Gearu
Make repositories ready for release.
Gearu is a small, explicit release-preparation tool for Python, Rust, and npm projects. Its name comes from Old English gearu: ready, prepared, or equipped.
Documentation: https://owebeeone.github.io/gearu/
Gearu takes an intended version and makes the repository mechanically ready to release:
gearu plan 0.1.0
gearu release 0.1.0
Or select the next semantic version from configured package versions and valid local and remote release tags:
gearu plan --bump minor
gearu release --bump minor
plan verifies and reports without changing tracked files or remote state.
release builds and tests a candidate in a temporary worktree, then creates the
local release commit and immutable tag. External actions are always explicit:
gearu release 0.1.0 --push
gearu release 0.1.0 --push --github-release
Boundaries
Gearu is responsible for:
- verifying repository, branch, commit, remote tag, and dependency-tag state;
- updating versions, lockfiles, and configured dependency pins;
- running project-specific release checks;
- creating a release commit and immutable tag;
- atomically pushing the commit and tag to one repository; and
- creating the GitHub Release that starts that repository's publish workflow.
Gearu does not publish packages directly to PyPI, crates.io, or npm. Registry
credentials and publication remain in GitHub Actions, triggered by the
release.published event.
Cross-repository release trains are ordered and verified, but cannot be atomic: Git only provides atomic pushes within a single remote.
Install
Once the first release is published:
uv tool install gearu
For development:
uv sync
uv run python run_tests.py
Bootstrap release guidance
From any Git repository, run:
gearu init
This creates or updates managed Gearu sections in AGENTS.md and RELEASE.md.
The short agent rule points to the full repository release instructions, which
cover installation, documentation, planning, local preparation, pushing,
GitHub Release creation, and recovery. Existing repository-specific content is
preserved, and repeated runs produce no changes.
init does not require gearu.toml; it can be the first Gearu setup step.
Configure
Add gearu.toml to the target repository:
[project]
name = "example"
branch = "main"
remote = "origin"
tag_prefix = "v"
github_repo = "owner/example"
# Optional for repositories that cut releases from a maintained release branch:
# source_branch = "main"
[python]
manifest = "pyproject.toml"
version = "static"
[release]
checks = [["python", "-m", "pytest", "-q"]]
Use [python] with version = "scm" for tag-derived versions. Rust projects
use [rust] with manifests = ["Cargo.toml"]; npm projects use [npm] with
manifest = "package.json". Lockfile refresh commands are configurable and run
only when their ecosystem manifest changes.
Cross-repository release dependencies can verify a remote tag and update an inline TOML pin:
[[dependencies]]
name = "example-core"
url = "https://github.com/owner/example-core"
tag = "{tag}"
pin_file = "Cargo.toml"
pin_key = "dependencies.example-core"
pin_field = "tag"
# Optional: prove Cargo.lock pins this package to the resolved tag commit.
lock_package = "example-core"
Override a same-version dependency deliberately with
--dependency-tag example-core=v1.1.0.
See Configuration for the complete schema and Release Process for the end-to-end operator flow and recovery rules.
Release model
Gearu itself is published only by
.github/workflows/publish.yml after a GitHub
Release is published. PyPI authentication uses Trusted Publishing; no PyPI API
token is stored in the repository.
License
Metadata
Release files for gearu 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| gearu-0.1.1.tar.gz | 77.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| gearu-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 108.3 kB
Release files / gearu-0.1.1.tar.gz
| Download URL | gearu-0.1.1.tar.gz |
|---|---|
| Size | 77.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d0f34c8a8bf64a52ff2eba7a5a8d295e8f212398061e54fb3400cd440d5dea1d
|
|
BLAKE2b-256 checksum How to use checksums |
f436c1445f3694e46376aa9fc8f5137ee5331def4909c2eb7bd2609d5e94c481
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 12, 2026.
Transparency logRelease files / gearu-0.1.1-py3-none-any.whl
| Download URL | gearu-0.1.1-py3-none-any.whl |
|---|---|
| Size | 30.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c56deb31c894ff6a8415426f29c33e5627e33509b615c2236acabe332de898c4
|
|
BLAKE2b-256 checksum How to use checksums |
e1f2cecf41920019ee7568da6f46220f477b2260f45024ee27d97875583680fd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 12, 2026.
Transparency log