git-orchard
A command-line utility for managing git-subtrees.
Install
AUR:
git-orchard is available from the Arch User Repository.
yay -S git-orchard
pip:
git-orchard is available as a pypi package.
pip install git-orchard
go:
go install github.com/jmelahman/git-orchard@latest
Usage
Subtrees are listed in a committed manifest at the repository root, .gitsubtrees or .config/git-orchard/subtrees (but not both), in the same syntax as .gitmodules:
[subtree "tools/foo"]
remote = git@github.com:owner/foo.git
branch = master
The same keys in git's own configuration (e.g. .git/config) override it for one clone.
Pulls and adds are squashed unless the manifest sets orchard.squash = false.
git orchard init # list the subtrees already in git history
git orchard add tools/foo git@github.com:owner/foo.git
git orchard status # commits ahead/behind each upstream
git orchard pull [prefix...] # merge upstream changes
git orchard push [prefix...] # publish, fast-forward only
git orchard push --changed-since REV # only subtrees changed since REV
git orchard push --tag tools/foo/v1.2.3 # publish as v1.2.3 upstream
git orchard release tools/foo # tag the next version, e.g. tools/foo/v1.2.4, and push it to origin
git orchard release tools/foo v2.0.0 # or a version of your choosing
Without a version, release picks one after the latest release, much as tag does: the patch version incremented (--minor and --major increment those instead), or a pre-release's stable release; --suffix rc picks the next release candidate, e.g. v1.2.4-rc, then v1.2.4-rc.1.
Releases are the <prefix>/v* tags in the monorepo and on its remote, and the v* tags upstream, so releases from before the subtree count; --dry-run prints the pick.
release requires the upstream branch to contain the release already, so the upstream tag lands on its history; --upstream pushes the branch and tag there directly instead of leaving it to the action.
push, pull and release take --no-verify to skip git hooks.
push --force overwrites upstream branches and tags, leased on their value when the push starts so a concurrent update still fails it; the action never forces.
release --force moves an existing tag, unless the upstream already published it at another commit: the Go module proxy and release artifacts won't follow a moved release.
push splits each subtree out of the monorepo with git subtree split, which is deterministic, so the same history always gives the same commits and every push is a fast-forward.
An upstream with commits the monorepo doesn't have rejects the push until they're pulled in.
git-orchard only runs git, so credentials, SSH config and url.<base>.insteadOf rewrites apply as usual.
GitHub Action
This repository is also an action that mirrors a monorepo's subtrees on every push: changed subtrees are pushed to their upstreams, and a <prefix>/<name> tag is published to that prefix's upstream as <name>.
on:
push:
branches: [master]
tags: ["**/v*"] # `*` doesn't match `/`
jobs:
mirror:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
with:
fetch-depth: 0 # splits need the full history
persist-credentials: false
- uses: jmelahman/git-orchard@v1
with:
app-client-id: ${{ vars.ORCHARD_APP_CLIENT_ID }}
app-private-key: ${{ secrets.ORCHARD_APP_PRIVATE_KEY }}
The action pushes as a GitHub App, which git orchard github-app creates:
git orchard github-app # add --org ORG for an organization's repositories
It opens a browser to create a private App under your account from a manifest (contents and workflows write, no webhook), then to install it: pick the upstream repositories there.
With the GitHub CLI installed, it stores the App's client ID and private key on the monorepo (origin, or --repo) as the ORCHARD_APP_CLIENT_ID variable and ORCHARD_APP_PRIVATE_KEY secret; otherwise it writes the key to a file and prints the gh commands to store it.
The App and its key are yours; git-orchard runs no service.
The action mints a short-lived token from the App's installation for owner (default: the monorepo's owner).
Alternatively, pass token, e.g. a fine-grained token with "Contents" and "Workflows" read and write on the upstreams; GitHub refuses pushes that change .github/workflows without the latter.
Either way, GitHub remotes in the manifest are rewritten to use the token.
changed-since defaults to the start of the pushed range; set it empty to push every subtree.
The action builds git-orchard from its own source, so the CLI is always the version the action is pinned to.
Release files for git-orchard 1.0.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| git_orchard-1.0.3-py3-none-win_arm64.whl | Python 3 | none | Windows ARM64 | Details |
| git_orchard-1.0.3-py3-none-manylinux_2_17_x86_64.whl | Python 3 | none | Linux glibc 2.17+ x86-64 | Details |
| git_orchard-1.0.3-py3-none-macosx_11_0_arm64.whl | Python 3 | none | macOS 11.0+ ARM64 | Details |
| git_orchard-1.0.3-py3-none-macosx_10_12_x86_64.whl | Python 3 | none | macOS 10.12+ x86-64 | Details |
Total release size: 16.5 MB
Release files / git_orchard-1.0.3-py3-none-win_arm64.whl
| Download URL | git_orchard-1.0.3-py3-none-win_arm64.whl |
|---|---|
| Size | 3.9 MB |
| Tags | Python 3 Windows ARM64 |
|
SHA-256 checksum How to use checksums |
f85334b116458dc77c9dfc41f0b927e33be87cf7473486b9a6b3d4348aaf9d9e
|
|
BLAKE2b-256 checksum How to use checksums |
2b05f1d62823bde8fde8124f80a7fd29f766e0ca5dd13cdbff9409333477217f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.18 {"installer":{"name":"uv","version":"0.12.18","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / git_orchard-1.0.3-py3-none-manylinux_2_17_x86_64.whl
| Download URL | git_orchard-1.0.3-py3-none-manylinux_2_17_x86_64.whl |
|---|---|
| Size | 4.3 MB |
| Tags | Linux glibc 2.17+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
d6e81a172f21b810a43d2074c4041f51ad89557c21e9facd75e8b45fc28391da
|
|
BLAKE2b-256 checksum How to use checksums |
143355afc99047e207a1493cbcc35c7c828b8792a7dd279b9226a9d15f51d80b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.18 {"installer":{"name":"uv","version":"0.12.18","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / git_orchard-1.0.3-py3-none-macosx_11_0_arm64.whl
| Download URL | git_orchard-1.0.3-py3-none-macosx_11_0_arm64.whl |
|---|---|
| Size | 4.0 MB |
| Tags | Python 3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
4ec5d162fca88e662440dc1b4830bc4f597be5ce1611f0f000c17ed7c79a4ad8
|
|
BLAKE2b-256 checksum How to use checksums |
f3a3bd44587586d4817a57078ec9f91b5553362fdaf90ccf2c46f05e362ed6a2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.18 {"installer":{"name":"uv","version":"0.12.18","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / git_orchard-1.0.3-py3-none-macosx_10_12_x86_64.whl
| Download URL | git_orchard-1.0.3-py3-none-macosx_10_12_x86_64.whl |
|---|---|
| Size | 4.3 MB |
| Tags | Python 3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
6ee5ceaf8f254bd573d83fb464ac2d7f8fdfa365e27231ec9fdc45e9dd77e92d
|
|
BLAKE2b-256 checksum How to use checksums |
047dd878cf159644255c140dac650dc112bf46c1f94086991479657b940ad90c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.18 {"installer":{"name":"uv","version":"0.12.18","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|