Public Source Publisher ba9167ccd7
ForgeFlow signed release / release (push) Successful in 29s
ForgeFlow quality gate / secret-scan (push) Successful in 4s
ForgeFlow quality gate / quality (push) Successful in 18m22s
Publish curated ForgeFlow source from 972d562f8c7e4b9bba896477879a598fffcf6cb3
2026-09-30 22:13:34 +00:00

ForgeFlow

From a local change to a verified server revision.

Product tour · Features · Get started · Deployment model

ForgeFlow is a Windows desktop application for teams that use Git, Gitea and self-hosted Docker or Unraid servers. It brings local changes, remote commits and the exact revision running on a server into one workspace, then guides review, commit, push, deployment and verification.

Public-source edition: This repository contains reviewed source files from a private canonical repository. Stable Windows releases are built from this curated source and carry an Ed25519-signed publisher manifest. PUBLIC_SOURCE_MANIFEST.json identifies the exact source revision and file hashes; private Git history is not included.

Downloads: Get current Windows releases from ForgeFlow-Public. The legacy release page stays available while older installations move to the new update endpoint.

See the workflow

ForgeFlow release overview using demo repositories

Review local work Reconcile deployments
Repository workspace and selective staging Server inventory and deployment links

The captures use example repositories and demo state; they are not a live infrastructure dashboard.

Key capabilities

Area What ForgeFlow helps you do
Action queue See which repositories need review, a push, deployment or health attention.
Git review Inspect diffs, stage files or hunks, commit, push and recover from common sync problems.
Gitea awareness Compare local and remote revisions, review branch protection and open a pull request.
Server inventory Discover Docker, Compose and DockerMan workloads and link them only when repository evidence matches.
Exact-commit deployment Dispatch a reviewed revision and compare the full local, Gitea and live commit SHAs.
Git Validator Inspect repository identity, protection, documentation, secret hygiene and oversized files.
Diagnostics Keep configuration local and redact sensitive values in support exports.

ForgeFlow distinguishes a matching commit from a healthy deployment. It keeps incomplete evidence visible instead of claiming that a server is current when its live SHA is unknown.

Get started

Install the Windows app

  1. Download an installer or portable executable from the published release page.
  2. Launch ForgeFlow and complete the setup wizard.
  3. Add your Gitea URL, a token with the required repository permissions, and the local folders to scan.
  4. Optionally add a Docker or Unraid host, then use Scan servers to review detected workloads.

The packaged updater checks a release against the exact published release commit, its SHA-256 checksum and the embedded Ed25519 publisher key. Existing installations receive the 0.10.16 bridge release from the legacy endpoint; after installation, the default update endpoint changes to ForgeFlow-Public.

Explore with example data

Requirements: Node.js 22, npm and Git.

npm ci
npm run demo

Open http://127.0.0.1:41737. The browser demo uses example repositories and server state; it does not mutate your Git checkouts or deploy a workload. To run the full desktop application from source, use npm start after npm ci.

Deployment model

flowchart LR
    Desktop[ForgeFlow desktop] --> Git[Local Git worktree]
    Desktop --> Gitea[Gitea repository and Actions]
    Gitea --> Runner[Approved deployment workflow]
    Runner --> Server[Docker or Unraid host]
    Server --> Evidence[Live revision and health evidence]
    Evidence --> Desktop

For server-pull deployments, the host fetches the exact approved commit with a repository-scoped read-only deploy key and a pinned SSH host key. ForgeFlow validates Compose configuration and checks post-deployment health. A direct copy remains an explicit fallback, never an implicit replacement for the verified pull path.

Start with the setup guide, deployment setup, SSH and Unraid deployment, and migration example. Keep runtime data and credentials outside Git. The diagnostics guide explains safe support bundles.

Develop and verify

npm ci
npm run check
npm run acceptance

npm run check performs source verification, linting and tests. Browser acceptance and Windows packaging are separate release gates. src/main/ contains desktop services and IPC, src/renderer/ contains the UI, src/shared/ holds shared policies, scripts/ contains validation and release tooling, and tests/ covers core behavior.

The private canonical repository publishes a reviewed, content-only snapshot to ForgeFlow-Public. Its manifest records the source revision; private Git history and operational evidence are excluded. A version change in the curated public repository starts the Windows quality, build, signing and release workflow. Source-only changes do not publish a new binary version.

ForgeFlow is available under the MIT License. Report security issues through SECURITY.md.

S
Description
Curated public source export of ForgeFlow; signed releases remain temporarily on Jens/ForgeFlow
Readme MIT
1.8 MiB
0 Stars 1 Watchers 0 Forks
2026-09-30 22:33:25 +00:00
Languages
JavaScript 91.3%
CSS 5.7%
PowerShell 2.9%