Skip to content

Repository files navigation

🚀 Simple GitHub CLI (sgh-cli)

Bulk GitHub operations across an entire organization. Create a release branch in 200 repositories, review every open PR your team filed this week, or find which repos still have branch protection disabled — with one command instead of a shell loop.

CI Go Version License

Disclaimer: This project is an independent, community-built tool and is not affiliated with, endorsed by, or sponsored by GitHub, Inc. "GitHub" is a trademark of GitHub, Inc.

Why this exists

GitHub's own gh is excellent and repository-scoped by design. sgh is the other axis: every command takes an organization and fans out across its repositories concurrently, with regex include/exclude filtering, a shared worker pool, rate-limit handling, and --dry-run on anything destructive.

sgh branch create --org my-org --new Release-2.0 --ref main --dry-run
sgh pr list --org my-org --state open --sort repo
sgh workflow list --org my-org --failed --branch main
sgh protected-branch list --org my-org --branch main

Features

  • Branches and tags — create, rename, delete, and filter across every repository
  • Pull requests — create, list, view, review, update, merge, close, reopen in bulk, plus an interactive selector
  • GitHub Actions — list, view, rerun, cancel, dispatch, and approve/reject workflow runs waiting on environment gates, with live monitoring
  • Branch protection — inspect and update protection rules org-wide
  • Repository lifecycle — archive/unarchive and flip visibility in bulk
  • Issues, teams, org audit log, and secret scanning alerts
  • Interactive TUI dashboard — sgh tui
  • Per-owner tokens in your OS keyring — never the config file, with a plaintext fallback when no keyring is available
  • Built for scale — concurrent workers, rate-limit tracking, exponential backoff, circuit breaking
  • Scriptable — --output table|compact|json, shell completion for Bash/Zsh/Fish/PowerShell

Install

brew install pradyb/tap/sgh
# or
go install github.com/pradyb/sgh-cli/cmd/sgh@latest

Or download a prebuilt binary for Linux, macOS, or Windows from the releases page — each release publishes checksums.txt alongside the binaries.

Full instructions, including building from source and shell completion: docs/installation.md

Quick start

1. Create a token. A fine-grained PAT is recommended. The permissions table lists exactly what each feature needs — for read-only use you need very little. workflow approve additionally needs Deployments (write) and the token's user must be a required reviewer of the environment.

2. Set your environment:

export SGH_TOKEN=your_token_here
export SGH_ORG=your-org        # so you can drop --org from every command

3. Check it works:

sgh health
sgh whoami

4. Do something useful:

# What's open across the org?
sgh pr list --org your-org

# Cut a release branch everywhere — preview first
sgh branch create --org your-org --new Release-1.1 --ref main --dry-run
sgh branch create --org your-org --new Release-1.1 --ref main

Preview before you commit. Every write command accepts --dry-run. On a tool that acts on every repository at once, that flag is the difference between a bulk operation and a bulk incident.

Commands

Group Commands
Repositories repo · clone · commit · issue
Git branch · tag · pr · protected-branch
CI/CD workflow · post-release
Organization org · team · security · audit
Utilities config · tui · whoami · health · shortcuts · version · completion

Most list and view subcommands have a single-word shortcut — prl, brl, wfl, rpl. Run sgh shortcuts for the full set.

Full reference with every alias, subcommand, and flag: docs/commands.md

Documentation

Installation Install and upgrade methods, checksums, shell completion
Authentication Token types and the permissions each feature needs
Configuration Config file, per-owner tokens, repository filtering
Command reference Every command, flag, and shorthand
Usage examples Working examples per command group
Advanced usage Scripting, concurrency, rate limits
Troubleshooting 403s, rate limits, empty results
Development Building, testing, architecture

🔒 Security

To report a security vulnerability, do not open a public GitHub issue. See the Security Policy for responsible disclosure instructions.

Token safety:

  • Per-owner tokens are stored in your OS keyring, not the config file — see Per-owner tokens. If no keyring is available, sgh falls back to the config file in plain text (with a warning); keep it out of version control regardless
  • Prefer fine-grained PATs scoped to the repositories you actually need
  • Rotate immediately if you suspect exposure

🤝 Contributing

Contributions are welcome. For anything substantial, open an issue first so we can agree on the approach before you write code. See CONTRIBUTING.md for the process and docs/development.md for the build and test setup.

📄 License

MIT — see LICENSE.

Copyright (c) 2024 Pradeep Kumar Balakrishnan

Third-party dependency licenses are listed in THIRD_PARTY_NOTICES.md.

🙏 Acknowledgments

Built with Cobra, Bubble Tea and Bubbles, Lipgloss, Progressbar, and Zerolog, on top of the GitHub REST and GraphQL APIs.

About

Bulk GitHub operations across an entire organization

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages