Skip to main content

A toolkit for GitHub releases

Project description

ghr logo

Logo by Talia Blasquez, Instagram: @my_artistic_sidetrip. Licensed under CC BY 4.0.

ghr

A toolkit for GitHub releases.

Install tools from GitHub releases with one cross-platform command. A single static binary that picks the right asset for your OS and architecture. Supports verifying with minisign, sigstore, and checksums. Install it on a GitHub-hosted runner with pipx install ghr-bin.

Usage

ghr list                                          List installed tools
ghr install <spec> [<pubkey>] [<spec> ...]        Install one or more tools from GitHub releases
ghr uninstall <name>                              Remove an installed tool
ghr download <spec> [<pubkey>] [<spec> ...]       Download one or more release assets
ghr path add [--dry-run]                          Add ghr's bin dir to your user PATH
ghr path [bin|tools|cache]                        Show ghr directories
ghr minisign sign <file> [<file> ...]             Sign release artifacts with a minisign key
ghr version                                       Print version and exit
ghr help                                          Print this help and exit

Each <spec> is owner/repo[@tag] (auto-pick asset) or owner/repo/file[@tag] (specific asset). A 56-char RW/RU-prefixed base64 token immediately after a spec is treated as that spec's minisign public key. Run ghr <COMMAND> help to show help for a specific command, e.g. ghr download help.

Examples

# Install the latest release of a tool
ghr install burntsushi/ripgrep

# Install a specific version
# https://github.com/bytecodealliance/wasmtime/releases/tag/v44.0.1
ghr install bytecodealliance/wasmtime@v44.0.1

# Install several tools in one invocation (shared HTTP client + auth)
ghr install burntsushi/ripgrep@15.1.0 sharkdp/fd@v10.2.0

# Install minisign itself, verifying with its minisign public key
ghr install jedisct1/minisign@0.12 RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3

Install

pipx install ghr-bin
uv tool install ghr-bin
winget install ghr
brew install cataggar/ghr/ghr
curl -fsSL https://raw.githubusercontent.com/cataggar/ghr/main/install.sh | sh
iwr -useb https://raw.githubusercontent.com/cataggar/ghr/main/install.ps1 | iex
ghr install cataggar/ghr RWSbsumpaHb+N3KCEt/EUXQ5y6Kkk8r/zCb5Z4jhEuEX8x2/U5wr5QC0

See doc/README.md for download, install, directories, uninstall, and verification details (including verifying ghr's own releases).

GitHub Actions

For workflows, install several tools in one cached step:

- uses: cataggar/ghr/actions/install@v0.5.1  # pin to the matching ghr release
  with:
    tools: |
      burntsushi/ripgrep@14.1.1
      sharkdp/fd@v10.2.0

The action shares git tags with the ghr CLI — pinning @v0.5.1 pins both the action body and the ghr-bin binary. Pick the latest tag from the releases page.

See actions/install, actions/download, and the Caching in GitHub Actions section for details.

Signing releases

ghr minisign sign produces a minisign .minisig sidecar without an external minisign binary, a key file on disk, or an expect script. The secret key and password come from the environment, so a release job is a single step:

- run: ghr minisign sign hello.wasm -t "tag:${{ github.ref_name }} commit:${GITHUB_SHA}"
  env:
    MINISIGN_SECRET_KEY: ${{ secrets.MINISIGN_SECRET_KEY }}
    MINISIGN_PASSWORD:   ${{ secrets.MINISIGN_PASSWORD }}

Input files are bare positional arguments (each <file> is signed to <file>.minisig). A trusted comment may be given with -t (applied to every input); when omitted it defaults, like minisign, to timestamp:<unix>\tfile:<name>\thashed per file. The secret key must come from MINISIGN_SECRET_KEY and an encrypted key's password from MINISIGN_PASSWORD — there is no key-file flag, and the password is never read from a tty or stdin. Signatures use the prehashed (ED) format and are byte-for-byte identical to minisign -S output. Run ghr minisign sign help for all options.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

ghr_bin-0.6.6-py3-none-win_arm64.whl (1.0 MB view details)

Uploaded Python 3Windows ARM64

ghr_bin-0.6.6-py3-none-win_amd64.whl (1.1 MB view details)

Uploaded Python 3Windows x86-64

ghr_bin-0.6.6-py3-none-musllinux_1_1_x86_64.whl (1.0 MB view details)

Uploaded Python 3musllinux: musl 1.1+ x86-64

ghr_bin-0.6.6-py3-none-musllinux_1_1_aarch64.whl (1.0 MB view details)

Uploaded Python 3musllinux: musl 1.1+ ARM64

ghr_bin-0.6.6-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (1.0 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

ghr_bin-0.6.6-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl (1.0 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

ghr_bin-0.6.6-py3-none-macosx_11_0_arm64.whl (972.2 kB view details)

Uploaded Python 3macOS 11.0+ ARM64

ghr_bin-0.6.6-py3-none-macosx_10_9_x86_64.whl (1.0 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file ghr_bin-0.6.6-py3-none-win_arm64.whl.

File metadata

  • Download URL: ghr_bin-0.6.6-py3-none-win_arm64.whl
  • Upload date:
  • Size: 1.0 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ghr_bin-0.6.6-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 5efbafe77b0e4359b43e632700f5ad9b5df4dea222d402c29a73317342e087d7
MD5 31dbf1aaae8ee66b45cee0919003a97d
BLAKE2b-256 d068d461dd8db29ed0ae8c5a810c6f4fcaafaeb195e5f280b29c014a004e1b5d

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.6-py3-none-win_arm64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.6-py3-none-win_amd64.whl.

File metadata

  • Download URL: ghr_bin-0.6.6-py3-none-win_amd64.whl
  • Upload date:
  • Size: 1.1 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ghr_bin-0.6.6-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 cdd1b6dc0a4206c160f4a05a6d8a1c1fbea30dd4143e32d39357d433bbd6a07f
MD5 2d22d4423be3d47f3350a70c07e0bfba
BLAKE2b-256 bd474d3346faff62550ec0458b71ebcbf8b51792edb7a4d32fc4bd8e895ff6e9

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.6-py3-none-win_amd64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.6-py3-none-musllinux_1_1_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.6-py3-none-musllinux_1_1_x86_64.whl
Algorithm Hash digest
SHA256 ac5c8bbfb9dbae395cc9de59207f54f88b37164d6e54e421751503ad7e1bd5a3
MD5 e6b5faae1dff020e12a15ef2a56a69cf
BLAKE2b-256 4ccb474a6e2bf6e101318f46f402752a7e15b812bbbd33b8fa6a2b2b9989a0f1

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.6-py3-none-musllinux_1_1_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.6-py3-none-musllinux_1_1_aarch64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.6-py3-none-musllinux_1_1_aarch64.whl
Algorithm Hash digest
SHA256 19e7a5298133c96fb005cdb18c7343ab9cc29041563f847958f75be491cb2bc5
MD5 a9e3801341cd86f55b35a64d0414d4e2
BLAKE2b-256 43f3f45e2dcca1ac5ed1654cdb153d6671caa242dd018043a0f675dce3b97799

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.6-py3-none-musllinux_1_1_aarch64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.6-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.6-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 760c27e249efacd5317fdc90e72e31bd06c939ec6032f054a02bcd1648f76924
MD5 b75335812c98438e9b3e962a8ce29443
BLAKE2b-256 620d04ef623af65a02ed5f1544395f902b1c34f84d645c8a84bcd866a103a322

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.6-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.6-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.6-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 0ed9042647c352d6c1ebc1e9c44812dc2d1d819da86e726cf97b547aeddf84d0
MD5 e5b0b33c8126181fbc9dbadb56cb42c8
BLAKE2b-256 f0f9987b3343d6fa81c88d32d79feb73dbdd51d29761f2ef853a552a471c4a16

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.6-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.6-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.6-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 7449be316401ba793927c4a0751b4157e8c13c32ae200af5cac43ec223323f1c
MD5 e8cf06179c8362dd44b9f475f42c3df7
BLAKE2b-256 ef7482cafe1278900523745d83c7ecce6a7c7633e0264c03b4dbf7d6e3dd294b

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.6-py3-none-macosx_11_0_arm64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.6-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.6-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 22b3ecedecee41317eca64b422f124061fd0f79b0a925b6208a7ffe448a2702f
MD5 b22ec3ee7d336723655c0de49969505d
BLAKE2b-256 6f3976568d5936515a01672aec258a0e76dd6538dc30db82412a0762e6c09ab9

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.6-py3-none-macosx_10_9_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page