scriv-release
Changesets-style release automation on top of scriv.
scriv already manages per-PR changelog fragments. scriv-release adds the missing pieces for fully automated releases:
- A policy for mapping changelog categories to semver bump levels.
- Orchestration commands (
bump-level,next-version,collect,tag) that wrapscrivand a configurable version provider. - A GitHub Action that opens a "Changelog Preview" PR when fragments are pending, and tags a release once that PR is merged — the same flow popularized by Changesets in the JS ecosystem.
Quickstart
pip install "scriv-release[bump-my-version]"
# pyproject.toml
[tool.scriv-release]
version_provider = "bump-my-version"
In your repo's .github/workflows/release.yml:
on:
push:
branches: [main]
permissions: {}
jobs:
release:
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
steps:
- uses: actions/checkout@v6
with:
fetch-depth: 0
persist-credentials: false
- uses: whitphx/scriv-release@v0.4.0
with:
client-id: ${{ vars.RELEASE_APP_CLIENT_ID }}
app-private-key: ${{ secrets.RELEASE_APP_KEY }}
RELEASE_APP_CLIENT_ID and RELEASE_APP_KEY come from a GitHub App that you own. The action mints a short-lived installation token from the App so the tag-push it does at release time can trigger downstream workflows (the default GITHUB_TOKEN cannot — by design, to avoid recursion). To skip the manual App-creation flow, open
and click Create on your personal account (or fill the org name). GitHub's confirmation page is pre-populated with the recommended permissions (contents: write, pull_requests: write); submit, and the App is registered under your account. The page then walks you through generating a key, installing the App on the repo, and setting the secrets. See docs/token-setup.md for the longer explanation and a manual fallback.
For end-to-end onboarding, see docs/quickstart.md.
How it works
Two phases, branched on whether changelog fragments are present on HEAD:
- Fragments present →
scriv collectinto ascriv-release-previewbranch and open/update a "Changelog Preview" PR. - No fragments on
HEAD, but fragments onHEAD~1→ that means the preview PR was just merged. Determine the bump level fromHEAD~1's fragments, tag the release, push the tag.
This is the same file-presence-based detection Changesets uses, so it survives squash, rebase, and merge commits alike.
Status
Early scaffold. Public API and config keys may shift before 1.0.
License
MIT — see LICENSE.
Metadata
Release files for scriv-release 0.7.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| scriv_release-0.7.0.tar.gz | 145.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| scriv_release-0.7.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 161.3 kB
Release files / scriv_release-0.7.0.tar.gz
| Download URL | scriv_release-0.7.0.tar.gz |
|---|---|
| Size | 145.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4ecd94dc74d457c1166d14ec6593954aadcab3ef6ac748d34ed3d0eac1a060f6
|
|
BLAKE2b-256 checksum How to use checksums |
7880ae2514780b1229d802d938152e9ec737a9cad6323d2d1650f4cdffb34d35
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 16, 2026.
Transparency logRelease files / scriv_release-0.7.0-py3-none-any.whl
| Download URL | scriv_release-0.7.0-py3-none-any.whl |
|---|---|
| Size | 15.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
80147d9bcc8e18675969be39144d02e0d5147966bfac6604c7671c179431d472
|
|
BLAKE2b-256 checksum How to use checksums |
4245c0518d6c9715efc81c7c44504fc4ff4e847d32af537513346df1381706a3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 16, 2026.
Transparency log