Skip to main content

A toolkit for GitHub releases

Project description

ghr logo

Logo by Talia Blasquez, Instagram: @my_artistic_sidetrip. Licensed under CC BY 4.0.

ghr

A toolkit for GitHub releases.

Install tools from GitHub releases with one cross-platform command. A single static binary that picks the right asset for your OS and architecture. Supports verifying with minisign, sigstore, and checksums. Install it on a GitHub-hosted runner with pipx install ghr-bin.

Usage

ghr list                                          List installed tools
ghr install <spec> [<pubkey>] [<spec> ...]        Install one or more tools from GitHub releases
ghr uninstall <name>                              Remove an installed tool
ghr download <spec> [<pubkey>] [<spec> ...]       Download one or more release assets
ghr path add [--dry-run]                          Add ghr's bin dir to your user PATH
ghr path [bin|tools|cache]                        Show ghr directories
ghr minisign sign <file> [<file> ...]             Sign release artifacts with a minisign key
ghr version                                       Print version and exit
ghr help                                          Print this help and exit

Each <spec> is owner/repo[@tag] (auto-pick asset) or owner/repo/file[@tag] (specific asset). A 56-char RW/RU-prefixed base64 token immediately after a spec is treated as that spec's minisign public key. Run ghr <COMMAND> help to show help for a specific command, e.g. ghr download help.

Examples

# Install the latest release of a tool
ghr install burntsushi/ripgrep

# Install a specific version
# https://github.com/bytecodealliance/wasmtime/releases/tag/v44.0.1
ghr install bytecodealliance/wasmtime@v44.0.1

# Install several tools in one invocation (shared HTTP client + auth)
ghr install burntsushi/ripgrep@15.1.0 sharkdp/fd@v10.2.0

# Install minisign itself, verifying with its minisign public key
ghr install jedisct1/minisign@0.12 RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3

Install

pipx install ghr-bin
uv tool install ghr-bin
winget install ghr
brew install cataggar/ghr/ghr
curl -fsSL https://raw.githubusercontent.com/cataggar/ghr/main/install.sh | sh
iwr -useb https://raw.githubusercontent.com/cataggar/ghr/main/install.ps1 | iex
ghr install cataggar/ghr RWSbsumpaHb+N3KCEt/EUXQ5y6Kkk8r/zCb5Z4jhEuEX8x2/U5wr5QC0

See doc/README.md for download, install, directories, uninstall, and verification details (including verifying ghr's own releases).

GitHub Actions

For workflows, install several tools in one cached step:

- uses: cataggar/ghr/actions/install@v0.5.1  # pin to the matching ghr release
  with:
    tools: |
      burntsushi/ripgrep@14.1.1
      sharkdp/fd@v10.2.0

The action shares git tags with the ghr CLI — pinning @v0.5.1 pins both the action body and the ghr-bin binary. Pick the latest tag from the releases page.

See actions/install, actions/download, and the Caching in GitHub Actions section for details.

Signing releases

ghr minisign sign produces a minisign .minisig sidecar without an external minisign binary, a key file on disk, or an expect script. The secret key and password come from the environment, so a release job is a single step:

- run: ghr minisign sign hello.wasm -t "tag:${{ github.ref_name }} commit:${GITHUB_SHA}"
  env:
    MINISIGN_SECRET_KEY: ${{ secrets.MINISIGN_SECRET_KEY }}
    MINISIGN_PASSWORD:   ${{ secrets.MINISIGN_PASSWORD }}

Input files are bare positional arguments (each <file> is signed to <file>.minisig). A trusted comment may be given with -t (applied to every input); when omitted it defaults, like minisign, to timestamp:<unix>\tfile:<name>\thashed per file. The secret key must come from MINISIGN_SECRET_KEY and an encrypted key's password from MINISIGN_PASSWORD — there is no key-file flag, and the password is never read from a tty or stdin. Signatures use the prehashed (ED) format and are byte-for-byte identical to minisign -S output. Run ghr minisign sign help for all options.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

ghr_bin-0.6.4-py3-none-win_arm64.whl (1.0 MB view details)

Uploaded Python 3Windows ARM64

ghr_bin-0.6.4-py3-none-win_amd64.whl (1.1 MB view details)

Uploaded Python 3Windows x86-64

ghr_bin-0.6.4-py3-none-musllinux_1_1_x86_64.whl (1.0 MB view details)

Uploaded Python 3musllinux: musl 1.1+ x86-64

ghr_bin-0.6.4-py3-none-musllinux_1_1_aarch64.whl (1.0 MB view details)

Uploaded Python 3musllinux: musl 1.1+ ARM64

ghr_bin-0.6.4-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (1.0 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

ghr_bin-0.6.4-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl (1.0 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

ghr_bin-0.6.4-py3-none-macosx_11_0_arm64.whl (968.7 kB view details)

Uploaded Python 3macOS 11.0+ ARM64

ghr_bin-0.6.4-py3-none-macosx_10_9_x86_64.whl (1.0 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file ghr_bin-0.6.4-py3-none-win_arm64.whl.

File metadata

  • Download URL: ghr_bin-0.6.4-py3-none-win_arm64.whl
  • Upload date:
  • Size: 1.0 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ghr_bin-0.6.4-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 e94c3fbc64c2e9f114237190de5d7a687cba556832c61ff603b8ec65c0d1dd14
MD5 689f74f405694b74c19cafd7118bc786
BLAKE2b-256 c963ef9e4f71b67eb7b0b5e22a554dc4b546b43872c5a7b93b9db59357354444

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.4-py3-none-win_arm64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.4-py3-none-win_amd64.whl.

File metadata

  • Download URL: ghr_bin-0.6.4-py3-none-win_amd64.whl
  • Upload date:
  • Size: 1.1 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ghr_bin-0.6.4-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 67607b04a82fd4a7630be663db5e836b2151e5d9eee6bc7fdcc6a1f8403df582
MD5 b84ffd9e9cb19007b789beb95f0d8ce4
BLAKE2b-256 cdb16aa0a561fd620249ac8cafb48942471ec2a745afe9ef8f0d0e48165d0c76

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.4-py3-none-win_amd64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.4-py3-none-musllinux_1_1_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.4-py3-none-musllinux_1_1_x86_64.whl
Algorithm Hash digest
SHA256 1732677e2b2b857fe17ce781f2a1ceda7beb2bd5ff36bb2e7e4ab850cadebb07
MD5 7ebc2b13ce107fc46f73c7f289d648b2
BLAKE2b-256 dbd17df13fbadb9f90902eca84b0efbd72a5f0fb8a7e9cd20080435bfe2d1cc9

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.4-py3-none-musllinux_1_1_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.4-py3-none-musllinux_1_1_aarch64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.4-py3-none-musllinux_1_1_aarch64.whl
Algorithm Hash digest
SHA256 95c1384508a188314e812252eee11489a5883d0e498cae08eaf5a41d92b731f5
MD5 e92e8060f666aa9244870b5e84b6f7a7
BLAKE2b-256 5c53625b33234ab53699645681ddef3bcb7f8f3abef344a2a8037e5aaa8cd6d4

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.4-py3-none-musllinux_1_1_aarch64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.4-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.4-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 35bd654b160695d2fee806275ecef9e4876bff85bcfc87ad4ed528bc28da2685
MD5 3ecbc5b041c87eb582ebd6415c1c460d
BLAKE2b-256 b5f5da2f09a4e1dae3ec4effc71893d8f508ea505c0841ab455e4c2862ad30b0

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.4-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.4-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.4-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 05a50c0470c20eba91050eaff8463f3f2b6c69a3e68b5b1cc955f8d059cc2735
MD5 88e7efd1b97c89ae39d7077ef800dc23
BLAKE2b-256 2b0d2c12b464df5820f38da80f07dc0dbc84c35f6472aef70de9b9f06dddc08b

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.4-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.4-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.4-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 6e98bf769ec616879f4d8983bae8af8dbab22341b9bbaa7b02bc60a40a93e5ae
MD5 5510f33333f55aa299ea615f920b0f79
BLAKE2b-256 7869dc41e1a753a0eb504e946dc69ab6f07ed8f72865afd2152b2182d362997c

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.4-py3-none-macosx_11_0_arm64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.4-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.4-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 01d74fa612fdd7ae50c17faa70dc0ec71b426785703b6dba46419c694b7642fb
MD5 b22dd014496e3ea623796b0169c3c095
BLAKE2b-256 a999075a51714399b5c9f04ab0be5890237c59514863649ffccb9a4070ad9369

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.4-py3-none-macosx_10_9_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page