github / github/spec-kit

[Enhancement] Support `.tar.gz` / `.tgz` archives for extension, preset, and workflow installation

Abierto
#2,377 1 comentario 1 reacción 2 asignados Reclamado por @mnriem Ver en GitHub
enhancement stale
Lenguaje dominante
Python
Estrellas
137k
Forks
12.3k
Merge medio
2 d 7 h
PR fusionados (30 d)
155

Descripción

## Summary

The extension, preset, and workflow download pipelines currently only support ZIP archives. Adding `.tar.gz` / `.tgz` support would broaden interoperability with package registries and artifact stores that serve tarballs natively.

## Motivation

Our catalog system is URL-based and host-agnostic — any HTTPS endpoint works. However, some widely-used registries serve tarballs rather than ZIPs:

- **npm registries** serve `.tgz` packages
- Many CI/CD pipelines produce `.tar.gz` build artifacts
- Some artifact managers default to tarball formats

This means teams using these registries currently need to repackage artifacts as ZIPs before they can be used with `specify extension add --from`, `specify preset add --from`, or `specify workflow add`.

## Proposal

Detect archive format from the `Content-Type` header or file extension and extract accordingly:

| Format | Extensions | MIME types |
|---|---|---|
| ZIP (current) | `.zip` | `application/zip` |
| Gzipped tar (new) | `.tar.gz`, `.tgz` | `application/gzip`, `application/x-gzip`, `application/x-tar+gzip` |

Affected code paths:
- `src/specify_cli/extensions.py` — `_download_and_extract()`
- `src/specify_cli/presets.py` — `_download_and_extract()`
- `src/specify_cli/workflows/catalog.py` — workflow download logic

Python's `tarfile` module is in the standard library, so no new dependencies are needed.

## Security considerations

- Apply the same path traversal protection (tar slip) as the existing zip slip checks
- Use `tarfile.data_filter` (Python 3.12+) or equivalent safe extraction to prevent symlink attacks and absolute path entries

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.