Skip to content

sfetch v0.4.3

Choose a tag to compare

@github-actions github-actions released this 09 Feb 17:25

Summary

Windows .zip extraction fix and release DX alignment with fulseed conventions.

Highlights

Windows .zip extraction fix

  • Fixed archive format classification where the legacy archiveType: "tar.gz" default overrode the correctly-inferred .zip format from the file extension. This caused Windows .zip assets (e.g., goneat_v0.5.3_windows_amd64.zip) to be extracted with tar instead of Go's archive/zip, producing exit status 2 errors.
  • Root cause: the legacy compatibility guard in classifyAsset applied the config's archiveType even when inferArchiveFormat had already correctly determined the format from the extension.

Release DX alignment

  • Renamed SHA2-512SUMS to SHA512SUMS in release tooling (goreleaser/fulseed convention)
  • Added unified Makefile targets: release-export-keys, release-verify-keys, release-verify-signatures
  • Added release-upload-provenance target (manifests, signatures, keys only)
  • Renamed verify-release-key → release-verify-key (consistent release- prefix)
  • Renamed sign-release-assets.sh → sign-release-manifests.sh
  • Fixed upload script to handle missing signature files gracefully
  • Added scripts/verify-signatures.sh for post-sign verification
  • Bumped goneat to v0.5.3 across CI and Makefile

Breaking Changes

  • SHA2-512SUMS manifest renamed to SHA512SUMS in release artifacts. sfetch still recognizes SHA2-512SUMS from other projects.
  • Makefile targets verify-release-key and verify-minisign-pubkey renamed to release-verify-key and release-verify-minisign-pubkey.

Migration

No migration required for users. Maintainers using the release signing workflow should update their scripts to use the new target names.

Validation

  • go test ./... passes locally.
  • make precommit passes locally (tests, lint, schema validation, gosec, cross-platform build).

Examples

Install goneat on Windows via sfetch:

sfetch --repo fulmenhq/goneat --tag v0.5.3 --dest-dir .\bin --require-minisign

Update sfetch:

sfetch --self-update --yes