github / github/spec-kit

[Enhancement] Support `.tar.gz` / `.tgz` archives for extension, preset, and workflow installation

Ouverte
#2,377 1 commentaire 1 réaction 2 personnes assignées Réclamée par @mnriem Voir sur GitHub
enhancement stale
Langage dominant
Python
Étoiles
137k
Forks
12.3k
Merge moyen
2 j 7 h
PR mergées (30 j)
155

Description

## Summary

The extension, preset, and workflow download pipelines currently only support ZIP archives. Adding `.tar.gz` / `.tgz` support would broaden interoperability with package registries and artifact stores that serve tarballs natively.

## Motivation

Our catalog system is URL-based and host-agnostic — any HTTPS endpoint works. However, some widely-used registries serve tarballs rather than ZIPs:

- **npm registries** serve `.tgz` packages
- Many CI/CD pipelines produce `.tar.gz` build artifacts
- Some artifact managers default to tarball formats

This means teams using these registries currently need to repackage artifacts as ZIPs before they can be used with `specify extension add --from`, `specify preset add --from`, or `specify workflow add`.

## Proposal

Detect archive format from the `Content-Type` header or file extension and extract accordingly:

| Format | Extensions | MIME types |
|---|---|---|
| ZIP (current) | `.zip` | `application/zip` |
| Gzipped tar (new) | `.tar.gz`, `.tgz` | `application/gzip`, `application/x-gzip`, `application/x-tar+gzip` |

Affected code paths:
- `src/specify_cli/extensions.py` — `_download_and_extract()`
- `src/specify_cli/presets.py` — `_download_and_extract()`
- `src/specify_cli/workflows/catalog.py` — workflow download logic

Python's `tarfile` module is in the standard library, so no new dependencies are needed.

## Security considerations

- Apply the same path traversal protection (tar slip) as the existing zip slip checks
- Use `tarfile.data_filter` (Python 3.12+) or equivalent safe extraction to prevent symlink attacks and absolute path entries

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.