Skip to main content

A toolkit for GitHub releases

Project description

ghr logo

Logo by Talia Blasquez, Instagram: @my_artistic_sidetrip. Licensed under CC BY 4.0.

ghr

A toolkit for GitHub releases.

Install tools from GitHub releases with one cross-platform command. A single static binary that picks the right asset for your OS and architecture. Supports verifying with minisign, sigstore, and checksums. Install it on a GitHub-hosted runner with pipx install ghr-bin.

Usage

ghr list                                          List installed tools
ghr install <spec> [<pubkey>] [<spec> ...]        Install one or more tools from GitHub releases
ghr uninstall <name>                              Remove an installed tool
ghr download <spec> [<pubkey>] [<spec> ...]       Download one or more release assets
ghr path add [--dry-run]                          Add ghr's bin dir to your user PATH
ghr path [bin|tools|cache]                        Show ghr directories
ghr minisign sign <file> [<file> ...]             Sign release artifacts with a minisign key
ghr version                                       Print version and exit
ghr help                                          Print this help and exit

Each <spec> is owner/repo[@tag] (auto-pick asset) or owner/repo/file[@tag] (specific asset). A 56-char RW/RU-prefixed base64 token immediately after a spec is treated as that spec's minisign public key. Run ghr <COMMAND> help to show help for a specific command, e.g. ghr download help.

Examples

# Install the latest release of a tool
ghr install burntsushi/ripgrep

# Install a specific version
# https://github.com/bytecodealliance/wasmtime/releases/tag/v44.0.1
ghr install bytecodealliance/wasmtime@v44.0.1

# Install several tools in one invocation (shared HTTP client + auth)
ghr install burntsushi/ripgrep@15.1.0 sharkdp/fd@v10.2.0

# Install minisign itself, verifying with its minisign public key
ghr install jedisct1/minisign@0.12 RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3

Install

pipx install ghr-bin
uv tool install ghr-bin
winget install ghr
brew install cataggar/ghr/ghr
curl -fsSL https://raw.githubusercontent.com/cataggar/ghr/main/install.sh | sh
iwr -useb https://raw.githubusercontent.com/cataggar/ghr/main/install.ps1 | iex
ghr install cataggar/ghr RWSbsumpaHb+N3KCEt/EUXQ5y6Kkk8r/zCb5Z4jhEuEX8x2/U5wr5QC0

See doc/README.md for download, install, directories, uninstall, and verification details (including verifying ghr's own releases).

GitHub Actions

For workflows, install several tools in one cached step:

- uses: cataggar/ghr/actions/install@v0.5.1  # pin to the matching ghr release
  with:
    tools: |
      burntsushi/ripgrep@14.1.1
      sharkdp/fd@v10.2.0

The action shares git tags with the ghr CLI — pinning @v0.5.1 pins both the action body and the ghr-bin binary. Pick the latest tag from the releases page.

See actions/install, actions/download, and the Caching in GitHub Actions section for details.

Signing releases

ghr minisign sign produces a minisign .minisig sidecar without an external minisign binary, a key file on disk, or an expect script. The secret key and password come from the environment, so a release job is a single step:

- run: ghr minisign sign hello.wasm -t "tag:${{ github.ref_name }} commit:${GITHUB_SHA}"
  env:
    MINISIGN_SECRET_KEY: ${{ secrets.MINISIGN_SECRET_KEY }}
    MINISIGN_PASSWORD:   ${{ secrets.MINISIGN_PASSWORD }}

Input files are bare positional arguments (each <file> is signed to <file>.minisig). A trusted comment may be given with -t (applied to every input); when omitted it defaults, like minisign, to timestamp:<unix>\tfile:<name>\thashed per file. The secret key must come from MINISIGN_SECRET_KEY and an encrypted key's password from MINISIGN_PASSWORD — there is no key-file flag, and the password is never read from a tty or stdin. Signatures use the prehashed (ED) format and are byte-for-byte identical to minisign -S output. Run ghr minisign sign help for all options.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

ghr_bin-0.6.5-py3-none-win_arm64.whl (1.0 MB view details)

Uploaded Python 3Windows ARM64

ghr_bin-0.6.5-py3-none-win_amd64.whl (1.1 MB view details)

Uploaded Python 3Windows x86-64

ghr_bin-0.6.5-py3-none-musllinux_1_1_x86_64.whl (1.0 MB view details)

Uploaded Python 3musllinux: musl 1.1+ x86-64

ghr_bin-0.6.5-py3-none-musllinux_1_1_aarch64.whl (1.0 MB view details)

Uploaded Python 3musllinux: musl 1.1+ ARM64

ghr_bin-0.6.5-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (1.0 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

ghr_bin-0.6.5-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl (1.0 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

ghr_bin-0.6.5-py3-none-macosx_11_0_arm64.whl (969.0 kB view details)

Uploaded Python 3macOS 11.0+ ARM64

ghr_bin-0.6.5-py3-none-macosx_10_9_x86_64.whl (1.0 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file ghr_bin-0.6.5-py3-none-win_arm64.whl.

File metadata

  • Download URL: ghr_bin-0.6.5-py3-none-win_arm64.whl
  • Upload date:
  • Size: 1.0 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ghr_bin-0.6.5-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 4a6e1724d7b7394ce8ce3a0d28a4c55738f4e8d7bd09fcd94e6b54611465a823
MD5 cdb2efb1f632e6c9e561ca2aaba1b5f1
BLAKE2b-256 0c2e96453dfc61823ba531c83bad48063dfd9f9a1d26c2a60f4fb26b1a7a76df

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.5-py3-none-win_arm64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.5-py3-none-win_amd64.whl.

File metadata

  • Download URL: ghr_bin-0.6.5-py3-none-win_amd64.whl
  • Upload date:
  • Size: 1.1 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ghr_bin-0.6.5-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 87a847aa978932485aab51f8bdd5c1eddee6ef5a19621204e33ed29906fdb0ba
MD5 be9eea667769ee16dc7d3a95e01764ad
BLAKE2b-256 e95a8a3dd2d75467299c7b75970be674b52d43afff0e2f8296f306b00100bcf1

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.5-py3-none-win_amd64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.5-py3-none-musllinux_1_1_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.5-py3-none-musllinux_1_1_x86_64.whl
Algorithm Hash digest
SHA256 29b45898e609aac9b1dd29213b3c43abde3336c683cacf71f02a5066a8ee8f13
MD5 b5301663b4e5af17a47af28d835d0bf5
BLAKE2b-256 49a2ae3018ce6806059be1f5b9233cc06fec00101c1ff13a3e0b10eab070145d

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.5-py3-none-musllinux_1_1_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.5-py3-none-musllinux_1_1_aarch64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.5-py3-none-musllinux_1_1_aarch64.whl
Algorithm Hash digest
SHA256 b7277b162bb12b36f93090a1f8f966d9ed6c993cbdd57ec584d8ffd54f51d3b9
MD5 fa85df2653b97f622843a044a1dec723
BLAKE2b-256 a4256cfecad70cf28fb8490417f3ec3203961ea83e7cb64b7ee6d2970c6959d1

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.5-py3-none-musllinux_1_1_aarch64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.5-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.5-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 93df81c424ac31bf173a7206b19f6247ae0b241fcd269b692f8dc724d7922998
MD5 0c50a2c2da127a48a34f03c60ce55680
BLAKE2b-256 7afcb7681912fe6886bd0c3b36f000f14cf4a86c2fa31956bc55037111361ea5

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.5-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.5-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.5-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 9e81eaadab035cf00251567152b6972452219bd87add7e4babd6afae223487f7
MD5 9063e73e637daabb95d1682473a85a31
BLAKE2b-256 a1bf428fe6e4a9d178ee8a3fb2f762385b659c5a5566ae92c64f48627da0eac4

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.5-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.5-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.5-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 49d9be8a2c8871959955bf209e5790c6896b8e802f1b9a7cd35a0280b13c20f9
MD5 a3093ab521393f4e04f117c136105328
BLAKE2b-256 597a1f4621e5e713e06428e637be595f535ec117dad88c4d1bc24e062fd5839c

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.5-py3-none-macosx_11_0_arm64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.5-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.5-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 a86d88915ea2b831aebe932a33d5b9e015521fefafb135b087dff4f206726833
MD5 c5c5a552e4eace3bb38f4ac3b070a807
BLAKE2b-256 c35c4492de654b2d20fc9ad6c32f970bf205deb0c1cae292740f8e8a3190a19e

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.5-py3-none-macosx_10_9_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page