The plan is to use github releases from now on, and shorten using git.io
Also, git.io allows only shortening github repos; so there should be no harm
Really?
Who do you think your target audience is? I'm sorry, but this is not "really long":
https://github.com/supermarin/Alcatraz/releases/download/1.0.1/Alcatraz.tar.gz
If you're telling people to run random commands in their terminal that lead to local code execution, then you should trust that they can read a goddamn URL.If you don't think your user base can read URLs, then you shouldn't be telling them to launch the terminal and run your code.
It doesn't matter if git.io can only shorten git urls, as git.io will never be involved in a potential attack.
Using a link shortener is okay, but use one that supports HTTPS.