what's changed
two user-reported fixes, both reproduced before being touched.
fixed
- playlist downloads now get the album tag (closes #104). the same song tagged correctly when downloaded on its own and came down album-less inside a playlist, which turns out to be upstream: Spotify's playlist feed returns no album for any track, while the single-track endpoint returns the real one. the per-track fetch that already existed to rescue cover art now carries album and release date as well, and runs whenever any of the three is missing instead of only when the cover is. no extra network cost in practice, since the playlist feeds supply none of the three and that fetch was already firing for every track.
brew installandbrew upgradeno longer print a deprecation warning (closes #106). the cask used thepostflightblock, which Homebrew has deprecated and now rejects in official taps. it is now a structuredpostflight_stepsstanza, with the quarantine strip kept non-fatal so a failedxattrcan never abort an install. install it by its full name,sunnypatell/sunnify/sunnify(commands below): Homebrew 7 refuses a third-party cask by its short name until the tap is trusted, and naming it in full is what trusts it.
not changed, on purpose
the YouTube matcher, again. a change there trades silently: the file downloads, the tags look right, and the audio is a different song.
reported by @datre9 and @vv371. the album gap had been shipping since playlists existed, and it took a side-by-side metadata comparison to spot. thank you both.
verifying this release: every asset is covered by SLSA build L3 provenance - gh attestation verify <asset> --repo sunnypatell/sunnify-spotify-downloader, or check checksums.txt with sha256sum -c.
install via homebrew (macos):
brew tap sunnypatell/sunnify https://github.com/sunnypatell/sunnify-spotify-downloader
brew install --cask sunnypatell/sunnify/sunnifyfull changelog: v2.4.2...v2.4.3
⭐ if sunnify saved you time, star the repo - stars are how people find it.
attestations from this build
direct links to each attestation generated by the workflow run that produced these binaries (sigstore-signed, public-good rekor log entry, SLSA build L3 via the release-build.yml reusable workflow):
- build provenance: Sunnify-Windows.exe
- build provenance: Sunnify-Windows-CLI.exe
- build provenance: Sunnify-Linux
- build provenance: Sunnify-macOS.zip
- build provenance: Sunnify-macOS-Intel.zip
- sbom attestation for the binaries
- build provenance for the source tarball
the *.sigstore.json assets attached above are the same attestations as offline-verifiable bundles. these get auto-refreshed on every release re-build, so the links above always correspond to the binaries currently attached to this release.