GitHub CLI

Developer ToolsMIT

GitHub command-line tool

Latest v2.100.0 · by GitHubWritten in GoWebsitecli/cliRSS

Release activity

Release activity — 13 releases across 13 days since Mar 12, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before Mar 12, 2026. Older weeks are hidden at this screen width.
JunJulAugSep
SundayNo releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026No releases on Aug 16, 2026No releases on Aug 23, 2026No releases on Aug 30, 2026No releases on Sep 6, 2026
MondayNo releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026No releases on Aug 17, 2026No releases on Aug 24, 2026No releases on Aug 31, 2026No releases on Sep 7, 2026
TuesdayNo releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026No releases on Aug 11, 2026No releases on Aug 18, 2026No releases on Aug 25, 20261 release on Sep 1, 2026No releases on Sep 8, 2026
Wednesday1 release on May 27, 2026No releases on Jun 3, 20261 release on Jun 10, 20261 release on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026No releases on Aug 12, 2026No releases on Aug 19, 2026No releases on Aug 26, 2026No releases on Sep 2, 2026
ThursdayNo releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 20261 release on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026No releases on Aug 13, 20261 release on Aug 20, 2026No releases on Aug 27, 20261 release on Sep 3, 2026
FridayNo releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 20261 release on Jul 31, 2026No releases on Aug 7, 2026No releases on Aug 14, 2026No releases on Aug 21, 2026No releases on Aug 28, 2026No releases on Sep 4, 2026
SaturdayNo releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026No releases on Aug 15, 2026No releases on Aug 22, 2026No releases on Aug 29, 2026No releases on Sep 5, 2026

13 releases since Mar 12, 2026

Changelog

v2.100.0Latest

GitHub CLI 2.100.0

Added 4
  • Add per-host `api_host` configuration to route GitHub API traffic through a custom gateway
  • Expose `api_host` through `gh config get` and `gh config set` commands
  • Add `webhook` as an official extension
  • Print full command help after command misuse when `gh` is invoked by a coding agent
Fixed 1
  • Disable telemetry for unauthenticated GHES requests using absolute hostnames

From GitHub CLI

Experimental: Route GitHub API traffic through a custom host

Organizations can now route a GitHub host's API traffic through a gateway using the new per-host api_host configuration:

# Route API traffic for github.com through a gateway
gh config set api_host gh-gateway.example.com --host github.com

# Read the configured API host
gh config get api_host --host github.com

The original host remains in use for authentication, Git remotes, and browser URLs.

[!NOTE] api_host is experimental and is not a security boundary. Requests may still reach the original host.

What's Changed
✨ Features
  • Honor per-host api_host routing across GitHub API requests by @williammartin in #14104
  • Expose api_host through gh config get and gh config set by @williammartin in #14332
  • Add webhook as an official extension by @williammartin in #14326
  • Print full command help after command misuse when gh is invoked by a coding agent by @niik in #14198
🐛 Fixes
  • fix(api): disable telemetry for unauthenticated GHES requests using absolute hostnames by @williammartin in #14337
📚 Docs & Chores
  • Fix discussion acceptance test flags by @williammartin in #14321
  • Clarify supported GHES versions by @williammartin in #14324
  • Improve automated issue triage analysis by @sergiou87 in #14318
  • Record attachment counts in telemetry by @BagToad in #14327
:dependabot: Dependencies
  • chore(deps): bump golang.org/x/crypto from 0.55.0 to 0.56.0 by @babakks in #14331
  • chore(deps): bump Go toolchain from 1.26.7 to 1.26.8 by @babakks in #14330
  • chore(deps): bump github.com/cli/go-gh/v2 from 2.15.0 to 2.16.0 by @williammartin in #14338

Full Changelog: https://github.com/cli/cli/compare/v2.99.0...v2.100.0

View originalPermalink
How v2.100.0 went
v2.99.0

GitHub CLI 2.99.0

Added 4
  • Add repeatable `--attach` flag to upload local images and videos to issue, pull request, and comment bodies
  • Add worktree checkout support to `gh issue develop` with `--checkout` and `--worktree` flags
  • Use text-only spinner output when `gh` is invoked by a coding agent
  • Honor `PI_CODING_AGENT_DIR` for Pi user skills
Fixed 9
  • Explain when the target branch is checked out in another worktree in `gh repo sync`
  • Safely handle `--delete-branch` with linked worktrees in `gh pr merge`
  • End the declined-install warning with a newline in copilot
  • Clarify retry windows and attachment path resolution
  • Reject non-empty worktree targets before creating a branch in `gh issue develop`
  • Prevent linked-worktree corruption in `gh repo sync`

From GitHub CLI

Attach images and videos to issues and pull requests

The repeatable --attach flag uploads local images and videos and adds them to issue, pull request, or comment bodies. If a body already references the local path, gh replaces it with the uploaded URL; otherwise it appends the attachment:

# Attach files when creating or editing an issue
gh issue create --attach './repro.png#The error state'
gh issue edit 123 --attach ./walkthrough.mp4

# Attach files when creating or editing a pull request
gh pr create --attach ./before.png
gh pr edit 456 --attach ./after.png

# Attach files to comments
gh issue comment 123 --attach ./repro.png
gh pr comment 456 --attach ./result.mp4

Repeat the flag to attach multiple files in a single invocation. Attachments are available on GitHub.com and GitHub Enterprise Cloud.

For more information see https://gh.io/gh-attach and https://github.blog/changelog/2026-09-01-github-cli-media-in-issues-pull-requests-and-comments/

Worktree support extended to gh issue develop

gh issue develop can now create a linked branch and check it out in a new Git worktree, leaving your current working copy unchanged:

# Create a linked branch for an issue and check it out in a worktree
gh issue develop 123 --checkout --worktree /path/to/wt-feature
What's Changed
✨ Features
  • Add token and repository metadata required for attachment uploads by @BagToad in #14177
  • Add validation for attachable image and video files by @BagToad in #14178
  • Rewrite local Markdown references to uploaded attachment URLs by @BagToad in #14179
  • Add attachment uploads to GitHub by @BagToad in #14180
  • Add repeatable --attach flag parsing and upload orchestration by @BagToad in #14181
  • Add --attach to gh pr comment and gh issue comment by @BagToad in #14182
  • Add --attach to gh pr create and gh pr edit by @BagToad in #14183
  • Add --attach to gh issue create and gh issue edit by @BagToad in #14184
  • Add worktree checkout to gh issue develop by @sergiou87 in #14136
  • Use text-only spinner output when gh is invoked by a coding agent by @niik in #14191
  • Honor PI_CODING_AGENT_DIR for Pi user skills by @tommaso-moro in #14260
🐛 Fixes
  • fix(repo sync): explain when the target branch is checked out in another worktree by @williammartin in #14076
  • fix(pr merge): safely handle --delete-branch with linked worktrees by @tidy-dev in #14007
  • fix(copilot): end the declined-install warning with a newline by @BagToad in #14222
  • fix(attach): clarify retry windows and attachment path resolution by @BagToad in #14262
  • fix(issue develop): reject non-empty worktree targets before creating a branch by @tidy-dev in #14244
  • fix(repo sync): prevent linked-worktree corruption by @sergiou87 in #14060
  • fix(view): reject --comments with --json by @BagToad in #14215
  • fix(attach): limit batches to 50 files by @BagToad in #14289
  • fix(skills): install Codex user skills to ~/.agents/skills by @scarletkc in #14154
📚 Docs & Chores
  • Address review feedback across the --attach stack by @BagToad in #14200
  • Refactor commands to own attachment flag policy by @BagToad in #14255
  • Document attachment support in the gh skill by @BagToad in #14261
  • Document gh issue develop --checkout --worktree in the gh skill by @babakks in #14265
  • Clarify pull request testing guidance by @williammartin in #14272
  • Fix issue triage to apply suspected-spam labels directly by @williammartin in #14271
  • Prevent Dependabot from updating agentic-workflow dependencies by @williammartin in #14274
  • Modernize Go code with go fix by @BagToad in #14278
:dependabot: Dependencies
  • chore(deps): bump google.golang.org/grpc from 1.83.0 to 1.83.1 by @dependabot in #14247
  • chore(deps): bump charm.land/bubbletea/v2 from 2.0.8 to 2.0.9 by @dependabot in #14248
  • chore(deps): bump the codeql-actions group across 1 directory with 3 updates by @dependabot in #14250
  • chore(deps): bump charm.land/bubbles/v2 from 2.1.1 to 2.2.0 by @dependabot in #14249
  • chore(deps): bump agentic-workflows to 0.87.5 by @williammartin in #14273
  • chore(deps): bump charm.land/bubbles/v2 from 2.2.0 to 2.2.1 by @dependabot in #14275
  • chore(deps): bump https://github.com/sigstore/protobuf-specs from 0.5.1 to 0.5.2 by @dependabot in #14258
  • chore(deps): bump https://github.com/google/go-containerregistry from 0.21.9 to 0.22.0 by @dependabot in #14267
  • chore(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 by @dependabot in #14299
  • chore(deps): bump azure/login from 3.0.1 to 3.0.2 by @dependabot in #14301
  • chore(deps): bump the codeql-actions group with 3 updates by @dependabot in #14300
New Contributors

Full Changelog: https://github.com/cli/cli/compare/v2.98.0...v2.99.0

View originalPermalink
How v2.99.0 went
v2.98.0

GitHub CLI 2.98.0

Added 3
  • Add --worktree flag to gh pr checkout to checkout a pull request into a git worktree
  • Add --search-type flag to gh search issues to support semantic and hybrid search
  • Set GH_EXTENSION=1 environment variable when gh invokes an extension
Fixed 3
  • Fix RESTWithNext error type, repairing gh status and attestation retries
  • Trim spaces when parsing X-Oauth-Scopes in gh release create
  • Fix project item-add output for non-TTY
Security 1
  • Fix a vulnerability that bound the local forwarded port to all available network interfaces by default in gh codespace ports forward

From GitHub CLI

Security

A security vulnerability has been identified, and fixed, that binds the local forwarded port to all available network interfaces by default.

Users of gh codespace ports forward are advised to update gh to version v2.98.0 as soon as possible.

For more information see: https://github.com/cli/cli/security/advisories/GHSA-vfhh-p7hm-pxfh

Support worktrees in pr checkout

Users can now checkout a pull request into a git worktree by using the new --worktree PATH flag in gh pr checkout:

gh pr checkout 12 --worktree ../wt-feature
Add semantic search to search issues

The gh search issues command now supports semantic search for issues. Users can select the search type by passing the --search-type flag:

gh search issues --search-type semantic ...

gh search issues --search-type hybrid ...

For more information about semantic search see: "Improved Search for github issues is now generally available".

What's Changed
✨ Features
🐛 Fixes
📚 Docs & Chores
:dependabot: Dependencies
New Contributors

Full Changelog: https://github.com/cli/cli/compare/v2.97.0...v2.98.0

View originalPermalink
How v2.98.0 went
v2.97.0

GitHub CLI 2.97.0

Added 3
  • Add name-based resolution to gh project item-edit to reference project fields and single-select options by name
  • Add named field columns to gh project item-list to show fields as extra columns
  • Add Grok skill host support
Changed 1
  • Replace Windsurf with Devin in gh skill agents
Fixed 3
  • Gracefully handle failed GitHub verifier initialization caused by a missing trusted root
  • Bump keyring operation timeout from 3s to 60s so interactive unlock prompts have time to complete
  • Fix skill picker label wrapping
Security 4
  • Fix escape sequence injection in commands including gh gist view, gh api, gh pr diff, gh release download --output -, gh codespace logs, gh skills preview, and gh agent-task view/create by neutralizing terminal escape sequences
  • Fix request URL construction to properly escape variable path components and prevent altering the request path
  • Fix gh auth status to mask authentication tokens for token types whose format contains an underscore after the prefix, such as github_pat_*, ghs_*, and ghu_*
  • Fix gh attestation verify to escape regex metacharacters in certificate matcher built from --signer-repo and --signer-workflow

From GitHub CLI

Security

Four security vulnerabilities have been identified, and fixed, in this release. Users are advised to update gh to version v2.97.0 as soon as possible.

Several commands (including gh gist view, gh api, gh pr diff, gh release download --output -, gh codespace logs, gh skills preview, and gh agent-task view/create) printed externally controlled content without neutralizing terminal escape sequences, allowing escape sequence injection into a user's terminal.

See https://github.com/cli/cli/security/advisories/GHSA-3m3g-3wcr-px46 for more information.

Some request URLs were built without escaping their variable path components, so a value containing URL path metacharacters could alter the request path and cause gh to address a different resource than intended.

See https://github.com/cli/cli/security/advisories/GHSA-4fjg-2h4q-fwg3 for more information.

gh auth status (without --show-token) could print a portion of the authentication token in plaintext for token types whose format contains an underscore after the prefix, such as github_pat_*, ghs_*, and ghu_*.

See https://github.com/cli/cli/security/advisories/GHSA-cg6r-mpgc-h9mm for more information.

gh attestation verify built the certificate matcher from --signer-repo and --signer-workflow without escaping regex metacharacters, so a lookalike repository or workflow name could satisfy a matcher intended for a trusted signer and bypass attestation verification.

See https://github.com/cli/cli/security/advisories/GHSA-mm27-mwq9-fr5g for more information.

Address project fields and items by name in gh project

gh project item-edit and gh project item-list can now reference project fields and single-select options by name:

# Set an item's field by name
gh project item-edit 1 --owner monalisa --url <url> --field "Status" --value "In Progress"

# Show named fields as extra columns
gh project item-list 1 --owner "@me" --field "Status" --field "Priority"
What's Changed
✨ Features
  • Add name-based resolution to gh project item-edit by @zwick in #13807
  • Add named field columns to gh project item-list by @zwick in #13823
  • Add Grok skill host support by @tommaso-moro in #13864
  • Replace Windsurf with Devin in gh skill agents by @tommaso-moro in #13987
🐛 Fixes
  • Gracefully handle failed GitHub verifier initialization caused by a missing trusted root by @malancas in #13624
  • Bump keyring operation timeout from 3s to 60s so interactive unlock prompts have time to complete by @kofuk in #13787
  • Fix skill picker label wrapping by @tommaso-moro in #13967
📚 Docs & Chores
  • Bump Go to 1.26.5 by @github-actions[bot] in #13817
  • Add OWNER/REPO format hint to the gh search --repo flag by @BagToad in #13922
  • Present by-name item-edit as the first-class project flow in docs by @Solaris-star in #13927
  • Add a macOS keyring security doc by @williammartin in #13960
  • Add a code review agent skill by @BagToad in #14003
  • Establish a pull request template for scale by @BagToad in #14004
  • Add an agentic issue-triage workflow by @lukewar in #13777
  • Use the Actions token for Copilot inference in the issue-triage workflow by @tidy-dev in #13830
  • Refresh the issue-triage agentic workflow to gh-aw v0.83.1 by @alondahari in #13949
  • Add a dependabot-triage agentic workflow by @williammartin in #13985
  • Harden the deployment workflow by @niik in #13780
  • Replace SITE_DEPLOY_PAT with the gh-cli-site-deployer App by @williammartin in #13492
  • Group CodeQL Dependabot updates by @williammartin in #13943
  • Remove a dead CODEOWNERS rule for the non-existent pkg/cmd/release/attestation/ by @kobihikri in #13886
  • Fix typos in code and documentation by @pstoeckle in #13940
  • Fix duplicated-word typos in comments by @SORBELLOSTEFANIE in #13900
:dependabot: Dependencies
  • chore(deps): bump charm.land/lipgloss/v2 from 2.0.4 to 2.0.5 by @dependabot in #13790
  • chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.0 by @dependabot in #13789
  • chore(deps): bump https://github.com/klauspost/compress from 1.18.6 to 1.19.0 by @dependabot in #13791
  • chore(deps): bump charm.land/bubbletea/v2 from 2.0.7 to 2.0.8 by @dependabot in #13800
  • chore(deps): bump golang.org/x/text from 0.38.0 to 0.39.0 by @dependabot in #13812
  • chore(deps): bump golang.org/x/sys from 0.46.0 to 0.47.0 by @dependabot in #13821
  • chore(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3 by @dependabot in #13801
  • chore(deps): bump github/gh-aw-actions/setup from 0.81.6 to 0.82.2 by @dependabot in #13832
  • chore(deps): bump charm.land/bubbles/v2 from 2.1.0 to 2.1.1 by @dependabot in #13813
  • chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 by @dependabot in #13822
  • chore(deps): bump github/gh-aw-actions/setup from 0.82.2 to 0.82.3 by @dependabot in #13843
  • chore(deps): bump actions/cache/restore from 5.0.5 to 6.1.0 by @dependabot in #13841
  • chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 by @dependabot in #13867
  • chore(deps): bump github/codeql-action/analyze from 4.36.3 to 4.37.0 by @dependabot in #13869
  • chore(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.0 by @dependabot in #13868
  • chore(deps): bump github/codeql-action/init from 4.36.3 to 4.37.1 by @dependabot in #13870
  • chore(deps): bump https://github.com/yuin/goldmark from 1.8.2 to 1.8.4 by @dependabot in #13888
  • chore(deps): bump https://github.com/sigstore/sigstore-go from 1.2.1 to 1.2.2 by @dependabot in #13842
  • chore(deps): bump github/gh-aw-actions/setup from 0.82.3 to 0.82.8 by @dependabot in #13877
  • chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0 by @dependabot in #13933
  • chore(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1 by @dependabot in #13934
  • chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 by @dependabot in #13936
  • chore(deps): bump actions/attest from 4.1.1 to 4.2.0 by @dependabot in #13935
  • chore(deps): bump https://github.com/mattn/go-isatty from 0.0.22 to 0.0.23 by @dependabot in #13937
  • chore(deps): bump github/gh-aw-actions/setup from 0.82.8 to 0.82.13 by @dependabot in #13938
  • chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 by @dependabot in #13941
  • chore(deps): bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.1 by @dependabot in #13942
  • chore(deps): bump https://github.com/gabriel-vasile/mimetype from 1.4.13 to 1.4.14 by @dependabot in #13944
  • chore(deps): bump nodeselector/setup-apple-codesign from ab275d0 to 309922b by @dependabot in #13878
  • chore(deps): bump https://github.com/klauspost/compress from 1.19.0 to 1.19.1 by @dependabot in #13950
  • chore(deps): bump github/gh-aw-actions/setup from 0.82.13 to 0.82.14 by @dependabot in #13951
  • chore(deps): bump the codeql-actions group with 3 updates by @dependabot in #13965
  • chore(deps): bump https://github.com/mattn/go-isatty from 0.0.23 to 0.0.24 by @dependabot in #13977
  • chore(deps): bump the codeql-actions group with 3 updates by @dependabot in #13978
  • chore(deps): bump https://github.com/gabriel-vasile/mimetype from 1.4.14 to 1.4.15 by @dependabot in #13976
  • chore(deps): bump github/gh-aw-actions/setup from 0.83.1 to 0.83.2 by @dependabot in #13979
  • chore(deps): bump github/gh-aw-actions/setup-cli from 0.83.1 to 0.83.2 by @dependabot in #13980
  • chore(deps): bump actions/checkout from 6 to 7 by @dependabot in #13981
  • chore(deps): bump github/gh-aw-actions/setup from 0.83.2 to 0.83.3 by @dependabot in #13995
  • chore(deps): bump github/gh-aw-actions/setup-cli from 0.83.2 to 0.83.3 by @dependabot in #13996
  • chore(deps): bump github/gh-aw-actions/setup-cli from 0.83.3 to 0.83.4 by @dependabot in #14018
New Contributors

Full Changelog: https://github.com/cli/cli/compare/v2.96.0...v2.97.0

View originalPermalink
How v2.97.0 went
v2.96.0

GitHub CLI 2.96.0

Added 3
  • Allow gh release download to work without authentication on public repositories
  • Detect additional third-party coding agents
  • Support antigravity-cli and antigravity2.0 in gh skill
Fixed 5
  • Show checks summary when all checks were cancelled
  • Install universal agent to ~/.agents/skills
  • Honor --dir flag in gh skill without agent prompt
  • Fix concurrent map writes in codespace port forwarding
  • Use int64 for GitHub database IDs
Security 1
  • Fix a security vulnerability that could allow command execution when connecting to a malicious Codespace via gh codespace jupyter

From GitHub CLI

Security

A security vulnerability has been identified, and fixed, that could allow command execution on a user's computer when connecting to a malicious Codespace via gh codespace jupyter.

Users of gh codespace jupyter are advised to update gh to version v2.96.0 as soon as possible.

For more information see: https://github.com/cli/cli/security/advisories/GHSA-8cg3-r6g9-fpg2

Download release assets without authentication

gh release download now works against public repositories without authentication, matching gh extension install. A token is still used when one is present:

# Download assets from a public repository, no login required
gh release download v2.96.0 --repo cli/cli
What's Changed
✨ Features
  • Allow gh release download without authentication on public repositories by @BagToad in #13723
  • Detect additional third-party coding agents by @BagToad in #13722
  • Support antigravity-cli and antigravity2.0 in gh skill by @BagToad in #13784
🐛 Fixes
  • fix: show checks summary when all checks were cancelled by @s3onghyun in #13679
  • fix(skills): install universal agent to ~/.agents/skills by @toller892 in #13681
  • fix(skills): honor --dir without agent prompt by @happysnaker in #13766
  • Fix concurrent map writes in codespace port forwarding by @williammartin in #13313
  • Use int64 for GitHub database IDs by @williammartin in #13403
📚 Docs & Chores
  • Pin reusable triage workflows to a commit SHA by @BagToad in #13705
  • Add security disclosure guidance to AGENTS.md by @BagToad in #13720
  • Clarify --clone boolean flag behaviour in gh repo fork help by @BagToad in #13786
  • Fix flaky TestHuhPrompterMultiSelectWithSearchPersistence on slow architectures by @pdostal in #13675
  • docs(search): add examples for multiple qualifiers by @happysnaker in #13756
  • docs: fix broken anchor link in release-process-deep-dive by @patrickwehbe in #13688
  • docs: fix broken install command and link/grammar errors by @patrickwehbe in #13690
  • docs: fix duplicated word in primer README by @s3onghyun in #13677
:dependabot: Dependencies
  • chore(deps): bump github.com/microsoft/dev-tunnels from 0.1.19 to 0.1.27 by @dependabot in #13708
  • chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot in #13703
  • chore(deps): bump github.com/google/go-containerregistry from 0.21.6 to 0.21.7 by @dependabot in #13702
  • chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0 by @dependabot in #13740
  • chore(deps): bump actions/attest from 4.1.0 to 4.1.1 by @dependabot in #13754
  • chore(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 by @dependabot in #13759
  • chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 by @dependabot in #13779
New Contributors

Full Changelog: https://github.com/cli/cli/compare/v2.95.0...v2.96.0

View originalPermalink
How v2.96.0 went
v2.95.0

GitHub CLI 2.95.0

Added 4
  • Add `gh repo read-file` command to read repository files without cloning
  • Add `gh repo read-dir` command to list directory entries in a repository without cloning
  • List available skills when install runs non-interactively
  • Support custom CLAUDE_CONFIG_DIR in install
Fixed 1
  • Stage skills updates in a temporary directory and swap in-place

From GitHub CLI

Read repository files and directories with gh repo read-file and gh repo read-dir

Two new preview commands read repository contents without cloning:

# Read a single file to stdout
gh repo read-file README.md --repo cli/cli

# Read from a specific branch, tag, or commit
gh repo read-file go.mod --ref v2.94.0 --repo cli/cli

# Write a file to disk (use --clobber to overwrite)
gh repo read-file README.md --output ./README.md --repo cli/cli

# List the entries in a directory
gh repo read-dir script --repo cli/cli

Both commands default to the repository's default branch, accept --ref to target any branch, tag, or commit, and support --json, --jq, and --template for scripting. This makes it easy for agents and automation to inspect a repo without a full checkout.

[!NOTE] gh repo read-file and gh repo read-dir are in preview and subject to change without notice.

What's Changed
✨ Features
🐛 Fixes
📚 Docs & Chores
:dependabot: Dependencies

Full Changelog: https://github.com/cli/cli/compare/v2.94.0...v2.95.0

View originalPermalink
How v2.95.0 went
v2.94.0

GitHub CLI 2.94.0

Added 7
  • Add gh discussion command set (list, view, create, edit) as a preview
  • Add gh discussion comment to comment on and reply to discussions
  • Add issue types, sub-issues, and relationships support to gh issue create, edit, view, and list
  • Add gh skill list to inventory installed agent skills
  • Add --all flag to gh skill install to install every skill in a repository
  • Alias gh extension uninstall to gh extension remove
  • Auto-install official extensions in CI
Changed 1
  • Skip skills without metadata when running gh skill update --all
Fixed 1
  • Support skill discovery in nested directories

From GitHub CLI

Issue types, sub-issues, and relationships in gh issue

This release brings GitHub's advanced issue features to gh issue create, edit, view, and list. You can set and view an issue's type, organize work with sub-issues, and track blocked-by and blocking relationships without leaving the command line:

# Set an issue's type
gh issue create --type Bug
gh issue edit 123 --type Bug

# Organize work with sub-issues
gh issue create --parent 100
gh issue edit 100 --add-sub-issue 123

# Track blocked-by and blocking relationships
gh issue create --blocked-by 200
gh issue edit 123 --add-blocking 300

Issue types and sub-issues are available on GitHub.com and GHES 3.17+; relationships require GHES 3.19+.

Manage discussions with gh discussion

This release introduces the discussion command set for working with GitHub Discussions in gh:

# List discussions
gh discussion list

# View a discussion, its comments, or replies to a comment
gh discussion view 123 --comments

# Create a discussion
gh discussion create

# Edit a discussion
gh discussion edit 123

# Comment on a discussion
gh discussion comment 123

# Reply to a comment using its URL
gh discussion comment <url>

Run gh discussion --help for more information.

[!NOTE] The discussion command set is in preview and is subject to change without notice.

Equip your agents with new gh features

Teach your agents how to leverage new GitHub CLI features on release day by installing the gh skill:

# Install
gh skill install cli/cli gh --scope user

# Or update
gh skill update gh
What's Changed
✨ Features
  • Add gh discussion command set (list, view, create, edit) as a preview by @babakks and @maxbeizer in #13541
  • Add gh discussion comment to comment on and reply to discussions by @babakks in #13620
  • Add Issues 2.0 support: issue types, sub-issues, and relationships by @BagToad in #13057
  • Add gh skill list to inventory installed agent skills by @tommaso-moro in #13418
  • Add --all flag to gh skill install to install every skill in a repository by @tommaso-moro in #13471
  • Skip skills without metadata when running gh skill update --all by @tommaso-moro in #13469
  • Alias gh extension uninstall to gh extension remove by @BagToad in #13599
  • Auto-install official extensions in CI by @BagToad in #13581
🐛 Fixes
  • fix(skill): support skill discovery in nested directories by @tommaso-moro in #13459
📚 Docs & Chores
  • Bump Go to 1.26.4 by @github-actions[bot] in #13578
  • Clean up deferred issue update helper by @BagToad in #13584
  • Add terminal-mockup canvas extension for marketing screenshots by @BagToad in #13612
  • Add gh discussion and Issues 2.0 reference to the gh skill, plus a README note by @BagToad in #13631
:dependabot: Dependencies
  • chore(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 by @dependabot in #13521
  • chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.9 to 2.13.10 by @dependabot in #13520
  • chore(deps): bump github.com/mattn/go-colorable from 0.1.14 to 0.1.15 by @dependabot in #13572
  • chore(deps): bump charm.land/bubbletea/v2 from 2.0.6 to 2.0.7 by @dependabot in #13595
  • chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1 by @dependabot in #13596
  • chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 by @dependabot in #13597

Full Changelog: https://github.com/cli/cli/compare/v2.93.0...v2.94.0

View originalPermalink
How v2.94.0 went
v2.93.0

GitHub CLI 2.93.0

Added 1
  • Allow agents as application for secrets in the gh secret command set
Fixed 3
  • Remove numberFieldOnly optimization in pull request command that skips API validation
  • Print gh auth refresh for 401 returns
  • Derive digest algorithm from ref length in release verify commands
Security 1
  • Fix security vulnerability that would incorrectly include authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands

From GitHub CLI

Security

A security vulnerability has been identified, and fixed, that would incorrectly include authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands.

Users are advised to update gh to version v2.93.0 as soon as possible.

For more information see: https://github.com/cli/cli/security/advisories/GHSA-8xvp-7hj6-mcj9

Support agents in gh secret command set

The gh secret command set can now set agent secrets. For more information, see "Configuring secrets and variables for Copilot cloud agent".

What's Changed
✨ Features
🐛 Fixes
📚 Docs & Chores
:dependabot: Dependencies
New Contributors

Full Changelog: https://github.com/cli/cli/compare/v2.92.0...v2.93.0

View originalPermalink
How v2.93.0 went
v2.92.0

GitHub CLI 2.92.0

Added 2
  • Support GitHub Enterprise Cloud (GHEC) with data residency in skill subcommands (install, preview, publish, search, update)
  • Add --allow-hidden-dirs flag to skill preview command
Fixed 2
  • Fix SetSampleRate not updating sample_rate dimension
  • Add "Resource not accessible" to ProjectsV2IgnorableError
Security 1
  • Fix terminal escape sequence injection vulnerability in gh run view --log and gh run view --log-failed

From GitHub CLI

Security

A security vulnerability has been identified, and fixed, that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using gh run view --log or gh run view --log-failed.

Users are advised to update gh to version v2.92.0 as soon as possible.

For more information see: https://github.com/cli/cli/security/advisories/GHSA-crc3-h8v6-qh57

Support GitHub Enterprise Cloud (GHEC) in skill commandset

Now gh skill subcommands (install, preview, publish, search, update) are able to work with GHEC hosts with data residency.

Add --allow-hidden-dirs flag to skill preview

Following the addition of --allow-hidden-dirs to skill install in the previous release, now the flag is also supported in skill preview, allowing users to preview skills located in hidden (dot-prefixed) directories such as .claude/skills/, .agents/skills/, and .github/skills/.

What's Changed
✨ Features
🐛 Fixes
📚 Docs & Chores
:dependabot: Dependencies
New Contributors

Full Changelog: https://github.com/cli/cli/compare/v2.91.0...v2.92.0

View originalPermalink
How v2.92.0 went
v2.91.0

GitHub CLI 2.91.0

Added 6
  • GitHub CLI now sends pseudonymous telemetry to better understand how features are used
  • Support more agents in gh skill by enabling installation in multiple agent hosts
  • Add --allow-hidden-dirs flag to gh skill install to discover skills in hidden directories
  • Support nested skills/ directories in skill discovery
  • Detect if a skill to be installed is re-published from an upstream source and offer the option to install from there
  • Add --upstream flag to gh skill install for non-interactive use cases
Fixed 2
  • Fix gh skills publish --fix to not publish when only fixing is intended
  • Fix skill matching in preview command to use install name

From GitHub CLI

GitHub CLI now collects pseudonymous telemetry

To better understand how features are used in practice, especially as agentic adoption grows, GitHub CLI now sends pseudonymous telemetry.

See Telemetry for more details on what's collected, why, and how to opt out.

Support more agents in gh skill

Thanks to community feedback, gh now supports a large number of agent hosts. Run gh skill install --help for the list of available agents.

Improve skill discovery

gh skill install now adds the --allow-hidden-dirs flag to support discovering skills in hidden (dot-prefixed) directories such as .claude/skills/, .agents/skills/, and .github/skills/.

Detect skills re-published from other sources

GitHub CLI now detects if the skill to be installed is re-published from an upstream source and offers the option to install it from there. The --upstream flag is also added for non-interactive use cases.

What's Changed
:sparkles: Features
:bug: Fixes
:books: Docs & Chores

Full Changelog: https://github.com/cli/cli/compare/v2.90.0...v2.91.0

View originalPermalink
How v2.91.0 went
v2.90.0

GitHub CLI 2.90.0

Added 9
  • Add gh skill command group to discover, install, manage, and publish agent skills from GitHub repositories
  • gh skill search command to discover available skills
  • gh skill preview command to preview a skill without installing it
  • gh skill install command to install agent skills with support for pinning to specific versions
  • gh skill update command to check installed skills for updates
  • gh skill publish command to validate and publish agent skills with supply chain security checks
Changed 2
  • gh extension install no longer requires authentication to download public release assets
  • gh skill publish automatically pushes unpushed commits before publishing
Fixed 6
  • Fix infinite loop in gh release list --limit 0
  • Ensure api and auth commands record agentic invocations
  • Disable auth check for local-only skill flags
  • URL-encode parentPath in skills discovery API call
  • Fix use of target directory remotes in skills publish
  • Preserve namespace in skills search deduplication

From GitHub CLI

Manage agent skills with gh skill (Public Preview)

Agent skills are portable sets of instructions, scripts, and resources that teach AI coding agents how to perform specific tasks. The new gh skill command makes it easy to discover, install, manage, and publish agent skills from GitHub repositories - right from the CLI.

# Discover skills
gh skill search copilot

# Preview a skill without installing
gh skill preview github/awesome-copilot documentation-writer

# Install a skill
gh skill install github/awesome-copilot documentation-writer

# Pin to a specific version
gh skill install github/awesome-copilot documentation-writer --pin v1.2.0

# Check installed skills for updates
gh skill update --all

# Validate and publish your own skills
gh skill publish --dry-run

Skills are automatically installed to the correct directory for your agent host. gh skill supports GitHub Copilot, Claude Code, Cursor, Codex, Gemini CLI, and Antigravity. Target a specific agent and scope with --agent and --scope flags.

gh skill publish validates skills against the Agent Skills specification and checks remote settings like tag protection and immutable releases to improve supply chain security.

Read the full announcement on the GitHub Blog.

gh skill is launching in public preview and is subject to change without notice.

Official extension suggestions

When you run a command that matches a known official extension that isn't installed (e.g. gh stack), the CLI now offers to install it instead of showing a generic "unknown command" error.

This feature is available for github/gh-aw and github/gh-stack.

When possible, you'll be prompted to install immediately. When prompting isn't possible, the CLI prints the gh extension install command to run.

gh extension install no longer requires authentication

gh extension install previously required a valid auth token even though it only needs to download a public release asset. The auth check has been removed, so you can install extensions without being logged in.

What's Changed
✨ Features
🐛 Fixes
📚 Docs & Chores
:dependabot: Dependencies
New Contributors

Full Changelog: https://github.com/cli/cli/compare/v2.89.0...v2.90.0

View originalPermalink
How v2.90.0 went
v2.89.0

GitHub CLI 2.89.0

Added 2
  • New experimental TUI-based prompter powered by charmbracelet/huh available behind the GH_EXPERIMENTAL_PROMPTER environment variable
  • gh pr create, gh issue create, and gh issue edit now support search-based assignee selection and login-based mutation on github.com
Changed 1
  • Record agentic invocations in User-Agent header
Fixed 3
  • gh agent-task now resolves the Copilot API URL dynamically per host instead of using a hardcoded URL, fixing 401 Unauthorized errors on ghe.com tenancies
  • gh issue create and gh issue transfer now fetch only minimal fields necessary for issue operations, removing the requirement for extra token scopes
  • Resolve data race in codespaces port forwarder

From GitHub CLI

:copilot: gh agent-task now works on ghe.com tenancies

gh agent-task commands previously failed with 401 Unauthorized for users on ghe.com tenancy hosts because the Copilot API URL was hardcoded. The URL is now resolved dynamically per host, so gh agent-task works correctly regardless of your GitHub hosting environment.

Experimental new prompter

A new TUI-based prompter powered by charmbracelet/huh is available behind the GH_EXPERIMENTAL_PROMPTER environment variable. This is an early preview — try it out and share feedback!

export GH_EXPERIMENTAL_PROMPTER=1
gh issue create and gh issue transfer no longer require extra token scopes

gh issue create and gh issue transfer previously fetched repository fields they didn't need, which could require additional token scopes. These commands now fetch only the minimal fields necessary for issue operations.

What's Changed
✨ Features
  • gh pr create, gh issue create, gh issue edit: search-based assignee selection and login-based mutation on github.com by @BagToad in #13009
  • Add experimental huh-only prompter gated by GH_EXPERIMENTAL_PROMPTER by @BagToad in #12859
🐛 Fixes
  • fix(agent-task): resolve Copilot API URL dynamically for ghe.com tenancies by @BagToad in #12956
  • fix(issue): avoid fetching unnecessary fields in issue create and issue transfer by @babakks in #12884
  • fix: resolve data race in codespaces port forwarder by @Lslightly in #13033
📚 Docs & Chores
:dependabot: Dependencies
  • chore(deps): bump google.golang.org/grpc from 1.79.2 to 1.79.3 by @dependabot[bot] in #12963
  • chore(deps): bump github.com/google/go-containerregistry from 0.20.7 to 0.21.3 by @dependabot[bot] in #12962
  • chore(deps): bump github.com/zalando/go-keyring from 0.2.6 to 0.2.8 by @dependabot[bot] in #13031
  • chore(deps): bump microsoft/setup-msbuild from 2.0.0 to 3.0.0 by @dependabot[bot] in #13005
  • chore(deps): bump mislav/bump-homebrew-formula-action from 3.6 to 4.1 by @dependabot[bot] in #13004
  • chore(deps): bump azure/login from 2.3.0 to 3.0.0 by @dependabot[bot] in #12951
New Contributors

Full Changelog: v2.88.1...v2.89.0

View originalPermalink
How v2.89.0 went
v2.88.1

GitHub CLI 2.88.1

Changed 1
  • Migrate Windows code signing from client secret to OIDC
Fixed 1
  • Revert changes that broke error matching for graceful handling of missing read:project scope in pr commands

From GitHub CLI

Fix pr commands failing with read:project scope error

v2.88.0 introduced a regression where pr commands would fail with the error:

error: your authentication token is missing required scopes [read:project]
To request it, run:  gh auth refresh -s read:project

Previously, missing read:project scope was gracefully handled, and project data was silently skipped. A change inadvertently broke the error matching that enabled this graceful degradation. v2.88.1 reverts these changes so that pr commands work correctly without requiring the read:project scope.

What's Changed

Full Changelog: https://github.com/cli/cli/compare/v2.88.0...v2.88.1

View originalPermalink
How v2.88.1 went
View all

Discussion

If you publish GitHub CLI, you can claim this product by proving you administer its repository.