sfetch v0.4.0
Summary
sfetch now supports arbitrary URL downloads with safety defaults, plus raw GitHub content and smart GitHub release URL upgrades.
Highlights
Arbitrary URL fetch
- Use
--urlor a positional URL for generic HTTPS downloads --allow-httppermits HTTP only when explicitly enabled- Redirects are blocked unless
--follow-redirectsis set (limit with--max-redirects) - Content-type allowlist via
--allowed-content-typesor--allow-unknown-content-type
GitHub smart routing
- Raw GitHub URLs (
raw.githubusercontent.com) route through--github-raw - Release asset URLs upgrade to the release verification flow (higher trust)
Provenance and safety
- Redirect chains recorded in provenance
- URL credentials rejected to prevent leakage
Corpus updates
- Expanded URL and file-format coverage with explicit HTTP allowlist cases
Documentation
- Updated docs and README to improve awareness of v0.4.0 features including Smart URL routing, security defaults, and sfetch + shellsentry workflow
Breaking Changes
None.
Migration
Existing --repo workflows continue to work. For URL installs, switch from curl to sfetch --url or provide the URL positionally.
Examples
sfetch --url https://get.docker.com --output ./get-docker.sh
sfetch https://github.com/3leaps/sfetch/releases/download/v0.2.0/sfetch_darwin_arm64.tar.gz --dest-dir /tmp