2026-07-22 15:16:42 +00:00
# stoke
2026-07-26 23:11:30 +00:00
> CLI for the heavy-duty forge ([Forgejo](https://forgejo.org/)). Named for feeding a fire — the operator’ s hand on the forge.
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
`stoke` turns real forge work into commands: auth, repos, issues, PRs, releases, labels, orgs, and a raw API escape hatch. Default instance: [`https://forgejo.heavyduty.builders` ](https://forgejo.heavyduty.builders ).
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
Built with [Commander.js ](https://github.com/tj/commander.js/ ). Node.js ** ≥ 22.12** required.
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
---
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
## Install
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
**Debian / Ubuntu (recommended)**
Add apt distribution: deb packaging, registry publish, docs (#1)
Implements #1 — stoke installable with apt-get install stoke.
Packaging:
- scripts/build-deb.sh: builds dist/stoke_<version>_all.deb from a clean
staging copy (src + fresh npm ci --omit=dev), pure-JS Architecture: all,
Depends: nodejs (>= 22.12), /usr/lib/stoke payload with /usr/bin/stoke
symlink, copyright + changelog, normalized permissions. Lintian-clean.
- scripts/publish-deb.sh: uploads a .deb to the Forgejo Debian registry
(owner/distribution/component parameterized, defaults heavy-duty/
stable/main), authenticating with STOKE_TOKEN or the stoke login token.
- scripts/install-apt.sh: consumer-side one-time setup — adds the
registry key and apt source, then apt-get install stoke. Falls back to
a [trusted=yes] source when apt's sqv verifier rejects the forge's
registry signature (known upstream Forgejo signing bug; the script
prefers the signed source so setups heal once the forge is fixed).
- .forgejo/workflows/release.yml: on v* tags — test, build, publish to
the heavy-duty registry, attach the .deb to the release page. Needs a
runner and a RELEASE_TOKEN secret with org package write.
New command:
- stoke pr merge (-n, --method merge|rebase|rebase-merge|squash,
--title, --message, --delete-branch) — gap found while merging !2.
Docs and housekeeping:
- README: 'Install with apt' as the primary installation method with
manual setup and dpkg fallback, signature caveat, pr merge reference,
Packaging and releasing section with a release checklist.
- dist/ gitignored; version bumped to 1.2.0.
Verified end-to-end on this machine: built the deb (lintian-clean),
published it to the Forgejo Debian registry, installed it with
apt-get install stoke via install-apt.sh, and confirmed the installed
CLI works against the live forge. The test upload was removed from the
personal namespace afterwards; publishing under heavy-duty needs an
org-member token (401 reqPackageAccess with this restricted account).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 19:40:51 +00:00
```bash
curl -fsSL https://forgejo.heavyduty.builders/heavy-duty/stoke/raw/branch/main/scripts/install-apt.sh | bash
```
2026-07-26 23:11:30 +00:00
That script adds the forge’ s Debian registry, bootstraps Node 22 when the distro package is too old, and installs `stoke` . Upgrades then come with `apt-get upgrade` .
2026-07-22 21:39:51 +00:00
2026-07-26 23:11:30 +00:00
**From source**
2026-07-22 21:56:26 +00:00
```bash
2026-07-26 23:11:30 +00:00
npm install & & npm link
# or: node src/cli.js <command>
Add apt distribution: deb packaging, registry publish, docs (#1)
Implements #1 — stoke installable with apt-get install stoke.
Packaging:
- scripts/build-deb.sh: builds dist/stoke_<version>_all.deb from a clean
staging copy (src + fresh npm ci --omit=dev), pure-JS Architecture: all,
Depends: nodejs (>= 22.12), /usr/lib/stoke payload with /usr/bin/stoke
symlink, copyright + changelog, normalized permissions. Lintian-clean.
- scripts/publish-deb.sh: uploads a .deb to the Forgejo Debian registry
(owner/distribution/component parameterized, defaults heavy-duty/
stable/main), authenticating with STOKE_TOKEN or the stoke login token.
- scripts/install-apt.sh: consumer-side one-time setup — adds the
registry key and apt source, then apt-get install stoke. Falls back to
a [trusted=yes] source when apt's sqv verifier rejects the forge's
registry signature (known upstream Forgejo signing bug; the script
prefers the signed source so setups heal once the forge is fixed).
- .forgejo/workflows/release.yml: on v* tags — test, build, publish to
the heavy-duty registry, attach the .deb to the release page. Needs a
runner and a RELEASE_TOKEN secret with org package write.
New command:
- stoke pr merge (-n, --method merge|rebase|rebase-merge|squash,
--title, --message, --delete-branch) — gap found while merging !2.
Docs and housekeeping:
- README: 'Install with apt' as the primary installation method with
manual setup and dpkg fallback, signature caveat, pr merge reference,
Packaging and releasing section with a release checklist.
- dist/ gitignored; version bumped to 1.2.0.
Verified end-to-end on this machine: built the deb (lintian-clean),
published it to the Forgejo Debian registry, installed it with
apt-get install stoke via install-apt.sh, and confirmed the installed
CLI works against the live forge. The test upload was removed from the
personal namespace afterwards; publishing under heavy-duty needs an
org-member token (401 reqPackageAccess with this restricted account).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 19:40:51 +00:00
```
2026-07-26 23:11:30 +00:00
**Notes**
Add apt distribution: deb packaging, registry publish, docs (#1)
Implements #1 — stoke installable with apt-get install stoke.
Packaging:
- scripts/build-deb.sh: builds dist/stoke_<version>_all.deb from a clean
staging copy (src + fresh npm ci --omit=dev), pure-JS Architecture: all,
Depends: nodejs (>= 22.12), /usr/lib/stoke payload with /usr/bin/stoke
symlink, copyright + changelog, normalized permissions. Lintian-clean.
- scripts/publish-deb.sh: uploads a .deb to the Forgejo Debian registry
(owner/distribution/component parameterized, defaults heavy-duty/
stable/main), authenticating with STOKE_TOKEN or the stoke login token.
- scripts/install-apt.sh: consumer-side one-time setup — adds the
registry key and apt source, then apt-get install stoke. Falls back to
a [trusted=yes] source when apt's sqv verifier rejects the forge's
registry signature (known upstream Forgejo signing bug; the script
prefers the signed source so setups heal once the forge is fixed).
- .forgejo/workflows/release.yml: on v* tags — test, build, publish to
the heavy-duty registry, attach the .deb to the release page. Needs a
runner and a RELEASE_TOKEN secret with org package write.
New command:
- stoke pr merge (-n, --method merge|rebase|rebase-merge|squash,
--title, --message, --delete-branch) — gap found while merging !2.
Docs and housekeeping:
- README: 'Install with apt' as the primary installation method with
manual setup and dpkg fallback, signature caveat, pr merge reference,
Packaging and releasing section with a release checklist.
- dist/ gitignored; version bumped to 1.2.0.
Verified end-to-end on this machine: built the deb (lintian-clean),
published it to the Forgejo Debian registry, installed it with
apt-get install stoke via install-apt.sh, and confirmed the installed
CLI works against the live forge. The test upload was removed from the
personal namespace afterwards; publishing under heavy-duty needs an
org-member token (401 reqPackageAccess with this restricted account).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 19:40:51 +00:00
2026-07-26 23:11:30 +00:00
- On some apt versions (`sqv` / Debian 13+), Forgejo’ s registry signature is rejected (upstream bug). The installer falls back to `[trusted=yes]` over HTTPS; once the forge signature is fixed, the signed source is preferred again.
- Each release also attaches a `.deb` for `sudo dpkg -i stoke_<version>_all.deb` .
Add apt distribution: deb packaging, registry publish, docs (#1)
Implements #1 — stoke installable with apt-get install stoke.
Packaging:
- scripts/build-deb.sh: builds dist/stoke_<version>_all.deb from a clean
staging copy (src + fresh npm ci --omit=dev), pure-JS Architecture: all,
Depends: nodejs (>= 22.12), /usr/lib/stoke payload with /usr/bin/stoke
symlink, copyright + changelog, normalized permissions. Lintian-clean.
- scripts/publish-deb.sh: uploads a .deb to the Forgejo Debian registry
(owner/distribution/component parameterized, defaults heavy-duty/
stable/main), authenticating with STOKE_TOKEN or the stoke login token.
- scripts/install-apt.sh: consumer-side one-time setup — adds the
registry key and apt source, then apt-get install stoke. Falls back to
a [trusted=yes] source when apt's sqv verifier rejects the forge's
registry signature (known upstream Forgejo signing bug; the script
prefers the signed source so setups heal once the forge is fixed).
- .forgejo/workflows/release.yml: on v* tags — test, build, publish to
the heavy-duty registry, attach the .deb to the release page. Needs a
runner and a RELEASE_TOKEN secret with org package write.
New command:
- stoke pr merge (-n, --method merge|rebase|rebase-merge|squash,
--title, --message, --delete-branch) — gap found while merging !2.
Docs and housekeeping:
- README: 'Install with apt' as the primary installation method with
manual setup and dpkg fallback, signature caveat, pr merge reference,
Packaging and releasing section with a release checklist.
- dist/ gitignored; version bumped to 1.2.0.
Verified end-to-end on this machine: built the deb (lintian-clean),
published it to the Forgejo Debian registry, installed it with
apt-get install stoke via install-apt.sh, and confirmed the installed
CLI works against the live forge. The test upload was removed from the
personal namespace afterwards; publishing under heavy-duty needs an
org-member token (401 reqPackageAccess with this restricted account).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 19:40:51 +00:00
2026-07-26 23:11:30 +00:00
---
Add apt distribution: deb packaging, registry publish, docs (#1)
Implements #1 — stoke installable with apt-get install stoke.
Packaging:
- scripts/build-deb.sh: builds dist/stoke_<version>_all.deb from a clean
staging copy (src + fresh npm ci --omit=dev), pure-JS Architecture: all,
Depends: nodejs (>= 22.12), /usr/lib/stoke payload with /usr/bin/stoke
symlink, copyright + changelog, normalized permissions. Lintian-clean.
- scripts/publish-deb.sh: uploads a .deb to the Forgejo Debian registry
(owner/distribution/component parameterized, defaults heavy-duty/
stable/main), authenticating with STOKE_TOKEN or the stoke login token.
- scripts/install-apt.sh: consumer-side one-time setup — adds the
registry key and apt source, then apt-get install stoke. Falls back to
a [trusted=yes] source when apt's sqv verifier rejects the forge's
registry signature (known upstream Forgejo signing bug; the script
prefers the signed source so setups heal once the forge is fixed).
- .forgejo/workflows/release.yml: on v* tags — test, build, publish to
the heavy-duty registry, attach the .deb to the release page. Needs a
runner and a RELEASE_TOKEN secret with org package write.
New command:
- stoke pr merge (-n, --method merge|rebase|rebase-merge|squash,
--title, --message, --delete-branch) — gap found while merging !2.
Docs and housekeeping:
- README: 'Install with apt' as the primary installation method with
manual setup and dpkg fallback, signature caveat, pr merge reference,
Packaging and releasing section with a release checklist.
- dist/ gitignored; version bumped to 1.2.0.
Verified end-to-end on this machine: built the deb (lintian-clean),
published it to the Forgejo Debian registry, installed it with
apt-get install stoke via install-apt.sh, and confirmed the installed
CLI works against the live forge. The test upload was removed from the
personal namespace afterwards; publishing under heavy-duty needs an
org-member token (401 reqPackageAccess with this restricted account).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 19:40:51 +00:00
2026-07-26 23:11:30 +00:00
## Quick start
Add apt distribution: deb packaging, registry publish, docs (#1)
Implements #1 — stoke installable with apt-get install stoke.
Packaging:
- scripts/build-deb.sh: builds dist/stoke_<version>_all.deb from a clean
staging copy (src + fresh npm ci --omit=dev), pure-JS Architecture: all,
Depends: nodejs (>= 22.12), /usr/lib/stoke payload with /usr/bin/stoke
symlink, copyright + changelog, normalized permissions. Lintian-clean.
- scripts/publish-deb.sh: uploads a .deb to the Forgejo Debian registry
(owner/distribution/component parameterized, defaults heavy-duty/
stable/main), authenticating with STOKE_TOKEN or the stoke login token.
- scripts/install-apt.sh: consumer-side one-time setup — adds the
registry key and apt source, then apt-get install stoke. Falls back to
a [trusted=yes] source when apt's sqv verifier rejects the forge's
registry signature (known upstream Forgejo signing bug; the script
prefers the signed source so setups heal once the forge is fixed).
- .forgejo/workflows/release.yml: on v* tags — test, build, publish to
the heavy-duty registry, attach the .deb to the release page. Needs a
runner and a RELEASE_TOKEN secret with org package write.
New command:
- stoke pr merge (-n, --method merge|rebase|rebase-merge|squash,
--title, --message, --delete-branch) — gap found while merging !2.
Docs and housekeeping:
- README: 'Install with apt' as the primary installation method with
manual setup and dpkg fallback, signature caveat, pr merge reference,
Packaging and releasing section with a release checklist.
- dist/ gitignored; version bumped to 1.2.0.
Verified end-to-end on this machine: built the deb (lintian-clean),
published it to the Forgejo Debian registry, installed it with
apt-get install stoke via install-apt.sh, and confirmed the installed
CLI works against the live forge. The test upload was removed from the
personal namespace afterwards; publishing under heavy-duty needs an
org-member token (401 reqPackageAccess with this restricted account).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 19:40:51 +00:00
2026-07-22 15:03:32 +00:00
```bash
2026-07-26 23:11:30 +00:00
stoke auth login # interactive; or use STOKE_USERNAME / STOKE_PASSWORD
stoke auth status
stoke issue list -o heavy-duty -r stoke
stoke pr review -o heavy-duty -r stoke -n 3 --event approve -b "LGTM"
2026-07-22 15:03:32 +00:00
```
2026-07-26 23:11:30 +00:00
Full options and examples for every command: ** [docs/COMMANDS.md ](docs/COMMANDS.md )**.
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
---
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
## What you can do
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
| Area | Commands |
| --- | --- |
| **Auth** | `login` , `logout` , `status` |
| **Repos** | `clone` , `create` , `list` , `import` , `import-batch` , `rename` , `transfer` |
| **Issues** | `list` , `create` , `show` , `comment` |
| **PRs** | `list` , `create` , `show` , `comment` , `review` , `merge` |
| **Releases** | `list` , `view` , `create` |
| **Labels** | `list` , `create` , `delete` , `add` , `remove` |
| **Branches** | `list` |
| **Collaborators** | `add` |
| **Orgs / teams** | `create` , `repos` , `avatar` , team list/create/members |
| **Users** | `list` , `show` |
| **Escape hatch** | `stoke api <endpoint>` — any Forgejo REST path with the stored token |
Read commands support ** `--json` ** for machine-readable API output (see [COMMANDS.md ](docs/COMMANDS.md )).
---
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
## Configuration
Audit: fix auth/config bugs, add issue/pr create, tests and docs
Fixes found during a full audit of the CLI:
- auth logout: remote token revocation always failed with 401 because
Forgejo only accepts Basic auth on the token endpoints. Logout now
asks for (or accepts) the account password, supports --password,
--password-file and --local-only, and clearly reports when the token
is left active.
- Silent password prompt actually echoed the password on a TTY:
overriding rl.write does not suppress readline echo. Switched to the
callback readline module and mute _writeToOutput instead (the
readline/promises interface does not honor that hook).
- Global --config flag was silently ignored: config paths were resolved
at require time, before the preAction hook set STOKE_CONFIG_FILE.
Paths are now resolved lazily on every access.
- XDG_CONFIG_HOME handling put the config in $XDG_CONFIG_HOME/.config/stoke;
per the XDG spec it now resolves to $XDG_CONFIG_HOME/stoke.
- repo create: --auto-init defaulted to true with no way to disable it;
added --no-auto-init.
- repo import/import-batch: a GitHub token was required even for
non-GitHub services (e.g. --service git), making those imports fail
without gh/GITHUB_TOKEN. Tokens are now only auto-resolved for the
github service; batch imports resolve per entry and memoize.
- Branding leftovers: 'Run: forgejo auth login' hint and
forgejo-cli/1.0.0 User-Agent now say stoke (UA tracks pkg.version).
- Added request timeouts (30s default, 10m for migrations).
- --limit and --team-id are validated as integers instead of silently
misbehaving on garbage (NaN made -l show all results).
New commands (per the repo's every-operation-becomes-a-command design):
- stoke issue create (title/body/body-file/assignees)
- stoke pr create (head/base/title/body/body-file)
Tests and metadata:
- New test suite on the built-in node:test runner (25 tests) covering
config resolution/persistence, the API client with a mocked fetch,
and end-to-end CLI behavior. npm test previously matched no files.
- package.json: engines >=22.12.0 (required by commander@15 — the
README claimed Node 18), repository, keywords, author; version 1.1.0.
- README: corrected Node requirement, documented repo rename (was
missing), issue create, pr create, logout options and revocation
caveat, --no-auto-init, XDG behavior, import token rules, testing.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 19:28:23 +00:00
2026-07-26 23:11:30 +00:00
| | |
| --- | --- |
| Default path | `~/.config/stoke/config.json` (or `$XDG_CONFIG_HOME/stoke/config.json` ) |
| Override | `--config <path>` (before the subcommand) or `STOKE_CONFIG_FILE` |
| Permissions | directory `0700` , file `0600` |
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
Stored fields: `url` , `login` , `username` , `email` , `token` , `tokenId` .
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
**Token scopes** — `auth login` mints a least-privilege token by default (`issue` R/W, `repository` R/W, `user` R, `organization` R). Use `--full-scopes` or `--scopes <csv>` for org admin / package publish. Details in [COMMANDS.md → Auth ](docs/COMMANDS.md#auth ).
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
### Environment
2026-07-22 15:03:32 +00:00
| Variable | Purpose |
| --- | --- |
2026-07-22 15:16:42 +00:00
| `STOKE_URL` | Default Forgejo base URL |
2026-07-26 23:11:30 +00:00
| `STOKE_USERNAME` / `STOKE_PASSWORD` | Defaults for `auth login` |
| `STOKE_CONFIG_FILE` / `STOKE_CONFIG_DIR` | Config location |
| `XDG_CONFIG_HOME` | Default config directory parent |
| `GITHUB_TOKEN` | Source token for `repo import` when `--github-token` is omitted |
2026-07-22 21:21:21 +00:00
2026-07-26 23:11:30 +00:00
`FORGEJO_*` names still work as fallbacks.
2026-07-22 21:21:21 +00:00
2026-07-26 23:11:30 +00:00
---
2026-07-22 17:47:48 +00:00
2026-07-26 23:11:30 +00:00
## Develop
2026-07-22 17:56:14 +00:00
```text
2026-07-26 23:11:30 +00:00
src/cli.js commands and I/O
src/api.js Forgejo client (Basic auth for tokens; token auth elsewhere)
src/config.js secure config paths and persistence
2026-07-22 17:56:14 +00:00
```
Add apt distribution: deb packaging, registry publish, docs (#1)
Implements #1 — stoke installable with apt-get install stoke.
Packaging:
- scripts/build-deb.sh: builds dist/stoke_<version>_all.deb from a clean
staging copy (src + fresh npm ci --omit=dev), pure-JS Architecture: all,
Depends: nodejs (>= 22.12), /usr/lib/stoke payload with /usr/bin/stoke
symlink, copyright + changelog, normalized permissions. Lintian-clean.
- scripts/publish-deb.sh: uploads a .deb to the Forgejo Debian registry
(owner/distribution/component parameterized, defaults heavy-duty/
stable/main), authenticating with STOKE_TOKEN or the stoke login token.
- scripts/install-apt.sh: consumer-side one-time setup — adds the
registry key and apt source, then apt-get install stoke. Falls back to
a [trusted=yes] source when apt's sqv verifier rejects the forge's
registry signature (known upstream Forgejo signing bug; the script
prefers the signed source so setups heal once the forge is fixed).
- .forgejo/workflows/release.yml: on v* tags — test, build, publish to
the heavy-duty registry, attach the .deb to the release page. Needs a
runner and a RELEASE_TOKEN secret with org package write.
New command:
- stoke pr merge (-n, --method merge|rebase|rebase-merge|squash,
--title, --message, --delete-branch) — gap found while merging !2.
Docs and housekeeping:
- README: 'Install with apt' as the primary installation method with
manual setup and dpkg fallback, signature caveat, pr merge reference,
Packaging and releasing section with a release checklist.
- dist/ gitignored; version bumped to 1.2.0.
Verified end-to-end on this machine: built the deb (lintian-clean),
published it to the Forgejo Debian registry, installed it with
apt-get install stoke via install-apt.sh, and confirmed the installed
CLI works against the live forge. The test upload was removed from the
personal namespace afterwards; publishing under heavy-duty needs an
org-member token (401 reqPackageAccess with this restricted account).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 19:40:51 +00:00
```bash
2026-07-26 23:11:30 +00:00
npm test # Node built-in test runner
scripts/build-deb.sh # -> dist/stoke_< version > _all.deb
Add apt distribution: deb packaging, registry publish, docs (#1)
Implements #1 — stoke installable with apt-get install stoke.
Packaging:
- scripts/build-deb.sh: builds dist/stoke_<version>_all.deb from a clean
staging copy (src + fresh npm ci --omit=dev), pure-JS Architecture: all,
Depends: nodejs (>= 22.12), /usr/lib/stoke payload with /usr/bin/stoke
symlink, copyright + changelog, normalized permissions. Lintian-clean.
- scripts/publish-deb.sh: uploads a .deb to the Forgejo Debian registry
(owner/distribution/component parameterized, defaults heavy-duty/
stable/main), authenticating with STOKE_TOKEN or the stoke login token.
- scripts/install-apt.sh: consumer-side one-time setup — adds the
registry key and apt source, then apt-get install stoke. Falls back to
a [trusted=yes] source when apt's sqv verifier rejects the forge's
registry signature (known upstream Forgejo signing bug; the script
prefers the signed source so setups heal once the forge is fixed).
- .forgejo/workflows/release.yml: on v* tags — test, build, publish to
the heavy-duty registry, attach the .deb to the release page. Needs a
runner and a RELEASE_TOKEN secret with org package write.
New command:
- stoke pr merge (-n, --method merge|rebase|rebase-merge|squash,
--title, --message, --delete-branch) — gap found while merging !2.
Docs and housekeeping:
- README: 'Install with apt' as the primary installation method with
manual setup and dpkg fallback, signature caveat, pr merge reference,
Packaging and releasing section with a release checklist.
- dist/ gitignored; version bumped to 1.2.0.
Verified end-to-end on this machine: built the deb (lintian-clean),
published it to the Forgejo Debian registry, installed it with
apt-get install stoke via install-apt.sh, and confirmed the installed
CLI works against the live forge. The test upload was removed from the
personal namespace afterwards; publishing under heavy-duty needs an
org-member token (401 reqPackageAccess with this restricted account).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 19:40:51 +00:00
scripts/publish-deb.sh dist/stoke_< version > _all.deb heavy-duty stable main
```
2026-07-26 23:11:30 +00:00
Tag `v*` to release: CI runs tests, builds the `.deb` , publishes to the `heavy-duty` Debian registry, and attaches the package to the release (needs a runner + `RELEASE_TOKEN` with package/repo write).
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
1. Bump `version` in `package.json` / lockfile
2. Commit, tag `v<version>` , push the tag
3. Consumers: `apt-get update && apt-get upgrade`
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
---
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
## Security
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
- Tokens on disk: mode `0600` . Passwords are never stored.
- Prefer `--password-file` or `STOKE_PASSWORD` over `-p` (shell history / `!` expansion).
- Interactive password prompts do not echo.
- `stoke api` is a full authenticated passthrough — never feed it untrusted strings in the path or body.
- `stoke repo clone` never writes the token into the remote URL or `.git/config` .
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
---
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
## Docs
2026-07-22 15:03:32 +00:00
2026-07-26 23:11:30 +00:00
| Doc | Contents |
| --- | --- |
| [docs/COMMANDS.md ](docs/COMMANDS.md ) | Full command reference |
| [docs/DESIGN.md ](docs/DESIGN.md ) | Brand system and landing design |
2026-07-22 16:38:14 +00:00
2026-07-26 23:11:30 +00:00
---
2026-07-22 16:38:14 +00:00
2026-07-26 23:11:30 +00:00
## Why “stoke”?
2026-07-22 16:38:14 +00:00
2026-07-26 23:11:30 +00:00
Heavy-duty tools are **one syllable** , plain English, industrial, and often a verb⇄noun: `cast` , `rig` , `jig` , `boss` , `hand` . The Forgejo instance is **the forge** . *To stoke* a fire is to tend it and keep it burning — this CLI does that for issues, PRs, imports, and org setup.
2026-07-22 16:38:14 +00:00
2026-07-26 23:11:30 +00:00
Rejected names included `forge` (the platform, not the tool), `weld` / `quench` (wrong metaphor), and `flux` (reads as chemistry, not the shop floor).