# What and why: Downloading artifact Zlib, Bzip2, MbedTLS

**URL:** <https://discourse.julialang.org/t/what-and-why-downloading-artifact-zlib-bzip2-mbedtls/37044>\
**Category:** Juno\
**Created:** [April 4, 2020, 11:15pm UTC](https://discourse.julialang.org/t/what-and-why-downloading-artifact-zlib-bzip2-mbedtls/37044 "2020-04-04T23:15:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jaynick](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@jaynick](https://discourse.julialang.org/u/jaynick)\
**Post date:** [April 4, 2020, 11:15pm UTC](https://discourse.julialang.org/t/what-and-why-downloading-artifact-zlib-bzip2-mbedtls/37044/1 "2020-04-04T23:15:53Z")

</div>

At some companies one have to get permission to download software, and it’s a major effort. Thus, it’s necessary to identify the set of packages needed.  
(In fact at my previous company, cloning git repos was simply blocked - there was no way to use julia, period).

I downloaded all the necessary packages including Atom+Juno.

But then in Running Juno, it tries `Downloading artifact` of Zlib, Bzip2, MbedTLS.

What is `Downloading artifact`? Shouldn’t that occur when the package is built()?

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [April 5, 2020, 9:34am UTC](https://discourse.julialang.org/t/what-and-why-downloading-artifact-zlib-bzip2-mbedtls/37044/2 "2020-04-05T09:34:28Z")

</div>

Artifacts are explained in this [excellent blog post](https://julialang.org/blog/2019/11/artifacts/).

---

<div class="post-metadata">

**Author:** ![jaynick](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@jaynick](https://discourse.julialang.org/u/jaynick)\
**Post date:** [April 5, 2020, 11:42pm UTC](https://discourse.julialang.org/t/what-and-why-downloading-artifact-zlib-bzip2-mbedtls/37044/3 "2020-04-05T23:42:23Z")

</div>

looks like a good well thought-out design, like most of Julia

except that it further increases the need to download random things at unpredictable times, which is a problem in corporate environment.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [April 6, 2020, 6:00am UTC](https://discourse.julialang.org/t/what-and-why-downloading-artifact-zlib-bzip2-mbedtls/37044/4 "2020-04-06T06:00:05Z")

</div>

Perhaps you misunderstood some things. Artifacts are not “random things”: they come from well-specified sources and are verified:

> Note that each artifact contains both a `git-tree-sha1` and a `sha256` for each download entry. This is to ensure that the downloaded tarball is secure before attempting to unpack it, as well as enforcing that all tarballs must expand to the same overall tree hash.

Also, of course they are not downloaded at “unpredictable times”, but only when you add/update packages. Julia will not start downloading artifacts without the user initiating it.
