Republishes prebuilt binaries from upstream GitHub releases with normalized filenames.
| Tool | Upstream repo | Binary name |
|---|---|---|
| rg | BurntSushi/ripgrep | rg |
| bun | oven-sh/bun | bun |
| uv | astral-sh/uv | uv |
| yt-dlp | yt-dlp/yt-dlp | yt-dlp |
| ffmpeg | BtbN/FFmpeg-Builds; Martin Riedl macOS builds | ffmpeg |
| cua-driver | trycua/cua | cua-driver |
| cua-driver-uia | trycua/cua | cua-driver-uia |
{tool}-{version}-{os}-{arch}[-{variant}][.exe]
Examples: rg-15.1.0-linux-aarch64, uv-0.11.3-linux-x86_64-musl, yt-dlp-2026.03.17-darwin-universal
Release: 2026-07-10
| File | OS | Arch | Variant | Download |
|---|---|---|---|---|
rg-15.1.0-darwin-x86_64 |
darwin | x86_64 | - | download |
rg-15.1.0-darwin-aarch64 |
darwin | aarch64 | - | download |
rg-15.1.0-windows-aarch64.exe |
windows | aarch64 | - | download |
rg-15.1.0-windows-x86_64.exe |
windows | x86_64 | - | download |
rg-15.1.0-linux-armv7-musl |
linux | armv7 | musl | download |
rg-15.1.0-linux-i686 |
linux | i686 | - | download |
rg-15.1.0-linux-armv7 |
linux | armv7 | - | download |
rg-15.1.0-linux-aarch64 |
linux | aarch64 | - | download |
rg-15.1.0-windows-i686.exe |
windows | i686 | - | download |
rg-15.1.0-linux-s390x |
linux | s390x | - | download |
rg-15.1.0-linux-x86_64-musl |
linux | x86_64 | musl | download |
| File | OS | Arch | Variant | Download |
|---|---|---|---|---|
bun-1.3.14-darwin-aarch64 |
darwin | aarch64 | - | download |
bun-1.3.14-darwin-x86_64 |
darwin | x86_64 | - | download |
bun-1.3.14-linux-aarch64-musl |
linux | aarch64 | musl | download |
bun-1.3.14-linux-aarch64 |
linux | aarch64 | - | download |
bun-1.3.14-linux-x86_64-musl |
linux | x86_64 | musl | download |
bun-1.3.14-linux-x86_64 |
linux | x86_64 | - | download |
bun-1.3.14-windows-x86_64.exe |
windows | x86_64 | - | download |
| File | OS | Arch | Variant | Download |
|---|---|---|---|---|
uv-0.11.28-darwin-aarch64 |
darwin | aarch64 | - | download |
uv-0.11.28-windows-aarch64.exe |
windows | aarch64 | - | download |
uv-0.11.28-linux-aarch64 |
linux | aarch64 | - | download |
uv-0.11.28-linux-aarch64-musl |
linux | aarch64 | musl | download |
uv-0.11.28-linux-arm-musl |
linux | arm | musl | download |
uv-0.11.28-linux-armv7 |
linux | armv7 | - | download |
uv-0.11.28-linux-armv7-musl |
linux | armv7 | musl | download |
uv-0.11.28-windows-i686.exe |
windows | i686 | - | download |
uv-0.11.28-linux-i686 |
linux | i686 | - | download |
uv-0.11.28-linux-i686-musl |
linux | i686 | musl | download |
uv-0.11.28-linux-ppc64le |
linux | ppc64le | - | download |
uv-0.11.28-linux-riscv64 |
linux | riscv64 | - | download |
uv-0.11.28-linux-s390x |
linux | s390x | - | download |
uv-0.11.28-darwin-x86_64 |
darwin | x86_64 | - | download |
uv-0.11.28-windows-x86_64.exe |
windows | x86_64 | - | download |
uv-0.11.28-linux-x86_64 |
linux | x86_64 | - | download |
uv-0.11.28-linux-x86_64-musl |
linux | x86_64 | musl | download |
| File | OS | Arch | Variant | Download |
|---|---|---|---|---|
yt-dlp-2026.07.04-linux-x86_64 |
linux | x86_64 | - | download |
yt-dlp-2026.07.04-linux-aarch64 |
linux | aarch64 | - | download |
yt-dlp-2026.07.04-linux-armv7 |
linux | armv7 | - | download |
yt-dlp-2026.07.04-linux-x86_64-musl |
linux | x86_64 | musl | download |
yt-dlp-2026.07.04-linux-aarch64-musl |
linux | aarch64 | musl | download |
yt-dlp-2026.07.04-darwin-universal |
darwin | universal | - | download |
yt-dlp-2026.07.04-windows-x86_64.exe |
windows | x86_64 | - | download |
yt-dlp-2026.07.04-windows-aarch64.exe |
windows | aarch64 | - | download |
yt-dlp-2026.07.04-windows-i686.exe |
windows | i686 | - | download |
| File | OS | Arch | Variant | Download |
|---|---|---|---|---|
ffmpeg-8.1-linux-x86_64-gpl |
linux | x86_64 | gpl | download |
ffmpeg-8.1-linux-aarch64-gpl |
linux | aarch64 | gpl | download |
ffmpeg-8.1-windows-x86_64-gpl.exe |
windows | x86_64 | gpl | download |
ffmpeg-8.1-windows-aarch64-gpl.exe |
windows | aarch64 | gpl | download |
ffmpeg-8.1-darwin-x86_64-gpl |
darwin | x86_64 | gpl | download |
ffmpeg-8.1-darwin-aarch64-gpl |
darwin | aarch64 | gpl | download |
| File | OS | Arch | Variant | Download |
|---|---|---|---|---|
cua-driver-0.7.1-darwin-universal.tar.gz |
darwin | universal | - | download |
cua-driver-0.7.1-linux-x86_64 |
linux | x86_64 | - | download |
cua-driver-0.7.1-linux-aarch64 |
linux | aarch64 | - | download |
cua-driver-0.7.1-windows-x86_64.exe |
windows | x86_64 | - | download |
cua-driver-0.7.1-windows-aarch64.exe |
windows | aarch64 | - | download |
| File | OS | Arch | Variant | Download |
|---|---|---|---|---|
cua-driver-uia-0.7.1-windows-x86_64.exe |
windows | x86_64 | - | download |
cua-driver-uia-0.7.1-windows-aarch64.exe |
windows | aarch64 | - | download |
Each release includes version-less asset names. GitHub's /releases/latest redirect
gives you a stable URL that always points to the most recent published version:
# Download a binary
curl -fSL https://github.com/bearlyai/crossbins/releases/latest/download/rg-linux-x86_64 -o rg
chmod +x rg
# Check current versions programmatically
curl -fSL https://github.com/bearlyai/crossbins/releases/latest/download/manifest.json | jq .URL pattern: https://github.com/bearlyai/crossbins/releases/latest/download/{tool}-{os}-{arch}[-{variant}][.exe]
| crossbins | Electron / Node.js equivalent |
|---|---|
darwin |
darwin |
linux |
linux |
windows |
win32 |
aarch64 |
arm64 |
x86_64 |
x64 |
i686 |
ia32 |
universal |
(macOS universal — fallback when no arch-specific build exists) |
The manifest.json includes a platform_map with these translations.
./update.sh # downloads, extracts, normalizes into ./output/
ls -la output/
file output/* # verify binary typesSet GITHUB_TOKEN to avoid API rate limits when testing repeatedly.
Two config modes in binaries.json:
Archive-based tools (rg, bun, uv) — use asset_prefix + triple_map:
name— short name used in output filenamesrepo— GitHubowner/repobinary_name— the executable filename inside the archiveasset_prefix— pattern to match assets ({VERSION}is replaced with the resolved version)triple_map— maps upstream platform strings to{os, arch, variant}
Raw binary tools (yt-dlp) — use explicit_assets:
name,repo,binary_name— same as aboverelease_tag_pattern— optional regex to select only matching upstream release tagsversion_probe_regex— optional regex with a namedversioncapture, resolved from upstream asset nameschecksum_asset— optional release asset containing SHA256 checksums to verify before extractionexplicit_assets— list of{asset_name, source_type, os, arch, variant}entries.asset_name,asset_regex, orurlmay use{VERSION}fromversion_probe_regex;checksum_urlmay use{EFFECTIVE_URL}after redirects are resolved.source_typesupportsraw,zip,tar.gz, andtar.xz.checksum_nameandversion_check_regex— optional direct URL checks for checksum file entries and redirect targets
Just run ./update.sh — it always fetches the latest stable (non-draft, non-prerelease) release from GitHub.
The published Windows binaries (*-windows-*.exe) are Authenticode-signed under Bearly's
identity (CN = Bearly, Inc.) using Azure Trusted Signing —
the same certificate identity as the Bearly desktop installer. Signing runs in CI via
sign-windows.sh using jsign, so no
Windows runner is needed, and publish.sh refuses to upload any Windows binary that is not
signed as Bearly, Inc. (upstream signatures from other publishers do not satisfy the check).
Allow-listing in managed environments (BeyondTrust, AppLocker, WDAC, etc.): match the publisher identity
Bearly, Inc.— not a file hash or certificate thumbprint. Trusted Signing issues short-lived leaf certificates (~3-day lifetime, auto-timestamped) that rotate, and each binary's hash changes whenever its upstream tool updates. The publisher identity is the only value that stays constant across every version, and it matches the installer.
The published macOS binaries and app bundles (*-darwin-*) are signed with Bearly's
Developer ID Application certificate. App bundles are also notarized and stapled before
publish. publish.sh refuses to upload macOS artifacts unless they verify under Bearly's
Apple team identity; app-bundle archives must also carry a stapled notarization ticket.
The PyInstaller-based yt-dlp binary is signed with a library-validation exception so its
embedded Python framework can load under the hardened runtime; other raw binaries do not
receive that entitlement.
The CUA macOS archive is intentionally rewrapped before signing: upstream CuaDriver.app
becomes Bearly Computer Use Helper.app with bundle id com.bearly.computer-use-helper.
The helper's AppIcon.icns is the canonical Bearly Electron icon copied from
projects/electron/build/icon.icns in the Bearly repository.
This keeps macOS privacy prompts attributed to Bearly's helper. CUA is MIT licensed; the
required notice is included in the archive root and inside the helper app resources.
Linux binaries are not OS-signed; their release manifest entries carry SHA-256 hashes.
A GitHub Actions workflow runs weekly (Monday 9am UTC) to check for upstream updates. When versions change, it publishes a new release and commits the updated lock file and README. Before publish, CI verifies checksums, signs Windows and macOS artifacts, notarizes macOS app bundles, and refuses artifacts that do not verify under Bearly's signing identities.
The workflow also runs on pushes to main when binary config, scripts, or license notices change, and can be triggered manually.
curl, jq, tar, unzip, find — available on any Linux/macOS system and in the CI image.