Releases: cli/cli
Release list
GitHub CLI 2.100.0
Experimental: Route GitHub API traffic through a custom host
Organizations can now route a GitHub host's API traffic through a gateway using the new per-host api_host configuration:
# Route API traffic for github.com through a gateway
gh config set api_host gh-gateway.example.com --host github.com
# Read the configured API host
gh config get api_host --host github.comThe original host remains in use for authentication, Git remotes, and browser URLs.
Note
api_host is experimental and is not a security boundary. Requests may still reach the original host.
What's Changed
✨ Features
- Honor per-host
api_hostrouting across GitHub API requests by @williammartin in #14104 - Expose
api_hostthroughgh config getandgh config setby @williammartin in #14332 - Add
webhookas an official extension by @williammartin in #14326 - Print full command help after command misuse when
ghis invoked by a coding agent by @niik in #14198
🐛 Fixes
- fix(api): disable telemetry for unauthenticated GHES requests using absolute hostnames by @williammartin in #14337
📚 Docs & Chores
- Fix discussion acceptance test flags by @williammartin in #14321
- Clarify supported GHES versions by @williammartin in #14324
- Improve automated issue triage analysis by @sergiou87 in #14318
- Record attachment counts in telemetry by @BagToad in #14327
Dependencies
- chore(deps): bump
golang.org/x/cryptofrom 0.55.0 to 0.56.0 by @babakks in #14331 - chore(deps): bump Go toolchain from 1.26.7 to 1.26.8 by @babakks in #14330
- chore(deps): bump
github.com/cli/go-gh/v2from 2.15.0 to 2.16.0 by @williammartin in #14338
Full Changelog: v2.99.0...v2.100.0
GitHub CLI 2.99.0
Attach images and videos to issues and pull requests
The repeatable --attach flag uploads local images and videos and adds them to issue, pull request, or comment bodies. If a body already references the local path, gh replaces it with the uploaded URL; otherwise it appends the attachment:
# Attach files when creating or editing an issue
gh issue create --attach './repro.png#The error state'
gh issue edit 123 --attach ./walkthrough.mp4
# Attach files when creating or editing a pull request
gh pr create --attach ./before.png
gh pr edit 456 --attach ./after.png
# Attach files to comments
gh issue comment 123 --attach ./repro.png
gh pr comment 456 --attach ./result.mp4Repeat the flag to attach multiple files in a single invocation. Attachments are available on GitHub.com and GitHub Enterprise Cloud.
For more information see https://gh.io/gh-attach and https://github.blog/changelog/2026-09-01-github-cli-media-in-issues-pull-requests-and-comments/
Worktree support extended to gh issue develop
gh issue develop can now create a linked branch and check it out in a new Git worktree, leaving your current working copy unchanged:
# Create a linked branch for an issue and check it out in a worktree
gh issue develop 123 --checkout --worktree /path/to/wt-featureWhat's Changed
✨ Features
- Add token and repository metadata required for attachment uploads by @BagToad in #14177
- Add validation for attachable image and video files by @BagToad in #14178
- Rewrite local Markdown references to uploaded attachment URLs by @BagToad in #14179
- Add attachment uploads to GitHub by @BagToad in #14180
- Add repeatable
--attachflag parsing and upload orchestration by @BagToad in #14181 - Add
--attachtogh pr commentandgh issue commentby @BagToad in #14182 - Add
--attachtogh pr createandgh pr editby @BagToad in #14183 - Add
--attachtogh issue createandgh issue editby @BagToad in #14184 - Add worktree checkout to
gh issue developby @sergiou87 in #14136 - Use text-only spinner output when
ghis invoked by a coding agent by @niik in #14191 - Honor
PI_CODING_AGENT_DIRfor Pi user skills by @tommaso-moro in #14260
🐛 Fixes
- fix(repo sync): explain when the target branch is checked out in another worktree by @williammartin in #14076
- fix(pr merge): safely handle
--delete-branchwith linked worktrees by @tidy-dev in #14007 - fix(copilot): end the declined-install warning with a newline by @BagToad in #14222
- fix(attach): clarify retry windows and attachment path resolution by @BagToad in #14262
- fix(issue develop): reject non-empty worktree targets before creating a branch by @tidy-dev in #14244
- fix(repo sync): prevent linked-worktree corruption by @sergiou87 in #14060
- fix(view): reject
--commentswith--jsonby @BagToad in #14215 - fix(attach): limit batches to 50 files by @BagToad in #14289
- fix(skills): install Codex user skills to
~/.agents/skillsby @scarletkc in #14154
📚 Docs & Chores
- Address review feedback across the
--attachstack by @BagToad in #14200 - Refactor commands to own attachment flag policy by @BagToad in #14255
- Document attachment support in the
ghskill by @BagToad in #14261 - Document
gh issue develop --checkout --worktreein theghskill by @babakks in #14265 - Clarify pull request testing guidance by @williammartin in #14272
- Fix issue triage to apply suspected-spam labels directly by @williammartin in #14271
- Prevent Dependabot from updating agentic-workflow dependencies by @williammartin in #14274
- Modernize Go code with
go fixby @BagToad in #14278
Dependencies
- chore(deps): bump google.golang.org/grpc from 1.83.0 to 1.83.1 by @dependabot in #14247
- chore(deps): bump charm.land/bubbletea/v2 from 2.0.8 to 2.0.9 by @dependabot in #14248
- chore(deps): bump the codeql-actions group across 1 directory with 3 updates by @dependabot in #14250
- chore(deps): bump charm.land/bubbles/v2 from 2.1.1 to 2.2.0 by @dependabot in #14249
- chore(deps): bump agentic-workflows to 0.87.5 by @williammartin in #14273
- chore(deps): bump charm.land/bubbles/v2 from 2.2.0 to 2.2.1 by @dependabot in #14275
- chore(deps): bump https://github.com/sigstore/protobuf-specs from 0.5.1 to 0.5.2 by @dependabot in #14258
- chore(deps): bump https://github.com/google/go-containerregistry from 0.21.9 to 0.22.0 by @dependabot in #14267
- chore(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 by @dependabot in #14299
- chore(deps): bump azure/login from 3.0.1 to 3.0.2 by @dependabot in #14301
- chore(deps): bump the codeql-actions group with 3 updates by @dependabot in #14300
New Contributors
- @scarletkc made their first contribution in #14154
Full Changelog: v2.98.0...v2.99.0
GitHub CLI 2.98.0
Security
A security vulnerability has been identified, and fixed, that binds the local forwarded port to all available network interfaces by default.
Users of gh codespace ports forward are advised to update gh to version v2.98.0 as soon as possible.
For more information see: GHSA-vfhh-p7hm-pxfh
Support worktrees in pr checkout
Users can now checkout a pull request into a git worktree by using the new --worktree PATH flag in gh pr checkout:
gh pr checkout 12 --worktree ../wt-featureAdd semantic search to search issues
The gh search issues command now supports semantic search for issues. Users can select the search type by passing the --search-type flag:
gh search issues --search-type semantic ...
gh search issues --search-type hybrid ...For more information about semantic search see: "Improved Search for github issues is now generally available".
What's Changed
✨ Features
- Add --worktree flag to gh pr checkout by @tidy-dev in #13946
- Set GH_EXTENSION=1 when gh invokes an extension by @williammartin in #14072
- Add --search-type flag for semantic and hybrid issue search by @michaeljacholke in #14006
🐛 Fixes
- Fix
RESTWithNexterror type, repairinggh statusand attestation retries by @williammartin in #13988 - Trim spaces when parsing X-Oauth-Scopes in
gh release createby @williammartin in #14065 - Fix project item-add output for non-TTY by @zwick in #14056
📚 Docs & Chores
- Slim down dependabot triage comments by @williammartin in #14019
- Require explicit PR review ownership by @williammartin in #14028
- Collapse spam triage into the agentic issue-triage workflow by @williammartin in #14027
- Run Dependabot triage every hour by @sergiou87 in #14030
- Route deploy key requests through api.Client by @williammartin in #13989
- Route ssh key requests through api.Client by @williammartin in #13994
- Route gpg key requests through api.Client by @williammartin in #13997
- Route autolink requests through api.Client by @williammartin in #14013
- Route extension requests through api.Client by @williammartin in #14059
- Route release creation through api.Client by @williammartin in #14062
- Tell agents to use the PR template in AGENTS.md by @williammartin in #14074
- Make Dependabot triage cheaper and more decisive by @williammartin in #14079
- Route release deletions through api.Client by @williammartin in #14077
- Give Dependabot triage a real reachability check by @williammartin in #14087
- Restore automatic spam issue closure by @williammartin in #14088
- Add a scheduled tech debt burndown skill by @williammartin in #14095
- Use reflect.Pointer instead of deprecated reflect.Ptr by @williammartin in #14098
- Clarify what belongs in the PR template's testing section by @williammartin in #14103
- Rename cli-code-reviewer skill to code-review by @BagToad in #14116
- Add aw-actions group to dependabot configuration by @babakks in #14123
- Isolate tests from local machine's auth and git configuration by @BagToad in #14128
- Don't ask for feature detection cleanup comments when not needed by @babakks in #14139
- Accept pre-release tags in deployment validation by @BagToad in #14193
- ci: add temporary step to verify Linux repo signing keys by @babakks in #14202
- Revert "ci: add temporary step to verify Linux repo signing keys" by @babakks in #14203
- Fix issue triage action compatibility [skip changelog] by @tidy-dev in #14207
Dependencies
- chore(deps): bump github.com/sigstore/sigstore-go from 1.2.2 to 1.3.0 by @dependabot[bot] in #14047
- chore(deps): bump the codeql-actions group across 1 directory with 3 updates by @dependabot[bot] in #14049
- chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.0 by @dependabot[bot] in #14048
- chore(deps): bump github.com/google/go-containerregistry from 0.21.7 to 0.21.8 by @dependabot[bot] in #14066
- chore(deps): bump actions/attest from 4.2.1 to 4.2.2 by @dependabot[bot] in #14100
- chore(deps): bump azure/login from 3.0.0 to 3.0.1 by @dependabot[bot] in #14101
- chore(deps): bump the codeql-actions group across 1 directory with 3 updates by @dependabot[bot] in #14091
- chore(deps): bump github/gh-aw-actions/setup-cli from 0.83.4 to 0.85.4 by @dependabot[bot] in #14068
- chore(deps): bump github.com/google/go-containerregistry from 0.21.8 to 0.21.9 by @dependabot[bot] in #14119
- chore(deps): bump github.com/klauspost/compress from 1.19.1 to 1.19.2 by @dependabot[bot] in #14120
- chore(deps): bump the aw-actions group with 2 updates by @dependabot[bot] in #14147
- chore: sign APT repository with both keys by @babakks in #13271
- chore(deps): bump github.com/yuin/goldmark from 1.8.4 to 1.8.5 by @dependabot[bot] in #14029
- chore(deps): bump actions/attest from 4.2.0 to 4.2.1 by @dependabot[bot] in #14050
- Bump golangci-lint in CI to v2.12.2 by @williammartin in #14102
- chore(deps): bump the aw-actions group with 2 updates by @dependabot[bot] in #14124
- chore(deps): bump google.golang.org/protobuf from 1.36.11 to 1.36.12 by @dependabot[bot] in #14140
- Upgrade gh-aw workflows to v0.85.4 by @tidy-dev in #14141
- Bump Go to 1.26.6 by @github-actions[bot] in #14143
- chore: bump go to 1.26.7 by @babakks in #14205
- chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.1 by @dependabot[bot] in #14204
- chore(deps): bump the codeql-actions group across 1 directory with 3 updates by @dependabot[bot] in #14169
- chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 by @dependabot[bot] in #14164
- chore(deps): bump charm.land/lipgloss/v2 from 2.0.5 to 2.0.6 by @dependabot[bot] in #14166
- Bump gh-aw-actions to v0.87.1 and recompile agentic workflows by @BagToad in #14210
New Contributors
- @sergiou87 made their first contribution in #14030
- @michaeljacholke made their first contribution in #14006
Full Changelog: v2.97.0...v2.98.0
GitHub CLI 2.97.0
Security
Four security vulnerabilities have been identified, and fixed, in this release. Users are advised to update gh to version v2.97.0 as soon as possible.
Several commands (including gh gist view, gh api, gh pr diff, gh release download --output -, gh codespace logs, gh skills preview, and gh agent-task view/create) printed externally controlled content without neutralizing terminal escape sequences, allowing escape sequence injection into a user's terminal.
See GHSA-3m3g-3wcr-px46 for more information.
Some request URLs were built without escaping their variable path components, so a value containing URL path metacharacters could alter the request path and cause gh to address a different resource than intended.
See GHSA-4fjg-2h4q-fwg3 for more information.
gh auth status (without --show-token) could print a portion of the authentication token in plaintext for token types whose format contains an underscore after the prefix, such as github_pat_*, ghs_*, and ghu_*.
See GHSA-cg6r-mpgc-h9mm for more information.
gh attestation verify built the certificate matcher from --signer-repo and --signer-workflow without escaping regex metacharacters, so a lookalike repository or workflow name could satisfy a matcher intended for a trusted signer and bypass attestation verification.
See GHSA-mm27-mwq9-fr5g for more information.
Address project fields and items by name in gh project
gh project item-edit and gh project item-list can now reference project fields and single-select options by name:
# Set an item's field by name
gh project item-edit 1 --owner monalisa --url <url> --field "Status" --value "In Progress"
# Show named fields as extra columns
gh project item-list 1 --owner "@me" --field "Status" --field "Priority"What's Changed
✨ Features
- Add name-based resolution to
gh project item-editby @zwick in #13807 - Add named field columns to
gh project item-listby @zwick in #13823 - Add Grok skill host support by @tommaso-moro in #13864
- Replace Windsurf with Devin in
gh skillagents by @tommaso-moro in #13987
🐛 Fixes
- Gracefully handle failed GitHub verifier initialization caused by a missing trusted root by @malancas in #13624
- Bump keyring operation timeout from 3s to 60s so interactive unlock prompts have time to complete by @kofuk in #13787
- Fix skill picker label wrapping by @tommaso-moro in #13967
📚 Docs & Chores
- Bump Go to 1.26.5 by @github-actions[bot] in #13817
- Add
OWNER/REPOformat hint to thegh search --repoflag by @BagToad in #13922 - Present by-name
item-editas the first-class project flow in docs by @Solaris-star in #13927 - Add a macOS keyring security doc by @williammartin in #13960
- Add a code review agent skill by @BagToad in #14003
- Establish a pull request template for scale by @BagToad in #14004
- Add an agentic issue-triage workflow by @lukewar in #13777
- Use the Actions token for Copilot inference in the issue-triage workflow by @tidy-dev in #13830
- Refresh the issue-triage agentic workflow to gh-aw v0.83.1 by @alondahari in #13949
- Add a dependabot-triage agentic workflow by @williammartin in #13985
- Harden the deployment workflow by @niik in #13780
- Replace
SITE_DEPLOY_PATwith the gh-cli-site-deployer App by @williammartin in #13492 - Group CodeQL Dependabot updates by @williammartin in #13943
- Remove a dead CODEOWNERS rule for the non-existent
pkg/cmd/release/attestation/by @kobihikri in #13886 - Fix typos in code and documentation by @pstoeckle in #13940
- Fix duplicated-word typos in comments by @SORBELLOSTEFANIE in #13900
Dependencies
- chore(deps): bump charm.land/lipgloss/v2 from 2.0.4 to 2.0.5 by @dependabot in #13790
- chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.0 by @dependabot in #13789
- chore(deps): bump https://github.com/klauspost/compress from 1.18.6 to 1.19.0 by @dependabot in #13791
- chore(deps): bump charm.land/bubbletea/v2 from 2.0.7 to 2.0.8 by @dependabot in #13800
- chore(deps): bump golang.org/x/text from 0.38.0 to 0.39.0 by @dependabot in #13812
- chore(deps): bump golang.org/x/sys from 0.46.0 to 0.47.0 by @dependabot in #13821
- chore(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3 by @dependabot in #13801
- chore(deps): bump github/gh-aw-actions/setup from 0.81.6 to 0.82.2 by @dependabot in #13832
- chore(deps): bump charm.land/bubbles/v2 from 2.1.0 to 2.1.1 by @dependabot in #13813
- chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 by @dependabot in #13822
- chore(deps): bump github/gh-aw-actions/setup from 0.82.2 to 0.82.3 by @dependabot in #13843
- chore(deps): bump actions/cache/restore from 5.0.5 to 6.1.0 by @dependabot in #13841
- chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 by @dependabot in #13867
- chore(deps): bump github/codeql-action/analyze from 4.36.3 to 4.37.0 by @dependabot in #13869
- chore(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.0 by @dependabot in #13868
- chore(deps): bump github/codeql-action/init from 4.36.3 to 4.37.1 by @dependabot in #13870
- chore(deps): bump https://github.com/yuin/goldmark from 1.8.2 to 1.8.4 by @dependabot in #13888
- chore(deps): bump https://github.com/sigstore/sigstore-go from 1.2.1 to 1.2.2 by @dependabot in #13842
- chore(deps): bump github/gh-aw-actions/setup from 0.82.3 to 0.82.8 by @dependabot in #13877
- chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0 by @dependabot in #13933
- chore(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1 by @dependabot in #13934
- chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 by @dependabot in #13936
- chore(deps): bump actions/attest from 4.1.1 to 4.2.0 by @dependabot in #13935
- chore(deps): bump https://github.com/mattn/go-isatty from 0.0.22 to 0.0.23 by @dependabot in #13937
- chore(deps): bump github/gh-aw-actions/setup from 0.82.8 to 0.82.13 by @dependabot in #13938
- chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 by @dependabot in #13941
- chore(deps): bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.1 by @dependabot in #13942
- chore(deps): bump https://github.com/gabriel-vasile/mimetype from 1.4.13 to 1.4.14 by @dependabot in #13944
- chore(deps): bump nodeselector/setup-apple-codesign from ab275d0 to 309922b by @dependabot in #13878
- chore(deps): bump https://github.com/klauspost/compress from 1.19.0 to 1.19.1 by @dependabot in #13950
- chore(deps): bump github/gh-aw-actions/setup from 0.82.13 to 0.82.14 by @dependabot in #13951
- chore(deps): bump the codeql-actions group with 3 updates by @dependabot in #13965
- chore(deps): bump https://github.com/mattn/go-isatty from 0.0.23 to 0.0.24 by @dependabot in #13977
- chore(deps): bump the codeql-actions group with 3 updates by @dependabot in #13978
- chore(deps): bump https://github.com/gabriel-vasile/mimetype from 1.4.14 to 1.4.15 by @dependabot in #13976
- chore(deps): bump github/gh-aw-actions/setup from 0.83.1 to 0.83.2 by @dependabot in #13979
- chore(deps): bump github/gh-aw-actions/setup-cli from 0.83.1 to 0.83.2 by @dependabot in #13980
- chore(deps): bump actions/checkout from 6 to 7 by @dependabot in [#13981](https://github.com/cli/cli...
GitHub CLI 2.96.0
Security
A security vulnerability has been identified, and fixed, that could allow command execution on a user's computer when connecting to a malicious Codespace via gh codespace jupyter.
Users of gh codespace jupyter are advised to update gh to version v2.96.0 as soon as possible.
For more information see: GHSA-8cg3-r6g9-fpg2
Download release assets without authentication
gh release download now works against public repositories without authentication, matching gh extension install. A token is still used when one is present:
# Download assets from a public repository, no login required
gh release download v2.96.0 --repo cli/cliWhat's Changed
✨ Features
- Allow
gh release downloadwithout authentication on public repositories by @BagToad in #13723 - Detect additional third-party coding agents by @BagToad in #13722
- Support
antigravity-cliandantigravity2.0ingh skillby @BagToad in #13784
🐛 Fixes
- fix: show checks summary when all checks were cancelled by @s3onghyun in #13679
- fix(skills): install universal agent to
~/.agents/skillsby @toller892 in #13681 - fix(skills): honor
--dirwithout agent prompt by @happysnaker in #13766 - Fix concurrent map writes in codespace port forwarding by @williammartin in #13313
- Use
int64for GitHub database IDs by @williammartin in #13403
📚 Docs & Chores
- Pin reusable triage workflows to a commit SHA by @BagToad in #13705
- Add security disclosure guidance to
AGENTS.mdby @BagToad in #13720 - Clarify
--cloneboolean flag behaviour ingh repo forkhelp by @BagToad in #13786 - Fix flaky
TestHuhPrompterMultiSelectWithSearchPersistenceon slow architectures by @pdostal in #13675 - docs(search): add examples for multiple qualifiers by @happysnaker in #13756
- docs: fix broken anchor link in release-process-deep-dive by @patrickwehbe in #13688
- docs: fix broken install command and link/grammar errors by @patrickwehbe in #13690
- docs: fix duplicated word in primer README by @s3onghyun in #13677
Dependencies
- chore(deps): bump github.com/microsoft/dev-tunnels from 0.1.19 to 0.1.27 by @dependabot in #13708
- chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot in #13703
- chore(deps): bump github.com/google/go-containerregistry from 0.21.6 to 0.21.7 by @dependabot in #13702
- chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0 by @dependabot in #13740
- chore(deps): bump actions/attest from 4.1.0 to 4.1.1 by @dependabot in #13754
- chore(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 by @dependabot in #13759
- chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 by @dependabot in #13779
New Contributors
- @patrickwehbe made their first contribution in #13688
- @s3onghyun made their first contribution in #13679
- @toller892 made their first contribution in #13681
- @happysnaker made their first contribution in #13756
Full Changelog: v2.95.0...v2.96.0
GitHub CLI 2.95.0
Read repository files and directories with gh repo read-file and gh repo read-dir
Two new preview commands read repository contents without cloning:
# Read a single file to stdout
gh repo read-file README.md --repo cli/cli
# Read from a specific branch, tag, or commit
gh repo read-file go.mod --ref v2.94.0 --repo cli/cli
# Write a file to disk (use --clobber to overwrite)
gh repo read-file README.md --output ./README.md --repo cli/cli
# List the entries in a directory
gh repo read-dir script --repo cli/cliBoth commands default to the repository's default branch, accept --ref to target any branch, tag, or commit, and support --json, --jq, and --template for scripting. This makes it easy for agents and automation to inspect a repo without a full checkout.
Note
gh repo read-file and gh repo read-dir are in preview and subject to change without notice.
What's Changed
✨ Features
- feat: add
repo read-fileandrepo read-dirby @babakks in #13580 - feat(skills): list available skills when install runs non-interactively by @SamMorrowDrums in #13548
- Support custom CLAUDE_CONFIG_DIR in install by @tommaso-moro in #13523
🐛 Fixes
- fix(skills): stage updates in a temp dir and swap in-place by @SamMorrowDrums in #13449
📚 Docs & Chores
- Make filtering by bot authors more discoverable by @BagToad in #13642
- docs(discussion): polish help docs by @babakks in #13632
- Bump Go in devcontainer by @spenserblack in #13674
Dependencies
- chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 by @dependabot[bot] in #13640
- chore(deps): bump charm.land/lipgloss/v2 from 2.0.3 to 2.0.4 by @dependabot[bot] in #13663
- chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 by @dependabot[bot] in #13661
- chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2 by @dependabot[bot] in #13619
- chore(deps): bump github.com/sigstore/sigstore-go from 1.1.4 to 1.2.1 by @dependabot[bot] in #13662
- chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 by @dependabot[bot] in #13641
Full Changelog: v2.94.0...v2.95.0
GitHub CLI 2.94.0
Issue types, sub-issues, and relationships in gh issue
This release brings GitHub's advanced issue features to gh issue create, edit, view, and list. You can set and view an issue's type, organize work with sub-issues, and track blocked-by and blocking relationships without leaving the command line:
# Set an issue's type
gh issue create --type Bug
gh issue edit 123 --type Bug
# Organize work with sub-issues
gh issue create --parent 100
gh issue edit 100 --add-sub-issue 123
# Track blocked-by and blocking relationships
gh issue create --blocked-by 200
gh issue edit 123 --add-blocking 300Issue types and sub-issues are available on GitHub.com and GHES 3.17+; relationships require GHES 3.19+.
Manage discussions with gh discussion
This release introduces the discussion command set for working with GitHub Discussions in gh:
# List discussions
gh discussion list
# View a discussion, its comments, or replies to a comment
gh discussion view 123 --comments
# Create a discussion
gh discussion create
# Edit a discussion
gh discussion edit 123
# Comment on a discussion
gh discussion comment 123
# Reply to a comment using its URL
gh discussion comment <url>Run gh discussion --help for more information.
Note
The discussion command set is in preview and is subject to change without notice.
Equip your agents with new gh features
Teach your agents how to leverage new GitHub CLI features on release day by installing the gh skill:
# Install
gh skill install cli/cli gh --scope user
# Or update
gh skill update ghWhat's Changed
✨ Features
- Add
gh discussioncommand set (list,view,create,edit) as a preview by @babakks and @maxbeizer in #13541 - Add
gh discussion commentto comment on and reply to discussions by @babakks in #13620 - Add Issues 2.0 support: issue types, sub-issues, and relationships by @BagToad in #13057
- Add
gh skill listto inventory installed agent skills by @tommaso-moro in #13418 - Add
--allflag togh skill installto install every skill in a repository by @tommaso-moro in #13471 - Skip skills without metadata when running
gh skill update --allby @tommaso-moro in #13469 - Alias
gh extension uninstalltogh extension removeby @BagToad in #13599 - Auto-install official extensions in CI by @BagToad in #13581
🐛 Fixes
- fix(skill): support skill discovery in nested directories by @tommaso-moro in #13459
📚 Docs & Chores
- Bump Go to 1.26.4 by @github-actions[bot] in #13578
- Clean up deferred issue update helper by @BagToad in #13584
- Add terminal-mockup canvas extension for marketing screenshots by @BagToad in #13612
- Add
gh discussionand Issues 2.0 reference to theghskill, plus a README note by @BagToad in #13631
Dependencies
- chore(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 by @dependabot in #13521
- chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.9 to 2.13.10 by @dependabot in #13520
- chore(deps): bump github.com/mattn/go-colorable from 0.1.14 to 0.1.15 by @dependabot in #13572
- chore(deps): bump charm.land/bubbletea/v2 from 2.0.6 to 2.0.7 by @dependabot in #13595
- chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1 by @dependabot in #13596
- chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 by @dependabot in #13597
Full Changelog: v2.93.0...v2.94.0
GitHub CLI 2.93.0
Security
A security vulnerability has been identified, and fixed, that would incorrectly include authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands.
Users are advised to update gh to version v2.93.0 as soon as possible.
For more information see: GHSA-8xvp-7hj6-mcj9
Support agents in gh secret command set
The gh secret command set can now set agent secrets. For more information, see "Configuring secrets and variables for Copilot cloud agent".
What's Changed
✨ Features
🐛 Fixes
- fix(pr): remove numberFieldOnly optimization that skips API validation by @williammartin in #13327
- Print
gh auth refreshfor 401 returns by @333fred in #13068 - Derive digest algorithm from ref length in release verify commands by @bdehamer in #13430
📚 Docs & Chores
- Add missing //go:build integration tag to verify_integration_test.go by @pdostal in #13303
- Fix flaky accessible prompter Password test timeout by @pdostal in #13304
- Enable extended PR screening for external PRs by @tidy-dev in #13312
- Grammar fixes by @scop in #13326
- Bump
gh copilottelemetry sampling to 100% by @williammartin in #13362 - Record accessibility feature state in telemetry by @williammartin in #13363
- Poll TTY echo mode instead of sleeping in password tests by @pdostal in #13305
- Switch from actions/attest-build-provenance to actions/attest by @scop in #13325
- Fix skills acceptance tests by @williammartin in #13365
- Bump Go toolchain to 1.26.3 by @Copilot in #13367
- Trigger triage check-requirements on ready_for_review by @BagToad in #13383
- fix(copilot): hint to run copilot directly when exec fails by @babakks in #13393
- Update installation commands for GitHub CLI by @sassdawe in #13126
- Update CODEOWNERS for skills directory ownership by @williammartin in #13416
- fix(telemetry): prevent tzutil console flash on Windows by @adehad in #13353
- Fix bump-go.sh to tolerate missing toolchain directive by @Copilot in #12581
- docs: drop --repo gh-cli from dnf install lines by @c-tonneslan in #13444
- Remove third-party license debris by @williammartin in #13470
- Remove dependency on persistent token by @williammartin in #13474
- Remove discussion workflow by @williammartin in #13476
- Stop bumping homebrew on release by @williammartin in #13479
- build: update golang.org/x/crypto by @tommaso-moro in #13486
- Add 3 day dependabot cooldown period by @williammartin in #13488
- Run govulncheck daily instead of weekly by @williammartin in #13487
- SHA pin first-party GitHub Actions by @williammartin in #13491
- Link to Accessibility category for community discussions instead of ACR by @mxie in #13481
- docs: fix duplicated "of" in release-process-deep-dive by @vip892766gma in #13425
- chore(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 by @BagToad in #13510
- docs: note immutable releases starting v2.93.0 by @BagToad in #13518
- fix CI attestation integration tests after rename by @BagToad in #13536
Dependencies
- chore(deps): bump goreleaser/goreleaser-action from 7.0.0 to 7.2.1 by @dependabot[bot] in #13297
- chore(deps): bump github.com/klauspost/compress from 1.18.5 to 1.18.6 by @dependabot[bot] in #13328
- chore(deps): bump golang.org/x/sys from 0.43.0 to 0.44.0 by @dependabot[bot] in #13381
- chore(deps): bump golang.org/x/term from 0.42.0 to 0.43.0 by @dependabot[bot] in #13396
- chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.81.0 by @dependabot[bot] in #13346
- chore(deps): bump golang.org/x/text from 0.36.0 to 0.37.0 by @dependabot[bot] in #13397
- chore(deps): bump golang.org/x/crypto from 0.50.0 to 0.51.0 by @dependabot[bot] in #13420
- chore(deps): bump google.golang.org/grpc from 1.81.0 to 1.81.1 by @dependabot[bot] in #13436
- chore(deps): bump goreleaser/goreleaser-action from 7.2.1 to 7.2.2 by @dependabot[bot] in #13461
- chore(deps): bump github/codeql-action from 4 to 4.35.5 by @dependabot[bot] in #13489
- chore(deps): bump github.com/theupdateframework/go-tuf/v2 from 2.4.1 to 2.4.2 by @dependabot[bot] in #13462
- chore(deps): bump github.com/google/go-containerregistry from 0.21.5 to 0.21.6 by @dependabot[bot] in #13457
New Contributors
- @pdostal made their first contribution in #13303
- @333fred made their first contribution in #13068
- @scop made their first contribution in #13326
- @sassdawe made their first contribution in #13126
- @adehad made their first contribution in #13353
- @c-tonneslan made their first contribution in #13444
- @tenjaa made their first contribution in #13421
- @mxie made their first contribution in #13481
- @vip892766gma made their first contribution in #13425
Full Changelog: v2.92.0...v2.93.0
GitHub CLI 2.92.0
Security
A security vulnerability has been identified, and fixed, that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using gh run view --log or gh run view --log-failed.
Users are advised to update gh to version v2.92.0 as soon as possible.
For more information see: GHSA-crc3-h8v6-qh57
Support GitHub Enterprise Cloud (GHEC) in skill commandset
Now gh skill subcommands (install, preview, publish, search, update) are able to work with GHEC hosts with data residency.
Add --allow-hidden-dirs flag to skill preview
Following the addition of --allow-hidden-dirs to skill install in the previous release, now the flag is also supported in skill preview, allowing users to preview skills located in hidden (dot-prefixed) directories such as .claude/skills/, .agents/skills/, and .github/skills/.
What's Changed
✨ Features
- feat(skills): add --allow-hidden-dirs flag to preview command by @SamMorrowDrums in #13265
- feat(skills): support GHEC with data residency hosts by @SamMorrowDrums in #13264
🐛 Fixes
- Fix SetSampleRate not updating sample_rate dimension by @williammartin in #13259
- Fix log terminal injection by @williammartin in #13272
- Add "Resource not accessible" to ProjectsV2IgnorableError by @maxbeizer in #13281
📚 Docs & Chores
- fix: using variable interpolation `${{ in deployment.yml... by @orbisai0security in #13258
- docs: correct typo in Linux Homebrew copy by @cassidyjames in #13273
- Install skills flat by Name, not namespaced InstallName by @SamMorrowDrums in #13266
- chore: fix zsh completion on debian by @babakks in #13274
- Add trust disclaimer to extension help text by @travellertales in #13296
- Bump Go to 1.26.2 by @github-actions[bot] in #13301
Dependencies
- chore(deps): bump github.com/mattn/go-isatty from 0.0.20 to 0.0.21 by @dependabot[bot] in #13161
- chore(deps): bump github.com/google/go-containerregistry from 0.21.4 to 0.21.5 by @dependabot[bot] in #13162
- chore(deps): bump charm.land/lipgloss/v2 from 2.0.2 to 2.0.3 by @dependabot[bot] in #13163
- chore(deps): bump charm.land/bubbletea/v2 from 2.0.2 to 2.0.6 by @dependabot[bot] in #13206
- chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.8 to 2.13.9 by @dependabot[bot] in #13241
- chore(deps): bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22 by @dependabot[bot] in #13298
New Contributors
- @orbisai0security made their first contribution in #13258
- @cassidyjames made their first contribution in #13273
- @travellertales made their first contribution in #13296
Full Changelog: v2.91.0...v2.92.0
GitHub CLI 2.91.0
GitHub CLI now collects pseudonymous telemetry
To better understand how features are used in practice, especially as agentic adoption grows, GitHub CLI now sends pseudonymous telemetry.
See Telemetry for more details on what's collected, why, and how to opt out.
Support more agents in gh skill
Thanks to community feedback, gh now supports a large number of agent hosts. Run gh skill install --help for the list of available agents.
Improve skill discovery
gh skill install now adds the --allow-hidden-dirs flag to support discovering skills in hidden (dot-prefixed) directories such as .claude/skills/, .agents/skills/, and .github/skills/.
Detect skills re-published from other sources
GitHub CLI now detects if the skill to be installed is re-published from an upstream source and offers the option to install it from there. The --upstream flag is also added for non-interactive use cases.
What's Changed
✨ Features
- Add support for installation in multiple agent hosts in
gh skills installby @tommaso-moro in #13209 - Add --allow-hidden-dirs flag to gh skill install by @SamMorrowDrums in #13213
- Make skill discovery less strict: support nested
skills/directories by @SamMorrowDrums in #13235 - feat(skills): detect re-published skills and offer upstream install by @SamMorrowDrums in #13236
🐛 Fixes
- Fix
skills publish --fixto not publish by @SamMorrowDrums in #13237 - fix(skills): match skills by install name in preview command by @SamMorrowDrums in #13249
📚 Docs & Chores
- Remove misleading text by @tommaso-moro in #13203
- Add sampled command telemetry by @williammartin in #13191
- Do not send telemetry for aliases by @williammartin in #13192
- Add skills specific telemetry by @williammartin in #13204
- Record CI context in telemetry by @williammartin in #13210
- Record official extension telemetry by @williammartin in #13205
- Add telemetry command by @williammartin in #13253
- Log when there is no telemetry by @williammartin in #13255
- docs(skills): add gh and gh-skill agent skills by @BagToad in #13244
- Enable telemetry without env var by @williammartin in #13254
Full Changelog: v2.90.0...v2.91.0