# Downloads.download not working on github while OS curl does

**URL:** <https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272>\
**Category:** General Usage\
**Created:** [May 23, 2025, 11:18am UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272 "2025-05-23T11:18:06Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![disberd](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@disberd](https://discourse.julialang.org/u/disberd)\
**Post date:** [May 23, 2025, 11:18am UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/1 "2025-05-23T11:18:06Z")

</div>

Hi All,

I am facing problems downloading artifacts on a linux remote server I connect to via SSH. This is an issue that I have been facing only in the last days and I am using this server daily since months now.

This is my `versioninfo()` output:

```julia-repl
julia> versioninfo()
Julia Version 1.11.4
Commit 8561cc3d68d (2025-03-10 11:36 UTC)
Build Info:
  Official https://julialang.org/ release
Platform Info:
  OS: Linux (x86_64-linux-gnu)
  CPU: 24 × Intel(R) Xeon(R) Platinum 8462Y+
  WORD_SIZE: 64
  LLVM: libLLVM-16.0.6 (ORCJIT, haswell)
Threads: 24 default, 0 interactive, 12 GC (on 24 virtual cores)
Environment:
  JULIA_PKG_USE_CLI_GIT = true

```

I am having issues downloading the General registry (get the warning below) but this has so far not caused specific error per se.

 ![image](https://global.discourse-cdn.com/julialang/original/3X/4/d/4dae30d175046b16ad2fb1f28ff64df96ed4eb09.png)

The real error happens when trying to download artifacts, and appeared first when trying to download `XML2_jll` package via indirect dependency, triggering a similar error for both the pkgserver and the github fallback:

 ![image](https://global.discourse-cdn.com/julialang/original/3X/f/3/f37446295ec4a000e0d502db1144f47e83c14529.png)

I tried to pinpoint this issue, and I basically face the same problem when trying to directly download the tar.gz via `Downloads.download`, with the following output when doing `verbose=true`

```julia
julia> Downloads.download("https://github.com/JuliaBinaryWrappers/XML2_jll.jl/releases/download/XML2-v2.14.1+0/XML2.v2.14.1.x86_64-linux-gnu.tar.gz"; verbose = true)
* Couldn't find host github.com in the .netrc file; using defaults
* Host github.com:443 was resolved.
* IPv6: (none)               
* IPv4: 140.82.121.3
* Trying 140.82.121.3:443...
* Connected to github.com (140.82.121.3) port 443
* mbedTLS: Connecting to github.com:443
* mbedTLS: Set min SSL version to TLS 1.0
* ALPN: curl offers h2,http/1.1
* Recv failure: Connection reset by peer
* ssl_handshake returned - mbedTLS: (-0x0001) ERROR - Generic error
* Closing connection
ERROR: RequestError: Recv failure: Connection reset by peer while requesting https://github.com/JuliaBinaryWrappers/XML2_jll.jl/releases/download/XML2-v2.14.1+0/XML2.v2.14.1.x86_64-linux-gnu.tar.gz 

```

Strangely enough, when trying to directly download the same file on the shell using

```bash
curl -O -L https://github.com/JuliaBinaryWrappers/XML2_jll.jl/releases/download/XML2-v2.14.1+0/XML2.v2.14.1.x86_64-linux-gnu.tar.gz 

```

The downloads succeeds without problems.

Does anybody have any idea on how I could further investigate this issue or solve it?

---

<div class="post-metadata">

**Author:** ![disberd](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@disberd](https://discourse.julialang.org/u/disberd)\
**Post date:** [May 27, 2025, 11:49am UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/2 "2025-05-27T11:49:08Z")

</div>

I renamed the thread as the main issues seems to be really just on `Downloads.download` throwing an error on most of `https` link including github/pkg server which end up making Artifact downloads impossible on this remote machine.

I check possible previous threads with issues with `Downloads` like:

- [Julia Artifact Download Problem: How to tell Julia to follow 301-redirected downloads? - #5 by braza2](https://discourse.julialang.org/t/julia-artifact-download-problem-how-to-tell-julia-to-follow-301-redirected-downloads/82003/5)
- [BADCERT\_NOT\_TRUSTED error while updating the Registry? - #14 by oheil](https://discourse.julialang.org/t/badcert-not-trusted-error-while-updating-the-registry/119040/14)
- [How to skip certification check when using Downloads.download?](https://discourse.julialang.org/t/how-to-skip-certification-check-when-using-downloads-download/87865)

I have also seen that there used to be a way to override the _downloader_ used by julia by setting the `BINARYPROVIDER_DOWNLOAD_ENGINE` variable but this does not seem to be applicable anymore in recent julia versions.

I initially though this issue might be temporary on the server I am working on but it’s now multiple days that is going on and it’s making my julia use on this linux host very problematic as a lot of packages now directly or indirectly rely on artifacts.

Is there a way to make julia use the system’s `curl` somehow for Artifacts (and or the whole Pkg stuff?) I doubt so but maybe worth asking.

Also shamelessly pinging @StefanKarpinski directly (sorry for the bother) as I see you were often answering questions with Downloads.download issues.

---

<div class="post-metadata">

**Author:** ![GHTaarn](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ghtaarn/32/216007_2.png) [@GHTaarn](https://discourse.julialang.org/u/GHTaarn)\
**Post date:** [May 27, 2025, 1:36pm UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/3 "2025-05-27T13:36:08Z")

</div>

Do you get these problems with a completely fresh install? Specifically I am thinking of (temporarily) renaming your `~/.julia` directory, reinstalling julia (with juliaup) and unsetting `JULIA_PKG_USE_CLI_GIT` and trying to install something from `General` registry. If that doesn’t work then try installing a package with the explicit URL, e.g. `] add https://github.com/JuliaLang/Example.jl`. This will also test whether your problem will be solved by upgrading to 1.11.5

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [May 27, 2025, 2:02pm UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/4 "2025-05-27T14:02:03Z")

</div>

Some questions:

1. Is this server behind any kind of firewall or transparent proxy?
2. How did you install Julia? Is it possible it’s not using the libcurl that we ship?

---

<div class="post-metadata">

**Author:** ![disberd](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@disberd](https://discourse.julialang.org/u/disberd)\
**Post date:** [May 27, 2025, 2:42pm UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/5 "2025-05-27T14:42:03Z")

</div>

Hi, Thanks for the suggestions but I unofrtunately confirm that removing the depot and going to 1.11.5 (without OS git) does not helps on this

---

<div class="post-metadata">

**Author:** ![disberd](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@disberd](https://discourse.julialang.org/u/disberd)\
**Post date:** [May 27, 2025, 2:46pm UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/6 "2025-05-27T14:46:29Z")

</div>

Hi @StefanKarpinski,

Thanks a lot for taking the time to reply here. Regarding your questions:

1. The server is inside my company’s network and for sure there is a firewall (not sure about transaprent proxy). I don’t know the exact details on the firewall per se. I do have access to a full shell on the server itself (but without admin rights) in case there is something I can run to help clarify this better
2. I installed julia with juliaup, so I do believe libcurl should be the one shipped with julia itself. I also never had issues before 5-6 days ago and nothing else changed on my side, so I assume some policy changes on firewall happened

As a side note, I also have a bunch of packages that are hosted on a company-wide gitlab instance hosted on company infrastracture. (Which I assume is subject to same or similar firewall policies).  
Also on CI on this private gitlab instance, I do see the same problem on linux runners (but not on windows ones). And in that case I have CI jobs starting from the plain julia docker image.

Let me know if there is any command or futher investigation I might do to help diagnose the issue

---

<div class="post-metadata">

**Author:** ![disberd](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@disberd](https://discourse.julialang.org/u/disberd)\
**Post date:** [May 28, 2025, 9:34am UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/7 "2025-05-28T09:34:07Z")

</div>

A small update on this. I was able to override Pkg’s inner download function (thanks julia’s flexibility for this :D) to use the OS curl if it tries to download from [https://pkg.julialang.org/](https://pkg.julialang.org/)

I do something very cursed (as per code on [this gist](https://gist.github.com/disberd/c5a7a5e3e03e8f0d2ab451969ed84011)) which is basically overwriting the function `Pkg.PlatformEngines.download` to substitute these lines:

> <https://github.com/JuliaLang/Pkg.jl/blob/88629b552621cf8b0d5dbf3bbd5b00ecaa10d0e0/src/PlatformEngines.jl#L291-L293>

into these other lines:

```julia
try
      if startswith(url, "https://pkg.julialang.org")
          # We override the default download command with this cursed function to use the OS's curl for requests to pkg.julialang.org
          cmd = `curl -sS -L -o $dest`
          for header in headers
              key, val = header
              push!(cmd.exec, "-H", "$key: $val")
          end
          push!(cmd.exec, url)
          run(cmd)
      else
          Downloads.download(url, dest; headers, progress)
      end
finally

```

By doing this, I confirm that I can install packages and Artifacts both on the server I connect to via SSH and also within our gitlab CI runners.  
It is not pretty but at least allows me (and my colleagues) to keep working normally

I assume this means that firewall is not completely blocking links to pkgserver or github and hopefully it will be possible to find a cleaner solution for this (e.g. passing the correct parameters to `libcurl` used by `Downloads.download`)

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [May 30, 2025, 1:15pm UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/8 "2025-05-30T13:15:20Z")

</div>

So you’re only using command-line `curl` for connections to [pkg.julialang.org](http://pkg.julialang.org) and that’s sufficient to make things work?

---

<div class="post-metadata">

**Author:** ![disberd](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@disberd](https://discourse.julialang.org/u/disberd)\
**Post date:** [May 30, 2025, 2:11pm UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/9 "2025-05-30T14:11:34Z")

</div>

So far it seems, I also had to add github among things to use OS curl for as some of our internal packages artifacts are there. But for what concerns artifacts that seems to solve. It would be nice to have something cleaner though 😂

---

<div class="post-metadata">

**Author:** ![disberd](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@disberd](https://discourse.julialang.org/u/disberd)\
**Post date:** [May 31, 2025, 2:41pm UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/10 "2025-05-31T14:41:45Z")

</div>

Hi @StefanKarpinski, one small clarifications on my previous message.

So far I only modified the codepath hit by the download of artifacts only. In reality most of codes relying on `Downloads.download` will be causing an error, so I think I should actually patch `Downloads.download` on the remote machine (and gitlab CI), though I really hope to find a solution where knowing which options to pass Libcurl would actually solve this issue. Alternatively, is there a rather simple way to override `Downloads.download` to use OS curl? I guess not really.

I just tried `Downloads.download` on some random https domains on the remote server with mixed results:

```julia
using Downloads
websites = [
    "https://www.google.com",
    "https://www.github.com",
    "https://www.youtube.com",
    "https://www.wikipedia.org",
    "https://pkg.julialang.org",
    "https://gitlab.com",
    "https://www.docker.com",
    "https://www.python.org",
    "https://www.ubuntu.com",
    "https://www.rust-lang.org",
    "https://www.nodejs.org"
]
for website in websites
    outcome = try
        Downloads.download(website)
        "OK"
    catch e
        "ERROR"
    end
    println("$website: $outcome")
end

```

which prints:

```julia
https://www.google.com: OK
https://www.github.com: ERROR
https://www.youtube.com: ERROR
https://www.wikipedia.org: ERROR
https://pkg.julialang.org: ERROR
https://gitlab.com: ERROR
https://www.docker.com: OK
https://www.python.org: OK
https://www.ubuntu.com: OK
https://www.rust-lang.org: OK
https://www.nodejs.org: OK

```

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [May 31, 2025, 3:36pm UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/11 "2025-05-31T15:36:04Z")

</div>

That looks an awful lot like a firewall enforcing a site blocking policy. The question is why command-line curl works. Maybe you could ask IT for some help understanding what’s going on? You could also ask them to allow HTTPS (port 443) traffic to [julialang.org](http://julialang.org) and [julialang.net](http://julialang.net) and subdomains.

I’m fairly sure that it’s not a MITM proxy issue because that would look like invalid certificate warnings rather than connection resets. My guess is that this is blocking by site and resetting connections to sites that are not allowed. The question then is: how is the firewall distinguishing the cli curl requests which it allow, from the Julia libcurl requests, which it blocks. If you don’t want to ask IT, another way to investigate would be to fire up WireShark and look at some traces comparing requests from the cli and Julia.

---

<div class="post-metadata">

**Author:** ![disberd](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@disberd](https://discourse.julialang.org/u/disberd)\
**Post date:** [June 1, 2025, 8:33am UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/12 "2025-06-01T08:33:52Z")

</div>

Hi @StefanKarpinski,

I tried to do some more digging (mostly with help of Claude as I am not very versed in wireshark and docker which was required to use wireshark as I don’t have sudo access on the machine).

One of the first things I noticed is that libcurl was using TLS 1.3, while `download` was using a lower version.

I tried going various hoops to force this in `download` without success, and another suggestions was that maybe the issue was caused by mbedTLS (while the OS version uses OpenSSL).

I have realized that more recent version of LibCURL\_jll also switched to OpenSSL (based on the Project dependencies) and tried with julia 1.12 which indeed has a version of LibCURL which uses OpenSSL.

tried on julia 1.12 and indeed I don’t have problems with `download` there throwing errors so I guess this might be the actual issue? (Or any other modification between `LibCURL_jll@v8.6` and `LibCURL_jll@v8.11.1`).

I guess this means I should try to switch everything on the server to julia 1.12 as soon as possible.  
I guess there is no way to use OpenSSL on earlier julia versions right? Or no way to force LibCURL\_jll to use the OS curl rather than its own?

Is this something that could have been changed on my company’s firewall side? (not accepting either mbedTLS or TLS \< 1.3? Though it’s strange that some websites were still working correctly…

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [June 1, 2025, 2:29pm UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/13 "2025-06-01T14:29:16Z")

</div>

Oh that is curious. Glad it works on 1.12. If this is a legitimate issue, maybe we need to consider backporting OpenSSL usage to 1.10 since it’s the LTS release. It’s kind of a big change to backport but security fixes can be worth it.

---

<div class="post-metadata">

**Author:** ![disberd](https://avatars.discourse-cdn.com/v4/letter/d/8edcca/32.png) [@disberd](https://discourse.julialang.org/u/disberd)\
**Post date:** [June 2, 2025, 9:53am UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/14 "2025-06-02T09:53:46Z")

</div>

In the end I found that the easiest solution is to simply overwrite the LibCURL\_jll.jl entrypoint of the installed julia to put the full path of the system libcurl instead of the standard one.

This basically just boils down to substitute this line:

> <https://github.com/JuliaLang/julia/blob/760b2e5b7396f9cc0da5efce0cadd5d1974c4069/stdlib/LibCURL_jll/src/LibCURL_jll.jl#L25>

so that it points to `"/lib/x86_64-linux-gnu/libcurl.so.4"` rather than `"libcurl.so.4"` in my case.

This is very easy to do on the julia instalation for my user in the server and also very easy to do in CI.

This unfortunately does not work on julia \< 1.11, probably because before 1.11 julia will always use compiled code from the system image rather than using the contents in the source code?  
I had a quick check again at 1.11 release notes but didn’t find anything hinting at canges affecting this behavior.

I think I’ll still keep this as current solution as:

- it works on CI and ssh connections,
- is persistent (not in CI but that is not an issue),
- most of our tests can skip 1.10
- this solution also works in Pluto (as Pluto doesn’t really load startup file and would try to download packages before executing any package code, so there is no way of overriding the `download` function before it tries downloading package artifacts)

Just as extra information/curiosity on my side, is there anyway to use a different version of LibCURL\_jll or in any way to change the libcurl library used internally by julia?

Regarding assessing whether this is a legitimate issue and not really just very specific to my server’s configuration, is there anything more I can do on my side to help debugging this @StefanKarpinski?

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [June 2, 2025, 7:53pm UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/15 "2025-06-02T19:53:51Z")

</div>

> [@disberd](#):
>
> In the end I found that the easiest solution is to simply overwrite the [LibCURL\_jll.jl](https://juliaregistries.github.io/General/packages/redirect_to_repo/LibCURL_jll) entrypoint of the installed julia to put the full path of the system libcurl instead of the standard one.

@giordano Would it be possible to use the Overrides system to do this?

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [June 2, 2025, 7:55pm UTC](https://discourse.julialang.org/t/downloads-download-not-working-on-github-while-os-curl-does/129272/16 "2025-06-02T19:55:40Z")

</div>

Not for stdlibs.
