docmirror/dev-sidecar: a local proxy for GitHub and Stack Overflow acceleration
开发者边车,github打不开,github加速,git clone加速,git release下载加速,stackoverflow加速
At a glance
- What is it?
- dev-sidecar is an Electron desktop tool that rewrites system proxy settings and routes blocked developer traffic through mirror sites. It is aimed at developers in mainland China who need git clone and release downloads to work without a VPN.
- Who is it for?
- Adopt dev-sidecar if you are on Windows, macOS or Ubuntu, you work without a VPN, and your main pain is slow or failing git clone, release downloads and Stack Overflow assets. Skip it if you already run a working tunnel, or if you cannot accept a tool that rewrites your system proxy on launch and needs a root certificate installed.
- Can I use it commercially?
- Yes, with conditions. MPL-2.0 is a weak copyleft licence: you can use it inside commercial and closed-source software, but if you distribute changes to its own files, you must publish those changes under the same licence.
- Is it still maintained?
- Yes. The repository last received commits 4 days ago.
- What is it written in?
- Mainly JavaScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
DEEP OPEN-SOURCE ANALYSIS
The problem dev-sidecar targets
The README states the goal plainly: proxy https requests to domestic acceleration channels through a local proxy. The name comes from service mesh sidecars, meaning a helper that runs alongside the developer rather than replacing anything. The audience is narrow and specific. It is the developer who can reach the open internet in principle but finds github.com, raw.githubusercontent.com, gist.github.com, Docker Hub and Hugging Face slow, intermittent, or unreachable at certain hours. The README lists the symptoms it was built around: clone timing out, release and zip downloads crawling, avatars not loading, README images failing to render, and the recurring fatal: TaskCanceledException encountered or fatal: HttpRequestException encountered when git push asks for credentials again. It also covers Stack Overflow, where ajax.googleapis.com and the recaptcha image challenge are proxied to a CDN. This is a workaround tool, not a general VPN. The README says so directly: if you already have a tunnel, it suggests you do not need this bicycle.
How the interception and DNS selection actually work
Two mechanisms run side by side. The first is DNS optimization. The tool resolves a domain to a list of candidate IPs, tests them, and picks the fastest reachable one before handing it to the system. The README notes a concrete case: api.github.com sometimes resolves to a Singapore IP that works in the morning and stalls at night, and the speed test is what routes around that. The second mechanism is request interception. A local proxy matches the requested URL against per-domain regular expressions and applies one of several actions: redirect to a mirror host, proxy the request through a mirror while keeping the original URL, abort the request to fail fast, or return a fake success. Each rule can carry a backup list, and the README describes a speed-test mechanism that switches to a backup when the primary fails or times out. GitHub direct access is handled by modifying the SNI so the TLS handshake is not blocked, an approach the README credits to FastGithub. Note the scope: domains without a rule are not intercepted at all, so the tool only touches what you configure.
Installing the desktop app and taking the first clone
There is no npm or pip install for the end user. dev-sidecar ships as a desktop application, and the README points to the GitHub Release page for binaries. Windows users pick DevSidecar-x.x.x-windows-universal.exe, macOS users pick DevSidecar-x.x.x-macos-universal.dmg, Debian-family Linux users pick the .deb matching their architecture, and other Linux users can try the AppImage, which the README says is untested. The README warns that no application certificate was purchased, so the installer will show an unknown publisher prompt; on macOS you must unlock and allow the app under System Preferences, Security and Privacy, General.
The first launch prompts you to install a root certificate. The README explains that the certificate is generated locally at random and that the app does not collect user information, and that you can supply your own PEM certificate and private key in the acceleration service settings. Firefox does not use the system trust store, so it needs the certificate added manually in its own options.
After that, start the service and try a clone. The README gives a manual mirror form where you substitute the placeholders:
git clone https://hub.fastgit.org/{username}/{reponame}.gitThe README adds two caveats about this route: the cloned repository's origin remote will point at the mirror, so you must change it back, and the README also notes that several of the listed mirrors, including hub.fastgit.org and github.com.cnpmjs.org, appear to have stopped working as of 2024-11-18. The preferred path is the built-in script support, which adds a copy-as-accelerated-link button under the clone URL. Interception rules are edited as JSON in the acceleration service, with this shape:
{
"github.com": {
"/.*/.*/releases/download/": {
"redirect": "download.fastgit.org"
},
".*": {
"proxy": "github.com",
"sni": "baidu.com"
}
}
}The README documents the available keys for each rule: redirect, proxy, abort, success, cacheDays, options and optionsMaxAge, plus backup, test and replace for mirror matching.
The system proxy takeover is the real cost
The README's second important notice is blunt: the application modifies the system proxy on startup, so it conflicts with other proxy software, and you should use caution when running them together. Two specific cases are given. With Watt Toolkit, formerly Steam++, you must start Watt Toolkit in hosts mode. With game accelerators running in TUN adapter mode, coexistence is fine. The first notice describes a harder failure: because Electron cannot listen for Windows shutdown events, restarting the machine with dev-sidecar running could leave you with no network, recoverable by launching dev-sidecar again or by setting it to start at boot. The README notes this was fixed in version 1.8.9, so it applies to older builds.
The second limitation is more fundamental. In safe mode, interception and enhancement are off, remote configuration is not used, and only DNS optimization and speed testing run. The README is honest about what that buys you: it is roughly equivalent to looking up a foreign IP for GitHub and editing hosts by hand, GitHub reachability depends on the speed test, and direct access is only possible if a green IP exists. The default mode adds interception and remote configuration, which is where the certificate requirement comes from. The third constraint is that blocked domains cannot be rescued by DNS; the README repeats that adding a blocked domain to the DNS settings does nothing. Mirror availability is the fourth: the README itself marks three of the five listed GitHub mirrors as dead or unreliable, which tells you the acceleration targets rot and the remote configuration has to keep up.
How this differs from FastGithub and from a tunnel
FastGithub is the closest comparison, and the README credits it for the SNI modification idea used for GitHub direct access. The difference is breadth. FastGithub is a .NET tool focused on GitHub connectivity; dev-sidecar wraps a similar idea in an Electron desktop app and extends it to Stack Overflow, npm registry switching between the official and Taobao registries, Docker Hub, and a configurable JSON rule set for arbitrary domains with mirror backup and failover. That configurability is the actual product: you are not limited to the domains the author picked. The other alternative is a general tunnel, and the README dismisses it for a practical reason rather than a technical one. A tunnel moves all your traffic and usually costs money or reliability; dev-sidecar rewrites only the domains you list and leaves the rest alone. The trade is that you get a system proxy takeover and a root certificate in exchange for narrower scope. If your problem is one blocked domain and you already pay for a tunnel, the README's own advice is to keep the tunnel.
Maintenance, licence and what upgrades cost you
The repository is not archived, and the last push was on 2026-09-16, five days before this writing. Releases are frequent: v2.1.0 on 2026-06-28, v2.1.1 on 2026-06-29, and v2.2.0 on 2026-07-02. The project is licensed MPL-2.0, a file-level copyleft licence, which means modifications to MPL-covered files must be published under the same licence while you can combine them with proprietary code in separate files. This is not legal advice; check with your own counsel if you plan to redistribute a modified build. The upgrade path is the desktop installer rather than a package manager, so there is no lockfile pinning a version for you. The workspace uses [email protected] and the root package.json only defines lint scripts, so building from source is an Electron and pnpm workflow rather than a single command. The practical upgrade cost is configuration drift: if you maintain custom interception rules or a custom root certificate, verify they survive the new build, and re-check the mirror list, since the README's own history shows mirrors disappearing between versions.
Editorial conclusion
Adopt dev-sidecar if you are on Windows, macOS or Ubuntu, you work without a VPN, and your main pain is slow or failing git clone, release downloads and Stack Overflow assets. Skip it if you already run a working tunnel, or if you cannot accept a tool that rewrites your system proxy on launch and needs a root certificate installed. Before installing, read the section on conflicting proxy software and the note about restarting Windows with dev-sidecar running, then check the release page for the current version.
Frequently asked questions
What is the purpose of a sidecar, and what does dev-sidecar do with that idea?
The project takes its name from service mesh sidecars, meaning a helper that runs alongside another process. dev-sidecar applies that idea to the desktop: it runs a local proxy that routes https requests to domestic acceleration channels so GitHub, Stack Overflow and similar sites stay reachable.
What does sidecar mean in programming, and how does dev-sidecar fit that meaning?
In programming a sidecar is a companion process that assists a main one without replacing it. dev-sidecar is a desktop companion that modifies the system proxy on startup and intercepts matched requests, leaving unconfigured domains untouched.
What does sidecar mean in Kubernetes, and is dev-sidecar the same thing?
The README says the name was taken from service mesh sidecars, so the concept is borrowed rather than implemented. dev-sidecar is not a Kubernetes component; it is an Electron desktop application that runs a local proxy on Windows, macOS and Linux.
What are the disadvantages of a sidecar, and which of them apply to dev-sidecar?
The README documents two concrete drawbacks: the app modifies the system proxy on startup and conflicts with other proxy software, and it requires a locally generated root certificate in default mode. Safe mode avoids the certificate but the README describes it as roughly equivalent to editing hosts by hand.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/docmirror-dev-sidecar)
Community notes