SecureFetch
0.1.0
HTTPS requests from PowerShell over TLS 1.3 with the X25519MLKEM768 post-quantum hybrid key exchange, from rustls inside the module. Invoke-SecureFetch writes a SecureFetch.Response for each https:// address, with the protocol version, key exchange and cipher suite its handshake agreed; -RequirePostQuantum refuses a server that cannot agree X25519MLKEM768 before the r
HTTPS requests from PowerShell over TLS 1.3 with the X25519MLKEM768 post-quantum hybrid key exchange, from rustls inside the module. Invoke-SecureFetch writes a SecureFetch.Response for each https:// address, with the protocol version, key exchange and cipher suite its handshake agreed; -RequirePostQuantum refuses a server that cannot agree X25519MLKEM768 before the request is sent. Certificates are verified against the bundled Mozilla roots and, on Windows, the Windows store, or a choice of roots. It sends GET, HEAD, POST, PUT, PATCH, DELETE and OPTIONS with headers and bodies, follows redirects to https:// addresses only, downloads to a file, goes through HTTP proxies by CONNECT, decodes gzip, deflate, br and zstd bodies, and keeps connections for the next request to the same host. Invoke-WebRequest and every other module keep the host's own TLS stack. Bound directly to Rust with PoWerRuSt (pwrs), Rust bindings for writing PowerShell binary modules in the spirit of PyO3: the cmdlet is the library, not a wrapper over a command line. Windows x64, Linux x64 (glibc 2.28 and newer), macOS arm64 and FreeBSD x64 in one module, on PowerShell 7.4 or later and, on Windows, Windows PowerShell 5.1. Source and issues at https://github.com/Variably-Constant/SecureFetch; the binding framework at https://github.com/Variably-Constant/PWRS and https://crates.io/crates/PoWerRuSt.
Show more
Minimum PowerShell version
5.1
Installation Options
Owners
Copyright
(c) 2026 Mark Newton
Package Details
Author(s)
- Mark Newton
Tags
pwrs powershell tls tls13 post-quantum mlkem rustls https Windows Linux MacOS FreeBSD
Cmdlets
PSEditions
Dependencies
This module has no dependencies.
Release Notes
The first release: Invoke-SecureFetch. What is in it: https://github.com/Variably-Constant/SecureFetch/blob/main/CHANGELOG.md
FileList
- SecureFetch.nuspec
- SecureFetch.Format.ps1xml
- SecureFetch.psd1
- SecureFetch.psm1
- THIRD-PARTY-NOTICES.txt
- net10.0\Pwrs.Bootstrap.dll
- net10.0\Pwrs.Runtime.dll
- net10.0\SecureFetch.Shell.b646fad3644308f2.dll
- netstandard2.0\Pwrs.Bootstrap.dll
- netstandard2.0\Pwrs.Runtime.dll
- netstandard2.0\SecureFetch.Shell.b646fad3644308f2.dll
- net10.0\en-US\SecureFetch.Shell.b646fad3644308f2.dll-Help.xml
- netstandard2.0\en-US\SecureFetch.Shell.b646fad3644308f2.dll-Help.xml
- runtimes\freebsd-x64\THIRD-PARTY-NOTICES.txt
- runtimes\linux-x64\THIRD-PARTY-NOTICES.txt
- runtimes\osx-arm64\THIRD-PARTY-NOTICES.txt
- runtimes\win-x64\THIRD-PARTY-NOTICES.txt
- runtimes\freebsd-x64\native\libsecurefetch.so
- runtimes\linux-x64\native\libsecurefetch.so
- runtimes\osx-arm64\native\libsecurefetch.dylib
- runtimes\win-x64\native\securefetch.dll
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 0.1.0 (current version) | 10 | 9/29/2026 |