# \[SOLVED\] cmake.org availability (was: HTTP 403)

**URL:** https://discourse.cmake.org/t/solved-cmake-org-availability-was-http-403/15833
**Category:** Site Feedback
**Created:** [September 16, 2026, 6:38am UTC](https://discourse.cmake.org/t/solved-cmake-org-availability-was-http-403/15833 "2026-09-16T06:38:05Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![w124513](https://discourse.cmake.org/letter_avatar_proxy/v4/letter/w/cab0a1/32.png) [@w124513](https://discourse.cmake.org/u/w124513)
#### Post date: [September 16, 2026, 6:38am UTC](https://discourse.cmake.org/t/solved-cmake-org-availability-was-http-403/15833/1 "2026-09-16T06:38:06Z")

</div>

Hi there,

apparently the CMake Homepage ([cmake.org](http://cmake.org) - some documentation sub-spaces seem to work, like [https://cmake.org/cmake/help/latest/module/FetchContent.html](https://cmake.org/cmake/help/latest/module/FetchContent.html)) is somehow unavailable (pages return HTTP 403). Could you give a short feedback on whether this is a short term issue or might take some more time to get fixed?

Maybe there is just a redirection missing or something as some links seem to be redirecting to [cmake.org/documentation](http://cmake.org/documentation) but that also returns 403.

KR

---

<div class="post-metadata">

### Author: ![sebjames](https://discourse.cmake.org/letter_avatar_proxy/v4/letter/s/f1d935/32.png) [@sebjames](https://discourse.cmake.org/u/sebjames)
#### Post date: [September 16, 2026, 12:33pm UTC](https://discourse.cmake.org/t/solved-cmake-org-availability-was-http-403/15833/2 "2026-09-16T12:33:34Z")

</div>

This is a me-too. It matters to me because my github actions download the latest cmake from [cmake.org](http://cmake.org) before running, so all my CI is currently failing.

---

<div class="post-metadata">

### Author: ![w124513](https://discourse.cmake.org/letter_avatar_proxy/v4/letter/w/cab0a1/32.png) [@w124513](https://discourse.cmake.org/u/w124513)
#### Post date: [September 16, 2026, 3:18pm UTC](https://discourse.cmake.org/t/solved-cmake-org-availability-was-http-403/15833/3 "2026-09-16T15:18:04Z")

</div>

Seem to be up again.

Thank you, Kitware/CMake Team!

---

<div class="post-metadata">

### Author: ![Aiden.Woodruff](https://discourse.cmake.org/user_avatar/discourse.cmake.org/aiden.woodruff/32/6177_2.png) [@Aiden.Woodruff](https://discourse.cmake.org/u/Aiden.Woodruff)
#### Post date: [September 16, 2026, 6:42pm UTC](https://discourse.cmake.org/t/solved-cmake-org-availability-was-http-403/15833/4 "2026-09-16T18:42:59Z")

</div>

Hello,

Sorry about the main pages being unavailable earlier. We were subject to a massive DoS attack at [cmake.org](http://cmake.org) over the past couple of days, and we have adjusted our server configuration. Please let us know if you are getting 403 error codes again, and thank you for the patience while we fixed this.

---

<div class="post-metadata">

### Author: ![craig.scott](https://discourse.cmake.org/user_avatar/discourse.cmake.org/craig.scott/32/20_2.png) [@craig.scott](https://discourse.cmake.org/u/craig.scott)
#### Post date: [September 16, 2026, 9:55pm UTC](https://discourse.cmake.org/t/solved-cmake-org-availability-was-http-403/15833/5 "2026-09-16T21:55:57Z")

</div>

It is not recommended to have CI jobs download from [cmake.org](http://cmake.org), you should download the [releases from GitHub](https://github.com/Kitware/cmake/releases) instead. That’s where the links on the [cmake.org/download](http://cmake.org/download) page point to anyway, so there’s no reason to go via [cmake.org](http://cmake.org) for installation.

If you’re installing cmake as an apt package, note that the Kitware apt servers aren’t really meant for CI hammering them either. I don’t have the link handy, but it has been stated previously that the Kitware apt servers are intended only for desktop users. CI jobs should go directly to GitHub instead and download official releases from there.

---

<div class="post-metadata">

### Author: ![brad.king](https://discourse.cmake.org/user_avatar/discourse.cmake.org/brad.king/32/11_2.png) [@brad.king](https://discourse.cmake.org/u/brad.king)
#### Post date: [September 17, 2026, 12:27pm UTC](https://discourse.cmake.org/t/solved-cmake-org-availability-was-http-403/15833/6 "2026-09-17T12:27:24Z")

</div>

> [@craig.scott](#):
>
> it has been stated previously that the Kitware apt servers are intended only for desktop users

The instructions on [https://apt.kitware.com/](https://apt.kitware.com/) state:

> This repository is intended for developers to install packages on their own machines. Please do not use this apt repository in CI jobs. Our official [release](https://github.com/Kitware/CMake/releases) binaries are hosted by GitHub’s CDN.

---

<div class="post-metadata">

### Author: ![sebjames](https://discourse.cmake.org/letter_avatar_proxy/v4/letter/s/f1d935/32.png) [@sebjames](https://discourse.cmake.org/u/sebjames)
#### Post date: [September 17, 2026, 1:12pm UTC](https://discourse.cmake.org/t/solved-cmake-org-availability-was-http-403/15833/7 "2026-09-17T13:12:21Z")

</div>

Thanks for the advice. I was using this github action:

> **[GitHub - ssrobins/install-cmake: GitHub Action for installing the wonderful build...](https://github.com/ssrobins/install-cmake)**
>
> GitHub Action for installing the wonderful build tool, CMake

The ssrobins/install-cmake README explains how it works:

_The determination of the latest release and release candidate is done with a web scraping of [https://cmake.org/download/](https://cmake.org/download/). Then, it’s downloaded from [https://github.com/Kitware/CMake/releases](https://github.com/Kitware/CMake/releases) using the established naming pattern_

I _think_ that sounds ok, unless you’d also prefer that script not to contact [cmake.org](http://cmake.org) to read the releases page?

---

<div class="post-metadata">

### Author: ![brad.king](https://discourse.cmake.org/user_avatar/discourse.cmake.org/brad.king/32/11_2.png) [@brad.king](https://discourse.cmake.org/u/brad.king)
#### Post date: [September 17, 2026, 1:17pm UTC](https://discourse.cmake.org/t/solved-cmake-org-availability-was-http-403/15833/8 "2026-09-17T13:17:32Z")

</div>

> [@sebjames](#):
>
> determination of the latest release and release candidate is done with a web scraping of [https://cmake.org/download/](https://cmake.org/download/).

There is no need to do such scraping. We provide [this URL](https://cmake.org/files/LatestRelease/cmake-latest-files-v1.json) to programmatically identify the latest release. One would still need to contact `cmake.org`, but only to download one small JSON document.

---

<div class="post-metadata">

### Author: ![craig.scott](https://discourse.cmake.org/user_avatar/discourse.cmake.org/craig.scott/32/20_2.png) [@craig.scott](https://discourse.cmake.org/u/craig.scott)
#### Post date: [September 17, 2026, 8:45pm UTC](https://discourse.cmake.org/t/solved-cmake-org-availability-was-http-403/15833/9 "2026-09-17T20:45:27Z")

</div>

A fair while back, I created this [get\_cmake](https://github.com/Crascit/get_cmake/blob/main/get_cmake.bash) script that essentially does what you need for Linux and macOS. By default, it only contacts GitHub and doesn’t need to grab the latest release details from `cmake.org`, it works that out exclusively from the GitHub releases on its own. That removes `cmake.org `as a point of failure. It may be useful to see how the various pieces of logic can be implemented. I haven’t looked at it or used it myself in some time now, but I believe it should still work.
