[SOLVED] cmake.org availability (was: HTTP 403)

Hi there,

apparently the CMake Homepage (cmake.org - some documentation sub-spaces seem to work, like https://cmake.org/cmake/help/latest/module/FetchContent.html) is somehow unavailable (pages return HTTP 403). Could you give a short feedback on whether this is a short term issue or might take some more time to get fixed?

Maybe there is just a redirection missing or something as some links seem to be redirecting to cmake.org/documentation but that also returns 403.

KR

1 Like

This is a me-too. It matters to me because my github actions download the latest cmake from cmake.org before running, so all my CI is currently failing.

Seem to be up again.

Thank you, Kitware/CMake Team!

Hello,

Sorry about the main pages being unavailable earlier. We were subject to a massive DoS attack at cmake.org over the past couple of days, and we have adjusted our server configuration. Please let us know if you are getting 403 error codes again, and thank you for the patience while we fixed this.

1 Like

It is not recommended to have CI jobs download from cmake.org, you should download the releases from GitHub instead. That’s where the links on the cmake.org/download page point to anyway, so there’s no reason to go via cmake.org for installation.

If you’re installing cmake as an apt package, note that the Kitware apt servers aren’t really meant for CI hammering them either. I don’t have the link handy, but it has been stated previously that the Kitware apt servers are intended only for desktop users. CI jobs should go directly to GitHub instead and download official releases from there.

The instructions on https://apt.kitware.com/ state:

This repository is intended for developers to install packages on their own machines. Please do not use this apt repository in CI jobs. Our official release binaries are hosted by GitHub’s CDN.

1 Like

Thanks for the advice. I was using this github action:

The ssrobins/install-cmake README explains how it works:

The determination of the latest release and release candidate is done with a web scraping of https://cmake.org/download/. Then, it’s downloaded from https://github.com/Kitware/CMake/releases using the established naming pattern

I think that sounds ok, unless you’d also prefer that script not to contact cmake.org to read the releases page?

There is no need to do such scraping. We provide this URL to programmatically identify the latest release. One would still need to contact cmake.org, but only to download one small JSON document.

1 Like

A fair while back, I created this get_cmake script that essentially does what you need for Linux and macOS. By default, it only contacts GitHub and doesn’t need to grab the latest release details from cmake.org, it works that out exclusively from the GitHub releases on its own. That removes cmake.org as a point of failure. It may be useful to see how the various pieces of logic can be implemented. I haven’t looked at it or used it myself in some time now, but I believe it should still work.