DevSecOps CLI  •  MIT  •  now on PyPI

Forge your code.
Push anywhere.

PushForge turns publishing a project to GitHub into one command — detecting your stack, shielding your secrets, then building, committing and shipping in a single breath.

Read the docs
~/projects/ai-assistant — pushforge
$ pushforge
  ✓ GitHub account connected            (first time only)
  ✓ Project detected                    Python / FastAPI
  ✓ .gitignore generated
  ✓ Security scan completed             0 secrets
  ✓ Git repository initialized
  ✓ GitHub repository created
  ✓ Commit created
  ✓ Code pushed successfully

🚀 Project pushed successfully!
https://github.com/you/ai-assistant
The pipeline

One command. Six checkpoints.

Everything between "I have code" and "it's live on GitHub" — automated and safe.

01

Detect

PushForge reads your project and recognizes the stack — Python, Node, Go, Docker, Terraform and more.

02

Secure

A secret scan sweeps your files for credentials and blocks the push before a leak can ever happen.

03

Init

A carefully built .gitignore is generated and a Git repository is initialized for you.

04

Create

The GitHub repository is created (public or private) with a normalized, readable name.

05

Commit

A clear first commit is authored on main — or your preferred branch.

06

Push

Your code lands on GitHub. Incremental re-runs only ever push what's new.

Why PushForge

Built for the daily push

The things you'd otherwise type by hand, folded into one habit.

⚡

One command per project

In a brand-new or existing folder, pushforge is the whole workflow. No setup rituals.

🛡️

Security-first by default

Secret scanning blocks accidental credential leaks before they ever reach GitHub.

🏗️

CI/CD from day one

pushforge pipeline writes a GitHub Actions workflow matched to your stack — and auto-generates a README when there's none.

🔁

Incremental and safe

No force-pushes, no overwrites, no duplicate repositories. Repo state is respected every time.

🌍

Cross-platform

Linux, macOS and Windows. Same command, same output, anywhere.

🔒

Credentials protected

Tokens live in your OS keyring, never in your project. And they're never printed.

🧩

Designed to grow

Dockerize, deploy and AI assistance remain on the roadmap — CI/CD pipelines and auto-generated READMEs are already live.

Security model

Secrets never ship.

PushForge watches for API keys, private keys, database credentials and high-entropy tokens in your files. If something looks live, the push is blocked and the value is never displayed.

pushforge
⚠ Potential secret detected

  ✗ AWS key      config.py:12
  ✗ GitHub token  api/client.py:88

Push blocked to protect your credentials.
Remove the secrets and run 'pushforge' again.
✓

No force-push unless you explicitly opt in

✓

Existing repos & remotes are never overwritten

✓

Values never shown — at most a fingerprint

✓

Inline # pushforge-ignore for trusted fixtures

Install

Available on every OS

Python 3.11+ and git are all you need. Then it works in any folder.

Install
# Debian / Ubuntu
sudo apt install pipx
pipx install pushforge

# Fedora / Arch or any distribution
pipx install pushforge

# one-time path setup (adds ~/.local/bin)
pipx ensurepath
Use it anywhere
cd ~/projects/my-app
pushforge --version      # ✓ works from any folder
pushforge --dry-run      # preview, change nothing
pushforge --private       # publish a private repo
Install (Homebrew pipx)
brew install pipx
pipx install pushforge

# or without Homebrew, using pip
pip3 install --user pushforge
Apple Silicon note
# PyPI ships a universal wheel — no compilation.
# Works identically on Intel and Apple Silicon.
pipx install pushforge
pushforge --version
Install (PowerShell)
# install with pip (remember to enable "Add python.exe to PATH")
py -m pip install --user pushforge

# or with pipx
pipx install pushforge
Use it anywhere
cd C:\Users\you\my-app
pushforge --version
pushforge --private
Verify the install
# The magic is that install = done. No config, no env vars.
pushforge --version
pushforge auth status   # connect your account once
Proof, not promises

Fresh machine in 5 minutes

Every step above lands on a brand-new laptop the same way it does here. No hidden config.

Smoke test — new laptop
# 1. Tooling
sudo apt install pipx gh      # or: brew install pipx gh
pipx ensurepath && exec $SHELL

# 2. Install from PyPI (always the latest build)
pipx install pushforge

# 3. Connect GitHub once (uses gh; falls back to OAuth device flow)
pushforge auth login

# 4. Real publish test
mkdir ~/test-app && cd ~/test-app
echo "from fastapi import FastAPI" > main.py
echo -e "fastapi\npytest" > requirements.txt
pushforge     # detect → secure → gitignore → README → repo → commit → push

# 5. Bonus checks
pushforge pipeline     # CI/CD workflow for your stack
pushforge scan         # secret scan
Reference

The whole surface of PushForge

Small enough to remember, deep enough to automate everything.

CommandWhat it does
pushforgePublish the current project in one command
pushforge --privateCreate a private repository
pushforge -n my-repo -m "feat: init"Custom name and commit message
pushforge --dry-runPreview everything without touching anything
pushforge scanScan the project for potential secrets
pushforge pipelineGenerate a CI workflow for your stack
pushforge readmeGenerate a README when there's none
pushforge statusShow project / repo / auth summary
pushforge config --visibility privatePersist your default preferences
pushforge auth loginConnect GitHub with device flow (once)
Roadmap

From one command to a forge

The MVP ships without AI. These additions slot right onto the same core.

✅

pushforge pipeline · shipped

Generate GitHub Actions workflows matched to your stack.

✅

auto-README · shipped

Write a compact README when a project has none.

🐳

pushforge dockerize

Add a Dockerfile & docker-compose in seconds.

🚀

pushforge deploy

Deploy targets for the platforms you already use.

🧭

pushforge secure

Deep dependency and configuration auditing.

🤖

pushforge ai

LLM-assisted commit messages & security explains.

Ship in one command.

pipx install pushforge — then watch the forge do the work.