sfetch v0.4.3
Summary
Windows .zip extraction fix and release DX alignment with fulseed conventions.
Highlights
Windows .zip extraction fix
- Fixed archive format classification where the legacy
archiveType: "tar.gz"default overrode the correctly-inferred.zipformat from the file extension. This caused Windows.zipassets (e.g.,goneat_v0.5.3_windows_amd64.zip) to be extracted withtarinstead of Go'sarchive/zip, producingexit status 2errors. - Root cause: the legacy compatibility guard in
classifyAssetapplied the config'sarchiveTypeeven wheninferArchiveFormathad already correctly determined the format from the extension.
Release DX alignment
- Renamed
SHA2-512SUMStoSHA512SUMSin release tooling (goreleaser/fulseed convention) - Added unified Makefile targets:
release-export-keys,release-verify-keys,release-verify-signatures - Added
release-upload-provenancetarget (manifests, signatures, keys only) - Renamed
verify-release-key→release-verify-key(consistentrelease-prefix) - Renamed
sign-release-assets.sh→sign-release-manifests.sh - Fixed upload script to handle missing signature files gracefully
- Added
scripts/verify-signatures.shfor post-sign verification - Bumped goneat to v0.5.3 across CI and Makefile
Breaking Changes
SHA2-512SUMSmanifest renamed toSHA512SUMSin release artifacts. sfetch still recognizesSHA2-512SUMSfrom other projects.- Makefile targets
verify-release-keyandverify-minisign-pubkeyrenamed torelease-verify-keyandrelease-verify-minisign-pubkey.
Migration
No migration required for users. Maintainers using the release signing workflow should update their scripts to use the new target names.
Validation
go test ./...passes locally.make precommitpasses locally (tests, lint, schema validation, gosec, cross-platform build).
Examples
Install goneat on Windows via sfetch:
sfetch --repo fulmenhq/goneat --tag v0.5.3 --dest-dir .\bin --require-minisignUpdate sfetch:
sfetch --self-update --yes