Skip to main content

repomatic

Last release Python versions Downloads Unittests status Documentation status

A Python CLI and pyproject.toml configuration that let you release Python packages multiple times a day with only 2-clicks. Designed for uv-based Python projects, but usable for other projects too. Every step is a CLI command: reusable GitHub Actions workflows are only the trigger, so the same automation runs on your machine.

Maintainer-in-the-loop: nothing is done behind your back. Every change repomatic proposes arrives as a PR you review; every action it needs from you opens an issue.

What it automates

  • Version bumping, git tagging, and GitHub release creation
  • Changelog management
  • Python package building and PyPI publishing with supply chain attestations
  • Cross-platform binary compilation (Linux / macOS / Windows, x86_64 / arm64)
  • Formatting autofix for Python, Markdown, JSON, Shell, and typos
  • Linting: Python types with mypy, YAML, GitHub Actions, workflow security, URLs, secrets, and Awesome lists
  • Synchronization of uv.lock, GitHub Action pins, workflow version literals, and repomatic run tool versions with configurable stabilization cooldowns
  • Synchronization of .gitignore, .mailmap, and Mermaid dependency graph
  • Label management with file-based and content-based rules
  • Inactive issue locking
  • Static image optimization
  • Sphinx documentation building, deployment, and autodoc updates
  • Awesome list template synchronization

Why repomatic

repomatic does for the release process what ruff did for linting and uv did for packaging: replace a stack of single-purpose tools with one.

  • 23 third-party GitHub Actions replaced by internal CLI commands and SHA-256-verified binary downloads, keeping the supply chain attack surface minimal
  • 10 Python linters and formatters (pylint, pydocstyle, pycln, pyupgrade, isort, black, docformatter, mdformat-black, blacken-docs, mdformat-ruff) consolidated into ruff
  • 5 packaging and install tools (poetry, build, twine, check-wheel-contents, pip-audit) consolidated into uv
  • All uses: references pinned to full commit SHAs with stabilization windows before adopting new versions, managed entirely by self-hosted sync jobs
  • SLSA provenance attestations on every release artifact (wheels and compiled binaries)
  • VirusTotal scanning of compiled binaries to seed AV vendor databases and reduce false positives
  • Trusted Publishing for PyPI uploads: no long-lived tokens stored as secrets
  • Immutable releases enforced via GitHub's tag protection and release locking
  • Workflow security linting with zizmor on every push to catch dangerous triggers and excessive permissions
  • Credential scanning with gitleaks to prevent secret leakage
  • Single pyproject.toml configuration: no extra dotfiles, no JSON configs, no YAML presets to maintain
  • The CLI itself ships as standalone binaries (Linux / macOS / Windows, x86_64 / arm64): no Python environment needed to run it
  • 15+ code quality tools (ruff, mypy, biome, typos, mdformat, shfmt, yamllint, actionlint, lychee, oxipng, pyproject-fmt, labelmaker, gitleaks, zizmor) managed through one repomatic run <tool> interface with automatic installation and platform-specific binary caching

Quick start

$ cd my-project
$ uvx -- repomatic init
$ git add .
$ git commit -m "Add repomatic"
$ git push

Works for new and existing repositories. Managed files are always regenerated to the latest version; changelog.md is never overwritten. Push, and the workflows guide you through remaining setup via issues and PRs.

The workflows only call CLI commands, so every automated step can also be run and previewed locally:

$ uvx -- repomatic sync-deps --dry-run
$ uvx -- repomatic run ruff -- check

Animated terminal recording of a sync-deps dry run

repomatic help screen, listing every subcommand

See repomatic init --help for available components and options.

Documentation

See the full documentation for:

Used in

Check these projects to get real-life examples of usage and inspiration:

Send a PR to add your project if you use repomatic.

Metadata

Release files for repomatic 7.17.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for repomatic 7.17.0
File Size Uploaded
repomatic-7.17.0.tar.gz 3.0 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for repomatic 7.17.0
File Interpreter ABI Platform
repomatic-7.17.0-py3-none-any.whl Python 3 none any Details

Total release size: 4.1 MB

Release files / repomatic-7.17.0.tar.gz

Download URL repomatic-7.17.0.tar.gz
Size 3.0 MB
Tags Source
SHA-256 checksum
How to use checksums
ac7e13ac498df95b4bcb5af01f0de17a78e83e0c437b7913be3e6cd87c834b84
BLAKE2b-256 checksum
How to use checksums
0425ea4953f9bfde5efa19f5b1dbd7edbbcb27970c2a77b569211e0c2dd7d44f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"26.04","id":"resolute","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / repomatic-7.17.0-py3-none-any.whl

Download URL repomatic-7.17.0-py3-none-any.whl
Size 1.1 MB
Tags Python 3
SHA-256 checksum
How to use checksums
059b80f68bd27c968653003d2a009a39dc7b203f19648f730c441aede0dc0ce0
BLAKE2b-256 checksum
How to use checksums
fbe2ef0dd4eefa46b9d3e50688045349d614ece2f29549636fc32ad9b317b73e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"26.04","id":"resolute","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release history Release notifications | RSS feed

7.17.1

2 release files

This release

7.17.0 This release

2 release files

7.16.3

2 release files

7.16.2

2 release files

7.16.1

2 release files

7.16.0

2 release files

7.14.0

2 release files

7.13.0

2 release files

7.12.1

2 release files

7.12.0

2 release files

7.11.0

2 release files

7.10.0

2 release files

7.9.0

2 release files

7.8.0

2 release files

7.7.0

2 release files

7.6.0

2 release files

7.5.0

2 release files

7.4.1

2 release files

7.4.0

2 release files

7.3.1

2 release files

7.3.0

2 release files

7.2.0

2 release files

7.1.0

2 release files

7.0.0

2 release files

6.31.0

2 release files

6.30.0

2 release files

6.29.0

2 release files

6.28.1

2 release files

6.28.0

2 release files

6.27.0

2 release files

6.26.0

2 release files

6.25.1

2 release files

6.25.0

2 release files

6.24.0

2 release files

6.23.0

2 release files

6.22.0

2 release files

6.21.0

2 release files

6.20.0

2 release files

6.19.0

2 release files

6.18.4

2 release files

6.18.3

2 release files

6.16.0

2 release files

6.15.0

2 release files

6.14.0

2 release files

6.13.0

2 release files

6.12.0

2 release files

6.9.0

2 release files

6.8.0

2 release files

6.7.0

2 release files

6.6.0

2 release files

6.5.0

2 release files

6.4.1

2 release files

6.4.0

2 release files

6.3.2

2 release files

6.3.1

2 release files

6.3.0

2 release files

6.2.1

2 release files

6.2.0

2 release files

6.1.0

2 release files

6.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page