Skip to content

About

Static cURL with latest features

Topics

Resources

Stars

504 stars

Watchers

6 watching

Forks

Repository files navigation

Static cURL with latest features for Linux, macOS, and Windows

Static cURL binary built with the latest features, such as ECH, HTTP3, brotli, and zstd.

The script will automatically retrieve the latest version of each component.
Simply execute it to compile the most recent version.

Included components

curl -V

  • Protocols: dict file ftp ftps gopher gophers http https imap imaps ipfs ipns mqtt mqtts pop3 pop3s rtsp scp sftp smb smbs smtp smtps telnet tftp ws wss
  • Features: alt-svc asyn-rr AsynchDNS brotli ECH HSTS HTTP2 HTTP3 HTTPS-proxy HTTPSRR IDN IPv6 Largefile libz NTLM PSL SSL SSLS-EXPORT threadsafe TLS-SRP UnixSockets zstd

Usage

Download the latest release from the Releases page.
Extract the archive and use it.
The binary is built with GitHub Actions.

Release files

Starting from cURL 8.20.0, all builds use OpenSSL 4.x with ECH support enabled by default.
For older releases (before 8.20.0), two versions were provided: one with ECH support and one without.

  • curl-linux-ARCH-musl-VERSION: binaries for Linux, linked with musl
  • curl-linux-ARCH-glibc-VERSION: binaries for Linux, linked with glibc, these binaries may have compatibility issues in certain system environments
  • curl-linux-ARCH-dev-VERSION: binaries, headers and static library archives for Linux, linked with musl(after curl v8.2.1)
  • curl-macOS-ARCH-VERSION: binaries for macOS
  • curl-macOS-ARCH-dev-VERSION: binaries, headers and static library archives for macOS
  • curl-windows-ARCH-VERSION: binaries for Windows
  • curl-windows-ARCH-dev-VERSION: binaries, headers and library archives for Windows

Known issue

For Linux glibc versions, if your system’s /etc/nsswitch.conf file is configured with passwd: compat, glibc will attempt to load libnss_compat.so, libnss_nis.so, libpthread.so, etc. These libraries may not be compatible with the statically linked glibc, and the program might crash.
Currently, there is no good solution for this issue, except for compiling glibc within the script.
In this case, it is recommended to use the musl version.

Compile

This script utilizes clang(glibc) and qbt-musl-cross-make(musl) for cross-compilation on Linux, mstorsjo/llvm-mingw for cross-compilation for Windows, providing support for the following architectures:

  • Linux
    • x86_64
    • aarch64
    • armv7
    • armv5
    • i686
    • riscv64
    • s390x
    • mips64
    • mips64el
    • mips
    • mipsel
    • powerpc64le
    • powerpc
    • loongarch64
  • macOS
    • x86_64
    • aarch64
  • Windows
    • x86_64
    • aarch64
    • i686
    • armv7

How to compile

Linux

  • Install Docker, clone this Git repository, navigate to the repository directory, and then execute the following command:
    sh curl-static-cross.sh
    The script will create a container and compile the host architecture cURL only.

supported architectures

  • ARCHES: "x86_64 aarch64 armv7 armv5 riscv64 s390x mips64 mips64el mips mipsel powerpc64le powerpc i686 loongarch64"

  • If you need to specify more parameters, run:

    docker run --network host --rm -v $(pwd):/mnt -w /mnt \
        --name "build-curl-$(date +%Y%m%d-%H%M)" \
        -e ARCHES="x86_64 aarch64 armv7 armv5 riscv64 s390x mips64 mips64el mips mipsel powerpc64le powerpc i686 loongarch64" \
        -e TLS_LIB="openssl" \
        -e LIBC="glibc" \
        -e QBT_MUSL_CROSS_MAKE_VERSION="" \
        -e CURL_VERSION="" \
        -e OPENSSL_VERSION="" \
        -e NGTCP2_VERSION="" \
        -e NGHTTP3_VERSION="" \
        -e NGHTTP2_VERSION="" \
        -e ZLIB_LIB="zlib-ng" \
        -e ZLIB_VERSION="" \
        -e ZLIB_NG_VERSION="" \
        -e LIBUNISTRING_VERSION="" \
        -e LIBIDN2_VERSION="" \
        -e LIBPSL_VERSION="" \
        -e ARES_VERSION="" \
        -e ENABLE_TRURL="true" \
        -e TRURL_VERSION="" \
        debian:latest sh curl-static-cross.sh

macOS

Run the following command to compile:

ARCHES="x86_64 arm64" \
    TLS_LIB=openssl \
    CURL_VERSION="" \
    OPENSSL_VERSION="" \
    NGTCP2_VERSION="" \
    NGHTTP3_VERSION="" \
    NGHTTP2_VERSION="" \
    LIBIDN2_VERSION="" \
    LIBUNISTRING_VERSION="" \
    ZLIB_LIB="zlib-ng" \
    ZLIB_VERSION="" \
    ZLIB_NG_VERSION="" \
    BROTLI_VERSION="" \
    ZSTD_VERSION="" \
    LIBSSH2_VERSION="" \
    LIBPSL_VERSION="" \
    ARES_VERSION="" \
    bash curl-static-mac.sh

Windows

  • Install Docker, clone this Git repository, navigate to the repository directory, and then execute the following command:
    ARCHES="x86_64 i686 aarch64 armv7" sh curl-static-win.sh
    script will create a Linux container and cross-compile cURL via LLVM MinGW toolchain.

  • If you need to specify more parameters, run:

    docker run --network host --rm -v $(pwd):/mnt -w /mnt \
        --name "build-curl-$(date +%Y%m%d-%H%M)" \
        -e ARCHES="x86_64 i686 aarch64 armv7" \
        -e TLS_LIB="openssl" \
        -e CURL_VERSION="" \
        -e OPENSSL_VERSION="" \
        -e NGTCP2_VERSION="" \
        -e NGHTTP3_VERSION="" \
        -e NGHTTP2_VERSION="" \
        -e ZLIB_LIB="zlib-ng" \
        -e ZLIB_VERSION="" \
        -e ZLIB_NG_VERSION="" \
        -e LIBUNISTRING_VERSION="" \
        -e LIBIDN2_VERSION="" \
        -e LIBPSL_VERSION="" \
        -e ARES_VERSION="" \
        -e ENABLE_TRURL="true" \
        -e TRURL_VERSION="" \
        mstorsjo/llvm-mingw:latest sh curl-static-win.sh

Environment Variables

Supported Environment Variables list:
For all VERSION variables, leaving them blank will automatically fetch the latest version.

  • ARCHES: The list of architectures to compile. You can set one or multiple architectures from the following options: Compile
  • TLS_LIB: The TLS library. Only openssl for now.
  • LIBC: The libc. glibc(default) or musl, only affects Linux.
  • QBT_MUSL_CROSS_MAKE_VERSION: The version of qbt-musl-cross-make, only affects musl. Check the releases on qbt-musl-cross-make/releases
  • CURL_VERSION: The version of cURL. If set to dev, will fetch the latest source code of branch master from GitHub.
  • OPENSSL_VERSION: The version of OpenSSL. If set to dev, will fetch the branch OPENSSL_BRANCH from GitHub.
  • OPENSSL_BRANCH: The branch that fetch from GitHub, this variable will be ignored if OPENSSL_VERSION is not set to dev.
  • NGTCP2_VERSION: The version of ngtcp2.
  • NGHTTP3_VERSION: The version of nghttp3.
  • NGHTTP2_VERSION: The version of nghttp2.
  • LIBUNISTRING_VERSION: The version of libunistring.
  • LIBIDN2_VERSION: The version of libidn2.
  • LIBSSH2_VERSION: The version of libssh2.
  • ZLIB_LIB: The zlib library. zlib-ng(default) or zlib. zlib-ng is built in zlib compatible mode (ZLIB_COMPAT=ON) as a drop-in replacement for zlib, with runtime CPU detection for SIMD optimizations.
  • ZLIB_VERSION: The version of zlib, only affects ZLIB_LIB=zlib.
  • ZLIB_NG_VERSION: The version of zlib-ng, only affects ZLIB_LIB=zlib-ng.
  • BROTLI_VERSION: The version of brotli.
  • ZSTD_VERSION: The version of zstd.
  • LIBPSL_VERSION: The version of libpsl.
  • ARES_VERSION: The version of c-ares.
  • TRURL_VERSION: The version of trurl.
  • ENABLE_TRURL: Compile trurl. The default value is false, set it to true to enable. NOT available for macOS.
  • ENABLE_DEBUG: Enable curl debugging. The default value is false, set it to true to enable. This setting appends --enable-debug to the curl compilation options.

The compiled files will be saved in the current release directory.

Important Changes

ECH enabled by default (cURL >= 8.20.0)

  • All builds now use OpenSSL 4.x with ECH (Encrypted Client Hello) enabled by default, so there is only one build variant per platform.
  • The ENABLE_ECH variable has been removed.
  • For older releases (cURL < 8.20.0), two variants were provided (with and without ECH). OpenSSL 3.x can still be selected via OPENSSL_VERSION for compatibility.

Embedded CA certificates

  • The curl.se CA bundle (cacert.pem, checksum-verified at build time) is embedded into every binary via --with-ca-embed.
  • The binaries no longer depend on a CA file path from the build machine (e.g. Debian's /etc/ssl/certs/ca-certificates.crt), so HTTPS works out of the box on any distro, even without a system CA bundle.
  • Windows builds no longer ship a separate curl-ca-bundle.crt file; they use the same embedded bundle.
  • cacert.pem is included in each dev package, and its SHA256 is recorded in the release notes.
  • You can still override the trust store at runtime with --cacert / --capath or the CURL_CA_BUNDLE / SSL_CERT_FILE environment variables.

zlib-ng by default

  • zlib-ng replaces zlib by default, providing faster gzip/deflate compression and decompression with SIMD optimizations (SSE/AVX, NEON, etc.) selected at runtime based on the CPU.
  • It is built in zlib compatible mode (ZLIB_COMPAT=ON), so curl -V reports it as zlib/x.y.z.zlib-ng, and the dev package still provides libz.a and zlib.h.
  • Set ZLIB_LIB=zlib to build with the original zlib instead.

Platform-specific features

  • Windows: built with --enable-sspi and --enable-windows-unicode (SSPI authentication and Unicode file names/arguments).
  • macOS: built with --with-apple-sectrust and --enable-ca-native, so certificates can also be verified via the Apple Security framework / system keychain.

Other changes

  • No more Insufficient randomness errors: OpenSSL is now built with a private openssldir (/opt/static-curl/ssl) instead of /etc/ssl, so it no longer loads the host's /etc/ssl/openssl.cnf, which could break random seeding on some distros.
  • SMB and NTLM are explicitly enabled again, as they are disabled by default since cURL 8.20.0.
  • --libcurl option is enabled (--enable-libcurl-option), so curl --libcurl file.c can generate libcurl source code.
  • Podman can be used as a drop-in replacement for Docker when building for Linux and Windows.

About

Static cURL with latest features

Topics

Resources

Stars

504 stars

Watchers

6 watching

Forks

Releases

Used by

Contributors

Languages