Skip to main content

A toolkit for GitHub releases

Project description

ghr logo

Logo by Talia Blasquez. Licensed under CC BY 4.0.

ghr

A toolkit for GitHub releases.

Install tools from GitHub releases with one cross-platform command. A single static binary that picks the right asset for your OS and architecture. Supports verifying with minisign, sigstore, GitHub artifact attestations, and checksums. Install it on a GitHub-hosted runner with pipx install ghr-bin.

Usage

ghr list                                          List installed tools
ghr install <spec> [<pubkey>] [<spec> ...]        Install one or more tools from GitHub releases
ghr uninstall <name>                              Remove an installed tool
ghr download <spec> [<pubkey>] [<spec> ...]       Download one or more release assets
ghr path add [--dry-run]                          Add ghr's bin dir to your user PATH
ghr path [bin|tools|cache]                        Show ghr directories
ghr minisign sign <file> [<file> ...]             Sign release artifacts with a minisign key
ghr version                                       Print version and exit
ghr help                                          Print this help and exit

Each <spec> is owner/repo[@tag] (auto-pick asset) or owner/repo/file[@tag] (specific asset). A 56-char RW/RU-prefixed base64 token immediately after a spec is treated as that spec's minisign public key. Run ghr <COMMAND> help to show help for a specific command, e.g. ghr download help.

Examples

# Install the latest release of a tool
ghr install burntsushi/ripgrep

# Install a specific version
# https://github.com/bytecodealliance/wasmtime/releases/tag/v44.0.1
ghr install bytecodealliance/wasmtime@v44.0.1

# Install several tools in one invocation (shared HTTP client + auth)
ghr install burntsushi/ripgrep@15.1.0 sharkdp/fd@v10.2.0

# Install minisign itself, verifying with its minisign public key
ghr install jedisct1/minisign@0.12 RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3

Install

pipx install ghr-bin
uv tool install ghr-bin
winget install ghr
brew install cataggar/ghr/ghr
curl -fsSL https://raw.githubusercontent.com/cataggar/ghr/main/install.sh | sh
iwr -useb https://raw.githubusercontent.com/cataggar/ghr/main/install.ps1 | iex
ghr install cataggar/ghr RWSbsumpaHb+N3KCEt/EUXQ5y6Kkk8r/zCb5Z4jhEuEX8x2/U5wr5QC0

See doc/README.md for download, install, directories, uninstall, and verification details (including verifying ghr's own releases).

GitHub Actions

For workflows, install several tools in one cached step:

- uses: cataggar/ghr/actions/install@v0.5.1  # pin to the matching ghr release
  with:
    tools: |
      burntsushi/ripgrep@14.1.1
      sharkdp/fd@v10.2.0

The action shares git tags with the ghr CLI — pinning @v0.5.1 pins both the action body and the ghr-bin binary. Pick the latest tag from the releases page.

See actions/install, actions/download, and the Caching in GitHub Actions section for details.

Signing releases

ghr minisign sign produces a minisign .minisig sidecar without an external minisign binary, a key file on disk, or an expect script. The secret key and password come from the environment, so a release job is a single step:

- run: ghr minisign sign hello.wasm -t "tag:${{ github.ref_name }} commit:${GITHUB_SHA}"
  env:
    MINISIGN_SECRET_KEY: ${{ secrets.MINISIGN_SECRET_KEY }}
    MINISIGN_PASSWORD:   ${{ secrets.MINISIGN_PASSWORD }}

Input files are bare positional arguments (each <file> is signed to <file>.minisig). A trusted comment may be given with -t (applied to every input); when omitted it defaults, like minisign, to timestamp:<unix>\tfile:<name>\thashed per file. The secret key must come from MINISIGN_SECRET_KEY and an encrypted key's password from MINISIGN_PASSWORD — there is no key-file flag, and the password is never read from a tty or stdin. Signatures use the prehashed (ED) format and are byte-for-byte identical to minisign -S output. Run ghr minisign sign help for all options.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

ghr_bin-0.7.0-py3-none-win_arm64.whl (1.1 MB view details)

Uploaded Python 3Windows ARM64

ghr_bin-0.7.0-py3-none-win_amd64.whl (1.2 MB view details)

Uploaded Python 3Windows x86-64

ghr_bin-0.7.0-py3-none-musllinux_1_1_x86_64.whl (1.1 MB view details)

Uploaded Python 3musllinux: musl 1.1+ x86-64

ghr_bin-0.7.0-py3-none-musllinux_1_1_aarch64.whl (1.1 MB view details)

Uploaded Python 3musllinux: musl 1.1+ ARM64

ghr_bin-0.7.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (1.1 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

ghr_bin-0.7.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl (1.1 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

ghr_bin-0.7.0-py3-none-macosx_11_0_arm64.whl (1.0 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

ghr_bin-0.7.0-py3-none-macosx_10_9_x86_64.whl (1.1 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file ghr_bin-0.7.0-py3-none-win_arm64.whl.

File metadata

  • Download URL: ghr_bin-0.7.0-py3-none-win_arm64.whl
  • Upload date:
  • Size: 1.1 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for ghr_bin-0.7.0-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 bf0a537d7d3580a80ccb7d64b93e9da5298edb7c742b7ec6ccca7b749850d795
MD5 1b4925a7fb70cd143dd8c59c0e4af85d
BLAKE2b-256 a1e7b50504b288e2191f5b0afd933d7624675a7652bd87167e7247c135cfe8a3

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.7.0-py3-none-win_arm64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.7.0-py3-none-win_amd64.whl.

File metadata

  • Download URL: ghr_bin-0.7.0-py3-none-win_amd64.whl
  • Upload date:
  • Size: 1.2 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for ghr_bin-0.7.0-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 c817a276bb13858f676dca94e2857fdc0173365638425bc222cfbaadea99a543
MD5 6f07945806cfd955142ae4dc7c1def3a
BLAKE2b-256 2782139170c50367ab8e675a8fea5509080264667f71f632102027ebbc0a76ab

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.7.0-py3-none-win_amd64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.7.0-py3-none-musllinux_1_1_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.7.0-py3-none-musllinux_1_1_x86_64.whl
Algorithm Hash digest
SHA256 9fa4d4af8994e9a9d5aa193fbbcdd54ade761b01f74570a54973401f1ef276aa
MD5 22616934b5108c4319c325e8b84f0af0
BLAKE2b-256 ee959ad2886b120dccde54585f5147d96dd852cbcb1420307a51424c53c78dec

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.7.0-py3-none-musllinux_1_1_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.7.0-py3-none-musllinux_1_1_aarch64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.7.0-py3-none-musllinux_1_1_aarch64.whl
Algorithm Hash digest
SHA256 8d3b73168ea978a9fdd95a38049bab5b51e0727bdab6da0b5c664e3af18f5317
MD5 4eac65db53a24a4c2469db27db0acd03
BLAKE2b-256 020783392c4472b45763a64ffab07ee820d57323472022ff4c3280737a0529cd

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.7.0-py3-none-musllinux_1_1_aarch64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.7.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.7.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 679d0f7ee3f33648182cdfda8e9dd059a8446e9e1c4930d27b42e396f06831dc
MD5 d6630fccae8a15806108122cfeda3659
BLAKE2b-256 f1ad02ea10b1323bf643fcf5f31cf0cae2002e48850e56f239c1839a884e26fb

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.7.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.7.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.7.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 2b613f07f097b5226943b95100eb3c28f5898cefd45957a596165b3331bd0113
MD5 65e44153ac372228ba53e7f7ba62f1f3
BLAKE2b-256 7587ba3adcd651b0ee671f55b4997a3afe25b4d85e02203d5a228b66fdd93308

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.7.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.7.0-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.7.0-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 422ed5119168e11bd1c4e0f3ab36a07337c8a8853bf21303f43fbf8c6f98d749
MD5 1b13e6af178ddd9c97beaf6c2fcbec07
BLAKE2b-256 56c258a0d6940d6aa9fc66edbc8b27e8b5637dd042945a638649fc8b15a8e7dd

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.7.0-py3-none-macosx_11_0_arm64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.7.0-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.7.0-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 30981974213d93a2fdaa56a5b0c12933805084e5e53faf7beb92a621eb8d26c5
MD5 7243b58a86e7ca17a73e72615a8c46c1
BLAKE2b-256 34faeb0bd4c80d995e3e055d335d23018ca939b5ea8bb21e72b4848e5d89d7d9

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.7.0-py3-none-macosx_10_9_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page