Skip to content

sfetch v0.4.0

Choose a tag to compare

@github-actions github-actions released this 11 Jan 12:06

Summary

sfetch now supports arbitrary URL downloads with safety defaults, plus raw GitHub content and smart GitHub release URL upgrades.

Highlights

Arbitrary URL fetch

  • Use --url or a positional URL for generic HTTPS downloads
  • --allow-http permits HTTP only when explicitly enabled
  • Redirects are blocked unless --follow-redirects is set (limit with --max-redirects)
  • Content-type allowlist via --allowed-content-types or --allow-unknown-content-type

GitHub smart routing

  • Raw GitHub URLs (raw.githubusercontent.com) route through --github-raw
  • Release asset URLs upgrade to the release verification flow (higher trust)

Provenance and safety

  • Redirect chains recorded in provenance
  • URL credentials rejected to prevent leakage

Corpus updates

  • Expanded URL and file-format coverage with explicit HTTP allowlist cases

Documentation

  • Updated docs and README to improve awareness of v0.4.0 features including Smart URL routing, security defaults, and sfetch + shellsentry workflow

Breaking Changes

None.

Migration

Existing --repo workflows continue to work. For URL installs, switch from curl to sfetch --url or provide the URL positionally.

Examples

sfetch --url https://get.docker.com --output ./get-docker.sh
sfetch https://github.com/3leaps/sfetch/releases/download/v0.2.0/sfetch_darwin_arm64.tar.gz --dest-dir /tmp