Bulk GitHub operations across an entire organization. Create a release branch in 200 repositories, review every open PR your team filed this week, or find which repos still have branch protection disabled — with one command instead of a shell loop.
Disclaimer: This project is an independent, community-built tool and is not affiliated with, endorsed by, or sponsored by GitHub, Inc. "GitHub" is a trademark of GitHub, Inc.
GitHub's own gh is excellent and repository-scoped by design. sgh is the other axis: every command takes an organization and fans out across its repositories concurrently, with regex include/exclude filtering, a shared worker pool, rate-limit handling, and --dry-run on anything destructive.
sgh branch create --org my-org --new Release-2.0 --ref main --dry-run
sgh pr list --org my-org --state open --sort repo
sgh workflow list --org my-org --failed --branch main
sgh protected-branch list --org my-org --branch main- Branches and tags — create, rename, delete, and filter across every repository
- Pull requests — create, list, view, review, update, merge, close, reopen in bulk, plus an interactive selector
- GitHub Actions — list, view, rerun, cancel, dispatch, and approve/reject workflow runs waiting on environment gates, with live monitoring
- Branch protection — inspect and update protection rules org-wide
- Repository lifecycle — archive/unarchive and flip visibility in bulk
- Issues, teams, org audit log, and secret scanning alerts
- Interactive TUI dashboard —
sgh tui - Per-owner tokens in your OS keyring — never the config file, with a plaintext fallback when no keyring is available
- Built for scale — concurrent workers, rate-limit tracking, exponential backoff, circuit breaking
- Scriptable —
--output table|compact|json, shell completion for Bash/Zsh/Fish/PowerShell
brew install pradyb/tap/sgh
# or
go install github.com/pradyb/sgh-cli/cmd/sgh@latestOr download a prebuilt binary for Linux, macOS, or Windows from the releases page — each release publishes checksums.txt alongside the binaries.
Full instructions, including building from source and shell completion: docs/installation.md
1. Create a token. A fine-grained PAT is recommended. The permissions table lists exactly what each feature needs — for read-only use you need very little. workflow approve additionally needs Deployments (write) and the token's user must be a required reviewer of the environment.
2. Set your environment:
export SGH_TOKEN=your_token_here
export SGH_ORG=your-org # so you can drop --org from every command3. Check it works:
sgh health
sgh whoami4. Do something useful:
# What's open across the org?
sgh pr list --org your-org
# Cut a release branch everywhere — preview first
sgh branch create --org your-org --new Release-1.1 --ref main --dry-run
sgh branch create --org your-org --new Release-1.1 --ref mainPreview before you commit. Every write command accepts
--dry-run. On a tool that acts on every repository at once, that flag is the difference between a bulk operation and a bulk incident.
| Group | Commands |
|---|---|
| Repositories | repo · clone · commit · issue |
| Git | branch · tag · pr · protected-branch |
| CI/CD | workflow · post-release |
| Organization | org · team · security · audit |
| Utilities | config · tui · whoami · health · shortcuts · version · completion |
Most list and view subcommands have a single-word shortcut — prl, brl, wfl, rpl. Run sgh shortcuts for the full set.
Full reference with every alias, subcommand, and flag: docs/commands.md
| Installation | Install and upgrade methods, checksums, shell completion |
| Authentication | Token types and the permissions each feature needs |
| Configuration | Config file, per-owner tokens, repository filtering |
| Command reference | Every command, flag, and shorthand |
| Usage examples | Working examples per command group |
| Advanced usage | Scripting, concurrency, rate limits |
| Troubleshooting | 403s, rate limits, empty results |
| Development | Building, testing, architecture |
To report a security vulnerability, do not open a public GitHub issue. See the Security Policy for responsible disclosure instructions.
Token safety:
- Per-owner tokens are stored in your OS keyring, not the config file — see Per-owner tokens. If no keyring is available,
sghfalls back to the config file in plain text (with a warning); keep it out of version control regardless - Prefer fine-grained PATs scoped to the repositories you actually need
- Rotate immediately if you suspect exposure
Contributions are welcome. For anything substantial, open an issue first so we can agree on the approach before you write code. See CONTRIBUTING.md for the process and docs/development.md for the build and test setup.
MIT — see LICENSE.
Copyright (c) 2024 Pradeep Kumar Balakrishnan
Third-party dependency licenses are listed in THIRD_PARTY_NOTICES.md.
Built with Cobra, Bubble Tea and Bubbles, Lipgloss, Progressbar, and Zerolog, on top of the GitHub REST and GraphQL APIs.