** ![bwintx](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/bwintx/32/10450_2.png) [@bwintx](https://discourse.gohugo.io/u/bwintx)\
**Post date:** [December 19, 2025, 5:38pm UTC](https://discourse.gohugo.io/t/0-153-0-for-macos-pkg-rather-than-tar-gz/56398/4 "2025-12-19T17:38:19Z")

</div>

Oh, please don’t misunderstand, @bep — I think it’s a great idea. I’m mainly just trying to figure out how I update it locally going forward. (My old method deleted the previous version and pulled the current one, using an `xattr -dr com.apple.quarantine` command as a workaround for just the issues you mentioned.)

As for what @ZhenShuo2021 mentioned about hvm, it appears not to have been updated since a couple of months ago, so am I correct in assuming that it wouldn’t yet “know” this .pkg version of the binary? (Perhaps that’s a question for @jmooring.)

---

<div class="post-metadata">

**Author:** ![jmooring](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/jmooring/32/4214_2.png) [@jmooring](https://discourse.gohugo.io/u/jmooring)\
**Post date:** [December 19, 2025, 5:39pm UTC](https://discourse.gohugo.io/t/0-153-0-for-macos-pkg-rather-than-tar-gz/56398/5 "2025-12-19T17:39:24Z")

</div>

@bwintx Please open an issue in the hvm repo and let’s take the discussion there. Thanks.

---

<div class="post-metadata">

**Author:** ![bwintx](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/bwintx/32/10450_2.png) [@bwintx](https://discourse.gohugo.io/u/bwintx)\
**Post date:** [December 19, 2025, 5:40pm UTC](https://discourse.gohugo.io/t/0-153-0-for-macos-pkg-rather-than-tar-gz/56398/6 "2025-12-19T17:40:10Z")

</div>

Will do, @jmooring, and thanks in advance.

---

<div class="post-metadata">

**Author:** ![system](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/system/32/1_2.png) [@system](https://discourse.gohugo.io/u/system)\
**Post date:** [December 21, 2025, 5:40pm UTC](https://discourse.gohugo.io/t/0-153-0-for-macos-pkg-rather-than-tar-gz/56398/7 "2025-12-21T17:40:39Z")

</div>

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.
