Skip to main content

A toolkit for GitHub releases

Project description

ghr logo

Logo by Talia Blasquez. Licensed under CC BY 4.0.

ghr

A toolkit for GitHub releases.

Install tools from GitHub releases with one cross-platform command. A single static binary that picks the right asset for your OS and architecture. Supports verifying with minisign, sigstore, and checksums. Install it on a GitHub-hosted runner with pipx install ghr-bin.

Usage

ghr list                                          List installed tools
ghr install <spec> [<pubkey>] [<spec> ...]        Install one or more tools from GitHub releases
ghr uninstall <name>                              Remove an installed tool
ghr download <spec> [<pubkey>] [<spec> ...]       Download one or more release assets
ghr path add [--dry-run]                          Add ghr's bin dir to your user PATH
ghr path [bin|tools|cache]                        Show ghr directories
ghr minisign sign <file> [<file> ...]             Sign release artifacts with a minisign key
ghr version                                       Print version and exit
ghr help                                          Print this help and exit

Each <spec> is owner/repo[@tag] (auto-pick asset) or owner/repo/file[@tag] (specific asset). A 56-char RW/RU-prefixed base64 token immediately after a spec is treated as that spec's minisign public key. Run ghr <COMMAND> help to show help for a specific command, e.g. ghr download help.

Examples

# Install the latest release of a tool
ghr install burntsushi/ripgrep

# Install a specific version
# https://github.com/bytecodealliance/wasmtime/releases/tag/v44.0.1
ghr install bytecodealliance/wasmtime@v44.0.1

# Install several tools in one invocation (shared HTTP client + auth)
ghr install burntsushi/ripgrep@15.1.0 sharkdp/fd@v10.2.0

# Install minisign itself, verifying with its minisign public key
ghr install jedisct1/minisign@0.12 RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3

Install

pipx install ghr-bin
uv tool install ghr-bin
winget install ghr
brew install cataggar/ghr/ghr
curl -fsSL https://raw.githubusercontent.com/cataggar/ghr/main/install.sh | sh
iwr -useb https://raw.githubusercontent.com/cataggar/ghr/main/install.ps1 | iex
ghr install cataggar/ghr RWSbsumpaHb+N3KCEt/EUXQ5y6Kkk8r/zCb5Z4jhEuEX8x2/U5wr5QC0

See doc/README.md for download, install, directories, uninstall, and verification details (including verifying ghr's own releases).

GitHub Actions

For workflows, install several tools in one cached step:

- uses: cataggar/ghr/actions/install@v0.5.1  # pin to the matching ghr release
  with:
    tools: |
      burntsushi/ripgrep@14.1.1
      sharkdp/fd@v10.2.0

The action shares git tags with the ghr CLI — pinning @v0.5.1 pins both the action body and the ghr-bin binary. Pick the latest tag from the releases page.

See actions/install, actions/download, and the Caching in GitHub Actions section for details.

Signing releases

ghr minisign sign produces a minisign .minisig sidecar without an external minisign binary, a key file on disk, or an expect script. The secret key and password come from the environment, so a release job is a single step:

- run: ghr minisign sign hello.wasm -t "tag:${{ github.ref_name }} commit:${GITHUB_SHA}"
  env:
    MINISIGN_SECRET_KEY: ${{ secrets.MINISIGN_SECRET_KEY }}
    MINISIGN_PASSWORD:   ${{ secrets.MINISIGN_PASSWORD }}

Input files are bare positional arguments (each <file> is signed to <file>.minisig). A trusted comment may be given with -t (applied to every input); when omitted it defaults, like minisign, to timestamp:<unix>\tfile:<name>\thashed per file. The secret key must come from MINISIGN_SECRET_KEY and an encrypted key's password from MINISIGN_PASSWORD — there is no key-file flag, and the password is never read from a tty or stdin. Signatures use the prehashed (ED) format and are byte-for-byte identical to minisign -S output. Run ghr minisign sign help for all options.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

ghr_bin-0.6.9-py3-none-win_arm64.whl (1.0 MB view details)

Uploaded Python 3Windows ARM64

ghr_bin-0.6.9-py3-none-win_amd64.whl (1.1 MB view details)

Uploaded Python 3Windows x86-64

ghr_bin-0.6.9-py3-none-musllinux_1_1_x86_64.whl (1.0 MB view details)

Uploaded Python 3musllinux: musl 1.1+ x86-64

ghr_bin-0.6.9-py3-none-musllinux_1_1_aarch64.whl (1.0 MB view details)

Uploaded Python 3musllinux: musl 1.1+ ARM64

ghr_bin-0.6.9-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (1.0 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

ghr_bin-0.6.9-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl (1.0 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

ghr_bin-0.6.9-py3-none-macosx_11_0_arm64.whl (976.1 kB view details)

Uploaded Python 3macOS 11.0+ ARM64

ghr_bin-0.6.9-py3-none-macosx_10_9_x86_64.whl (1.0 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file ghr_bin-0.6.9-py3-none-win_arm64.whl.

File metadata

  • Download URL: ghr_bin-0.6.9-py3-none-win_arm64.whl
  • Upload date:
  • Size: 1.0 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ghr_bin-0.6.9-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 48e3f230a854fa20b2857382c609832280d2dd5c771883a37caba4820a00f7a0
MD5 0350ae11707c13acb84fe9e595c7c6d4
BLAKE2b-256 17379813a1830c7e02b80d89bed58060dca454908389a92821e446b297dc9167

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.9-py3-none-win_arm64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.9-py3-none-win_amd64.whl.

File metadata

  • Download URL: ghr_bin-0.6.9-py3-none-win_amd64.whl
  • Upload date:
  • Size: 1.1 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ghr_bin-0.6.9-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 386ff682715f89513d7b949da28b852f5686ec551ae26f3711efc4d88c7b7092
MD5 9a886c5eaac559b6b417fe3c807604bf
BLAKE2b-256 edd16d530babc38536aa7a27a9cc4e8ce95e4648f3291d65c451c9428373a2e8

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.9-py3-none-win_amd64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.9-py3-none-musllinux_1_1_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.9-py3-none-musllinux_1_1_x86_64.whl
Algorithm Hash digest
SHA256 134d15cacba8e878600d0c626e214e7a46905e633447bd77245807cf4f1ea1b7
MD5 a810950e9c04113f818af0830d93e0b9
BLAKE2b-256 622aaac6c7c386a5eace5a5ec02da7810683fd27521dc0e1d5913fa6d99fe82d

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.9-py3-none-musllinux_1_1_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.9-py3-none-musllinux_1_1_aarch64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.9-py3-none-musllinux_1_1_aarch64.whl
Algorithm Hash digest
SHA256 1cab7e0d3c5f6963ba4486d620659772bb2481a75c00e96cdd7a2798e3987831
MD5 5b7296c1f7b5db22b80d58ee61c78168
BLAKE2b-256 49497e1503adf250df016e81f6528b4538360f357b434f65a510d7d5c9d24229

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.9-py3-none-musllinux_1_1_aarch64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.9-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.9-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 d05b8a7a890871fc08caa2664bf6cbc13643c296d41489e0edb815445394907e
MD5 80e6d74c0c8c6683e88ad2f7330cc5f4
BLAKE2b-256 6fd3e7e025d52209aab8b495cf2ffb6bf18330d8f862b04d2eeed748648e11a7

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.9-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.9-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.9-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 8bd029fbc42c84598114a9a949a5c2110c778af89fc432492af0cf3e204fa5fb
MD5 dfe3eed7cdae6b6d34b92112799e42ac
BLAKE2b-256 848c948e2e2e12f3fbad41406bfc6d84ff2bec72b0ea45305eb454467931e561

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.9-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.9-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.9-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 d251c3d047db32796b5296eb99f55a80a0cee1fb932cbc3ed767d85e1060105f
MD5 5e173cf8262fc76518f476baf058e49c
BLAKE2b-256 661d49f55c3440eaca139ad83cf968184c4fdf6f7b64977dbe5bf2dbdfda627b

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.9-py3-none-macosx_11_0_arm64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ghr_bin-0.6.9-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for ghr_bin-0.6.9-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 43fcf4419bb31e1b75cd47a61e2321aa2a65da9e47f62f2f4543face99676b73
MD5 185bcf82088ce1d66ec20159a9f4ef0c
BLAKE2b-256 3780850f29ba621a2ea1b22e788973adb0f4df82d84fa58b07e621351df6623b

See more details on using hashes here.

Provenance

The following attestation bundles were made for ghr_bin-0.6.9-py3-none-macosx_10_9_x86_64.whl:

Publisher: pypi.yml on cataggar/ghr

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page