Описание
Security update for gh
This update for gh fixes the following issues:
Changes in gh:
-
Update to version 2.96.0:
- Critical security fix: patched vulnerability in gh codespace jupyter that could allow command execution when connecting to malicious Codespaces
- Merge commit from fork
- Fix concurrent map writes in codespace port forwarding (#13313)
- docs: fix broken install command and link/grammar errors (#13690)
- Clarify
--cloneboolean flag behaviour ingh repo forkhelp (#13786) - docs: fix duplicated word in primer README (#13677)
- fix(skills): honor --dir without agent prompt (#13766)
- Support antigravity-cli and antigravity2.0 in gh skill (#13784)
- chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0
- docs(search): reword raw qualifier examples
- chore(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3
- docs(search): simplify raw qualifier examples
- docs(search): add examples for multiple qualifiers
- chore(deps): bump actions/attest from 4.1.0 to 4.1.1
- chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0
- fix(cmdutil): honor DisableAuthCheck under repo-override parents
- feat(release): allow download without authentication
- fix(release): don't let a failed draft lookup mask a found release
- Fix flaky TestHuhPrompterMultiSelectWithSearchPersistence on slow architectures (#13675)
- Detect additional third-party coding agents (#13722)
- Add security disclosure guidance to AGENTS.md (#13720)
- chore(deps): bump actions/checkout from 6.0.3 to 7.0.0
- chore(deps): bump github.com/microsoft/dev-tunnels from 0.1.19 to 0.1.27
- ci: pin GitHub Actions to commit SHAs
- chore(deps): bump github.com/google/go-containerregistry
- Use int64 for GitHub database IDs (#13403)
- docs: fix broken anchor link in release-process-deep-dive (#13688)
- Cover all printSummary branches in a table test
- fix(skills): install universal agent to ~/.agents/skills
- fix: show checks summary when all checks were cancelled
-
The following bugs are no longer present in this release (may have been fixed in previous releases): bsc#1234566, bsc#1235345, bsc#1237669, bsc#1239496, bsc#1241837, bsc#1243930, bsc#1251464, bsc#1251666, bsc#1253929, bsc#1258617, bsc#1260271, bsc#1262339, bsc#1262943, bsc#1265405, bsc#1265777, bsc#1266173, bsc#1266618, bsc#1266975, bsc#1267158, bsc#1269427
-
Update to version 2.95.0:
- feat(skills): list available skills when install runs non-interactively (#13548)
- fix(skills): stage updates in a temp dir and swap in-place (#13449)
- feat: add
repo read-fileandrepo read-dir(#13580) - Bump Go in devcontainer
- Make filtering by bot authors more discoverable (#13642)
- chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0
- chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0
- chore(deps): bump charm.land/lipgloss/v2 from 2.0.3 to 2.0.4
- chore(deps): bump github.com/sigstore/sigstore-go from 1.1.4 to 1.2.1
- chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0
- test(skill): fix test case name
- test(skill): merge isolated test into table
- Potential fix for pull request finding
- docs(discussion): polish help docs
- chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2
- fix test
- support custom CLAUDE_CONFIG_DIR in install
-
Update to version 2.94.0:
- Add gh discussion and Issues 2.0 reference to the
ghskill, plus a README note (#13631) - fix(discussion comment): fix bug in requiring body/body-file in add/edit mode
- chore(discussion/client): rename client files
- test(acceptance): fix discussion comment acceptance tests
- fix(discussion/shared): error on out-of-range discussion number in URL
- fix(discussion view): print only requested items in non-tty output
- docs(discussion list): clarify answered examples refer to Q&A discussions
- fix(discussion view): show comments and replies in chronological order
- refactor(discussion list): simplify no-results message and use success icon helper
- fix(discussion view): use color scheme method for success icon
- fix(discussion view): error when --comments is used with a comment argument
- test(acceptance): use positional comment argument in discussion view test
- refactor(discussion/client): take host instead of repo in GetComment
- refactor(discussion view): replace --replies flag with positional comment argument
- chore: fix formatting
- test(acceptance): cover discussion comment URLs in comment and view tests
- feat(discussion): support comment URLs in --replies and comment command
- test(discussion comment): add non-tty delete flag validation test case
- test(acceptance): add discussion comment acceptance test
- refactor(acceptance): use discussion comment command instead of raw API calls
- feat(discussion): add discussion comment command
- feat(discussion/client): add comment manipulation methods
- chore: apply formatting
- chore(discussion): remove unused HttpClient field from create and edit
- fix(discussion): remove redundant error wrapping on ListCategories
- test(discussion list): rename TestNewCmdList2 to TestNewCmdList
- Add terminal-mockup canvas extension for marketing screenshots (#13612)
- fix(discussion): add missing repo flag override
- test(discussion list): consolidate tests into table-driven format
- docs(acceptance): add new jq2env and jq-assert functions
- test(discussion): add acceptance tests for discussion commands
- fix(discussion list): print "answered" instead of checkmark in non-tty mode
- refactor(discussion/client): precheck discussions enabled via getRepositoryMeta
- refactor(discussion): add Cursor field and ExportData to DiscussionListResult
- feat(extension): alias
uninstalltoremove - chore(deps): bump actions/checkout from 6.0.2 to 6.0.3
- chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1
- chore(deps): bump charm.land/bubbletea/v2 from 2.0.6 to 2.0.7
- docs(discussion view): improve long help text for clarity
- fix(discussion): handle partial failure on create/update label mutations
- Clean up deferred issue update helper (#13584)
- Auto-install official extension stubs in CI (#13581)
- chore(discussion/client): fix formatting
- docs(discussion/client): add godoc to exported consts
- refactor(discussion list): make pager call/error consistent with view command
- refactor(discussion): extract command-level consts for enums
- fix(discussion): various polish and small fixes
- Merge pull request #13057 from cli/kw/issues-2.0
- Bump Go to 1.26.4
- chore(deps): bump github.com/mattn/go-colorable from 0.1.14 to 0.1.15
- address review comments
- feat(discussion edit): add discussion edit command
- feat(discussion create): add discussion create command
- feat(discussion view): add discussion view command
- feat(discussion list): add discussion list command
- feat(discussion/shared): add shared utilities for discussion commands
- feat(discussion/client): add discussion client package
- Use github-copilot agent ID in skill list tests and help text
- Rename hosts field and helpers to agentHosts in skill list
- Stat SKILL.md before reading in skill list
- Sanitize terminal control characters in skill list output
- chore(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1
- chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.9 to 2.13.10
- address copilot comments, clarify text
- address copilot comments
- handle skills in skills/ folder when running list command, by marking them as published
- address bagtoad's feedback
- add --all flag to install all skills in a repo
- fix warning message to make it clear
- skip prompting for skills without metadata when running gh skill update --all
- add logic to preview too
- fix discovery support in nested dirs
- fix test
- fix tests
- fix linting
- add skill list command
- Add gh discussion and Issues 2.0 reference to the
-
Update to version 2.93.0:
- test(attestation): align integration tests with new external HTTP client
- fix: use separate http client for non-github hosts
- docs: note immutable releases starting v2.93.0
- bump golang.org/x/net
- Link to Accessibility category for community discussions instead of ACR (#13481)
- Allow agents as application for secrets (#13421)
- SHA pin first-party GitHub Actions
- chore(deps): bump github/codeql-action from 4 to 4.35.5
- Add 3 day dependabot cooldown period
- chore(deps): bump github.com/google/go-containerregistry
- Run govulncheck daily instead of weekly
- Merge pull request #13486 from cli/tommy/update-x-crypto
- Potential fix for pull request finding
- Potential fix for pull request finding
- Stop bumping homebrew on release
- chore(deps): bump goreleaser/goreleaser-action from 7.2.1 to 7.2.2 (#13461)
- Remove discussion workflow
- Remove dependency on persistent token
- Remove third-party license debris
- chore(deps): bump github.com/theupdateframework/go-tuf/v2
- docs: drop --repo gh-cli from dnf install lines
- Assert digest prefix in release verify no-attestation tests
- chore(deps): bump google.golang.org/grpc from 1.81.0 to 1.81.1
- Derive digest algorithm from ref length in release verify commands
- docs: fix duplicated "of" in release-process-deep-dive
- chore(deps): bump golang.org/x/crypto from 0.50.0 to 0.51.0
- Simplify bump-go.sh toolchain logic
- Remove unnecessary null checks in jq output handling
- Rewrite script to use go mod edit instead of grep/sed
- Address code review comments
- Improve version comparison to handle both X.Y.0 and X.Y.Z formats
- Update bump-go.sh to handle missing toolchain directive
- Initial plan
- Update CODEOWNERS for skills directory ownership
- chore(deps): bump golang.org/x/text from 0.36.0 to 0.37.0
- chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.81.0
- chore(deps): bump golang.org/x/term from 0.42.0 to 0.43.0
- fix(copilot): update test assertion to match updated error message
- fix(copilot): provide full path to copilot binary on exec error
- fix(copilot): hint to run copilot directly when exec fails
- fix(telemetry): use CREATE_NO_WINDOW to prevent tzutil console flash on Windows
- Fix triage-pull-requests skipping PRs that open as draft
- chore(deps): bump golang.org/x/sys from 0.43.0 to 0.44.0
- Bump Go toolchain to 1.26.3
- Fix skills acceptance tests
- Add explicit build tags to platform-specific echo test files
- Address review feedback on echo mode polling
- Poll TTY echo mode instead of sleeping in password tests
- Record accessibility state in telemetry
- Bump copilot telemetry sampling to 100%
- chore(deps): bump github.com/klauspost/compress from 1.18.5 to 1.18.6
- Remove numberFieldOnly API shortcut
- Grammar fixes
- Switch from actions/attest-build-provenance to actions/attest
- Enable extended PR screening for external PRs
- Fix flaky Password test by increasing echo mode setup timeout
- Add missing //go:build integration tag to verify_integration_test.go
- chore(deps): bump goreleaser/goreleaser-action from 7.0.0 to 7.2.1
- Apply patch from code review feedback.
- Print
gh auth refreshfor 401 returns - Update installation commands for GitHub CLI
-
Update to version 2.92.0:
- Bump Go to 1.26.2
- chore(deps): bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22
- Update command.go
- Add "Resource not accessible" to ProjectsV2IgnorableError
- chore: fix zsh completion on debian
- install_linux: correct typo in Homebrew copy
- chore(deps): bump charm.land/bubbletea/v2 from 2.0.2 to 2.0.6
- chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.8 to 2.13.9
- Update acceptance/testdata/workflow/run-view-log-escape-sequences.txtar
- Fix log terminal injection
- fix(skills): include --allow-hidden-dirs in preview hint from install
- Install skills flat by Name, not namespaced InstallName
- feat(skills): add --allow-hidden-dirs flag to preview command
- feat(skills): support GHEC with data residency hosts
- Fix SetSampleRate not updating sample_rate dimension
- fix: yaml.github-actions.security.run-shell-injection.run-shell-injection security vulnerability
- Enable telemetry without env var
- test(telemetry): assert ANSI escape chars for color codes
- fix(telemetry): lower bias in sample bucket calc
- feat(skills): detect re-published skills and offer upstream install
- Log when there is no telemetry
- Add telemetry command
- Record official extension telemetry
- fix(skills): prioritize DisplayName/Name over InstallName match
- fix(skills): match skills by install name in preview command
- use the right json field names for skills
- fix totalCount guidance
- docs(skills): note --template collisions and single-string search
- backtick skill filename
- docs(skills): drop hand-copied naming rules from gh-skill
- use hyphen instead
- docs(skills): add gh and gh-skill agent skills
- feat(skills): support nested skills/ directories in discovery
- fix(skills): make --fix and --dry-run mutually exclusive, suppress publish prompt
- fix(skills): use canonical 'gh skill' not 'gh skills' alias
- fix(skills): stop publish --fix from publishing
- Include CI context in telemetry
- refactor: decouple hidden-dir filtering from discovery layer
- Add support for installation in multiple agent hosts in
gh skills install(#13209) - Add skills specific telemetry
- chore(deps): bump github.com/google/go-containerregistry
- Do not send telemetry for aliases
- Apply review feedback
- Disable telemetry for GHES
- remove misleading text
- Add sampled command telemetry
- Update publish_test.go
- refactor: replace real git with run.CommandStubber in publish tests
- fix: apply review feedback — nil HttpClient, local dedup type
- Remove dispatch after install, install only
- Rename official extension files and types to stubs
- Replace em-dashes with regular dashes
- Address PR review feedback
- Add no em dash rule to AGENTS.md
- Suggest and install official extensions via stub commands
- Add @cli/code-reviewers to all CODEOWNERS rules
- Add cli/skill-reviewers as CODEOWNERS for skills packages
- style: fix gofmt alignment in publish tests
- fix: update acceptance test to match current error message
- fix: address post-merge review feedback for skills commands
- refactor: remove redundant nil-client fallback in skills publish (#13168)
- feat(skills): auto-push unpushed commits before publish
- refactor: use shared discovery logic in publish command
- fix(skill publish): remove misleading
validatealias - docs(skill): improve help docs
- fix skills names in examples
- Disable auth check for
gh extension install - Suggest and install official extensions for unknown commands
- Update acceptance/testdata/skills/skills-search-noresults.txtar
- URL-encode parentPath in skills discovery API call
- Disable auth check for local-only skill flags
- fix: address review feedback on namespace changes
- chore: remove unused newTestGitClient function
- fix: preserve namespace in skills search deduplication
- fix: use target directory remotes in skills publish
- fix: enforce size cap on first preview file, surface corrupted skills, fail on path traversal
- fix: align relevanceScore comments with implementation and fix typo
- chore(deps): bump charm.land/lipgloss/v2 from 2.0.2 to 2.0.3
- chore(deps): bump github.com/mattn/go-isatty from 0.0.20 to 0.0.21
- address review comments
- clean up interface and fix a few bugs
- cleanup frontmatter fields
- add .agents/skills as default installation path for hosts that support it: cursor, codex, gemini CLI, github copilot, antigravity.
- show loading spinner during installation, even for multi-file skills
- use markdown renderer in preview when previewing multi-file skills
- Expand test coverage and fix invariants/bugs
- add core logic and improve test coverage
- improve test coverage/cleanup
- register initial skills commands
- add skills command scaffold
- docs: fix SHA512 checksum for GPG key
- chore(deps): bump github.com/hashicorp/go-version from 1.8.0 to 1.9.0
- chore(deps): bump google.golang.org/grpc from 1.79.3 to 1.80.0
- chore(deps): bump github.com/sigstore/timestamp-authority/v2
- docs: add sha/md5 checksums of keyring files
- chore(deps): bump github.com/google/go-containerregistry
- chore(deps): bump github.com/sigstore/protobuf-specs from 0.5.0 to 0.5.1
- chore: delete experimental script/debian-devel
- chore(deps): bump charm.land/bubbles/v2 from 2.0.0 to 2.1.0
- Document dependency CVE policy in SECURITY.md
- docs: add manual PGP key verification commands
- chore: re-add toolchain to go1.26.2
- docs: polish wording around PGP keys
- docs: include PGP key fingerprints
- Fix infinite loop in 'gh release list --limit 0'
- chore(deps): bump github.com/in-toto/attestation from 1.1.2 to 1.2.0
- chore(deps): bump github.com/klauspost/compress from 1.18.4 to 1.18.5
- test(internal/authflow): assert user-agent header is not modified/added
- replace github.com/golang/snappy with klauspost/compress/snappy
- docs: require tests and linter pass before committing
- fix(auth): preserve User-Agent in authflow getViewer
- fix(api): propagate InvokingAgent in gh api HTTP client
- chore(deps): bump github.com/yuin/goldmark from 1.7.16 to 1.8.2
- chore(deps): bump advanced-security/filter-sarif from 1.0.1 to 1.1
-
Update to version 2.89.0:
- Ensure huh prompter cleans up
- fix(huh prompter): remove unused fields and imports
- go mod tidy
- feat(huh prompter): clear search input after submitting query
- refactor(huh prompter): custom Field for MultiSelectWithSearch
- feat(huh prompter): add placeholder to search input
- fix(huh prompter): use synchronized accessors to eliminate data race
- fix(accessible prompter): update test expectations for huh v2
- refactor(huh prompter): pipe-based test harness with full coverage
- test(huh prompter): add table-driven tests for all prompt types
- Upgrade to huh/v2 and fix selection persistence in MultiSelectWithSearch
- Fix gofmt alignment for prompter-enabled fields in IOStreams
- Use LayoutStack for huhPrompter MultiSelectWithSearch
- Add experimental huh-only prompter gated by GH_EXPERIMENTAL_PROMPTER
- Add nameWithOwner to necessary tests
- fix(pr view): fetch nameWithOwner in headRepository GraphQL query
- test(acceptance): remove run-download-traversal test
- fix(acceptance): set git identity in testscript sandbox
- internal/codespaces/portforwarder: define err in go func instead of use err defined in outer scope
- chore(deps): bump github.com/zalando/go-keyring from 0.2.6 to 0.2.8
- Update docs/triage.md
- Update docs/triage.md
- Align triage.md with unified triage process
- Fix typo: remove extra space in README.md link
- fix(survey): use useReviewerSearch consistently in prompt path
- fix(pr create): wire up @copilot assignee replacement and [bot] suffix
- refactor(survey): simplify ApiActorsSupported in RepoMetadataInput
- docs(featuredetection): document GHES removal criteria for ApiActorsSupported
- refactor(featuredetection): rename ActorIsAssignable to ApiActorsSupported
- refactor(pr shared): consolidate ActorAssignees and ActorReviewers into ApiActorsSupported
- refactor(pr shared): extract SpecialAssigneeReplacer for @me and Copilot expansion
- chore(deps): bump github.com/google/go-containerregistry
- Record agentic invocations in User-Agent header
- Address review: table tests, godocs, code style
- Add AGENTS.md optimized for AI agent token efficiency
- docs: simplify flag text
- docs(pr edit): improve command examples with grouped sections
- docs: clarify that --add-reviewer can re-request reviews
- feat(pr create, issue create): search-based assignee selection in MetadataSurvey
- review: address code review feedback
- refactor(issue edit): wire up search-based assignee selection
- refactor(pr edit): remove actor accumulation hack from assignee search
- refactor(pr edit, issue edit): use login-based assignee mutation for flag flows
- fix(pr create): use login-based assignee mutation on github.com
- chore(deps): bump microsoft/setup-msbuild from 2.0.0 to 3.0.0
- chore(deps): bump mislav/bump-homebrew-formula-action from 3.6 to 4.1
- Remove auto-labels from issue templates
- fix(agent-task): resolve Copilot API URL dynamically (#12956)
- chore(deps): bump google.golang.org/grpc from 1.79.2 to 1.79.3
- chore(deps): bump azure/login from 2.3.0 to 3.0.0
- fix: improve docs around IssueRepoInfo
- test(issue transfer): update stub for IssueRepositoryInfo query
- fix(issue transfer): use IssueRepoInfo to fetch minimal fields for issues
- test(issue create): update stubs for IssueRepositoryInfo query
- fix(issue create): use IssueRepoInfo to avoid requiring Contents:Read permission
- test(api): add tests for GitHubRepo and IssueRepoInfo
- refactor(api): add IssueRepoInfo for minimal issue repo queries
-
Update to version 2.88.1:
- Revert "fix: clarify scope error while creating issues for projects"
- Revert "refactor: deduplicate scope error handling between api/client.go and project queries"
- Switch deployment signing to OIDC authentication
-
Update to version 2.88.0:
- fix: add if guard to no-response job to prevent running on workflow_dispatch
- Add pitch surfacing workflow (monthly + manual dispatch)
- fix: address review feedback on squash merge commit message
- fix: gofmt alignment in test struct literals
- feat(repo): add --squash-merge-commit-message flag to gh repo edit
- chore(deps): bump golang.org/x/sync from 0.19.0 to 0.20.0
- refactor: change extractFileName param from []byte to string
- Update Go version requirement to 1.26+
- Bump golangci-lint from v2.6.0 to v2.11.0 for Go 1.26 support
- Bump Go from 1.25.7 to 1.26.1 to fix stdlib vulnerabilities
- Address review comments: use actorDisplayName for Copilot author display
- Show friendly display names in gh issue view
- Add generic actorDisplayName for all actor display names
- Show friendly Copilot (AI) name in gh pr view
- fix: align example indentation with codebase convention
- fix: address review feedback for --exclude flag
- fix: share diffHeaderRegexp between changedFilesNames and extractFileName, fix gofmt
- feat(pr diff): add --exclude flag to filter files from diff output
- Fetch org teams via repository.owner inline fragment
- chore(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.2
- Exclude PR author from reviewer candidates in SuggestedReviewerActors
- Fix duplicate reviewers in gh pr edit by passing logins as defaults
- Exclude current user from suggested reviewers in gh pr create
- Replace @copilot with Copilot reviewer login in gh pr create
- Add TODO requestReviewsByLoginCleanup on GHES ID-based reviewer path
- Remove /slug team reviewer shorthand normalization
- Add TODO requestReviewsByLoginCleanup on static reviewer MultiSelect
- Check state.ActorReviewers in MetadataSurvey reviewer search gate
- Label Copilot detection in SuggestedReviewerActorsForRepo as a hack
- Add TODO requestReviewsByLoginCleanup in CreatePullRequest
- refactor: deduplicate scope error handling between api/client.go and project queries
- Fix extension install error message showing raw struct instead of owner/repo (#12836)
- chore(deps): bump github.com/docker/cli
- Remove StateReason feature detection for issue close
- Remove unnecessary StateReasonDuplicate feature detection
- docs: add examples to gh issue close help text (#12830)
- Fix incorrect integer conversion from int to uint16 in port forwarder (#12831)
- Combine issue feature detection into a single GraphQL query
- feat(browse): add blame flag
- Reword
--no-upstreamhelp doc - test(issue list): cover additional PR search qualifier variants
- fix(issue list): reject pull request-only search qualifiers
- chore(deps): bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0
- chore(deps): bump github.com/gabriel-vasile/mimetype
- chore(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.1
- chore(deps): bump actions/attest-build-provenance from 3.2.0 to 4.1.0
- chore(deps): bump actions/download-artifact from 7 to 8
- chore(deps): bump actions/upload-artifact from 6 to 7
- Set COPILOT_GH env var when launching Copilot CLI
- Simplify progress indicators in issue develop
- Emit null for zero createdAt/updatedAt values
- Address Copilot review feedback
- Polish --json support for agent-task view
- Polish --json support for agent-task list
- Fix gofmt alignment in view_test.go
- feat(pr): add changeType field to files JSON output
- Add --duplicate-of flag and duplicate reason to gh issue close
- Add --json support to
gh agent-task view - Add --json support to
gh agent-task list - fix(project/item-edit): preserve title/body when editing draft issue with partial flags
- Add databaseId to assignees GraphQL fragment
- fix(licenses): implement VCS-friendly embedding
- chore(gitignore): ignore generated license files
- Use pre-compiled regexp for matching Content-Type
- chore(script/licenses): fix indentation
- fix(script/licenses): generate licenses in separate dirs
- Fix invalid ANSI SGR escape code in JSON and diff colorization
- Add --no-upstream flag to gh repo clone
- Clarify ReviewerCandidate relationship to AssignableActor
- Move PR review queries from queries_pr.go to queries_pr_review.go
- Use org/slug format in test fixtures and remove /slug normalization
- Normalize /slug team shorthand to org/slug and fix docs
- Include bot logins in login-based reviewer mutation guard
- Skip reviewer metadata fetch when using search-based selection
- Update test assertions to expect org/slug team format
- Wire bot reviewer logins through CreatePullRequest
- Partition bot reviewers separately for RequestReviewsByLogin
- Preserve org/slug format for team reviewer slugs
- Apply suggestion from @BagToad
- Remove redundant comment
- Don't swallow error from FD
- Remove redundant comments
- Fix issue develop repeated invocation with named branches
- Fix redundant API call in gh issue view --comments (#12606)
- Add toGitHubV4Strings helper to reduce code duplication
- Address PR review comments
- gh pr create: CCR and multiselectwithsearch
- trigger rerun
- test: TestGenerateScopeErrorForGQL and TestRequiredScopesFromServerMessage
- fix: clarify scope error while creating issues for projects
- fix: error when --remote flag used with repo argument
- build: customizable install
prefix
-
Update to version 2.87.3:
- Fix project mutation query variable usage
-
Update to version 2.87.2:
- chore(deps): bump golang.org/x/crypto from 0.47.0 to 0.48.0
- fix(agent-task/capi): fix capi API version
- Remove debris licenses
-
Update to version 2.87.0:
- Bundle licenses at release time (#12625)
- Rename query for clarity
- Remove pointer comments
- Simplify error message
- Remove DTO concept
- Add
--queryflag toproject item-list(#12696) - Clarify --clobber flag deletes assets before re-uploading
- Add usage examples to gh gist edit command
- Remove feedback issue template
- Migrate PR triage workflows to shared workflows
- Rename triage workflow to triage-discussion-label
- Pass environment as input to shared triage workflow
- Add missing environment and label check to triage workflow
- Initial plan
- fix(workflow run): bail out on feature detection error
- refactor(featuredetection): remove temp in favour of early returns
- docs(workflow run): improve help docs
- docs(workflow run): add cleanup marker with explanation on future changes
- fix(workflow run): apply
url.PathEscapewhen compiling URL - refactor(workflow run): remove temp
out - Add missing TODO comments for featuredetection if-statements
- docs(featuredetection): fix typo in comment
- test(featuredetection): fix test case name
- test(workflow run): verify retrieval of workflow run details
- feat(workflow run): retrieve workflow run if supported by the API
- test(featuredetection): add tests for
ActionsFeatures - fix(featuredetection): add
ActionsFeaturesto detect workflow dispatch features - pin REST API version to 2022-11-28
- Migrate stale workflow to shared workflow
- Respect --exit-status with --log and --log-failed
- document fork default branch behavior
- Migrate issue triage workflows to shared workflows
- fork default branch only in pr create
- update third party licenses
- chore(deps): bump golang.org/x/crypto from 0.46.0 to 0.47.0
- Add manual dispatch to bump-go workflow
- bump go to 1.25.7
- update third party licenses
- chore(deps): bump golang.org/x/term from 0.38.0 to 0.39.0
- update third party licenses
- chore(deps): bump golang.org/x/text from 0.32.0 to 0.33.0
- Add toGitHubV4Strings helper to reduce code duplication
- Address PR review comments
- update third party licenses
- chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.4 to 2.13.7
- Update third party licenses
- chore(deps): bump github.com/theupdateframework/go-tuf/v2
- Update third-party licenses
- Clarify comment on reviewer API behavior
- Clarify assignee/reviewer fetching behavior
- Clarify EditableReviewers comment
- Clarify Copilot assignee comment
- Use unfiltered totalCount for reviewer 'more results' display
- Include name in reviewer display for existing review requests
- update Go 1.25.6
- Implement cascading quota for reviewer suggestions
- fix(pr edit): send empty slices to clear reviewers in replace mode
- Fix return proper slug only for ReviewerTeam
- Remove redundant comment
- chore: update licenses
- chore: bump
cli/oauthtov1.2.2 - Add CCR and reviewer MultiSelectWithSearch
- chore(deps): bump actions/attest-build-provenance from 3.1.0 to 3.2.0
- Remove outdated comment in SuggestedAssignableActors
- Apply suggestions from code review
- Remove outdated TODO comments in survey.go
- Remove redundant comment in editRun test
- Return total assignee count in SuggestedAssignableActors
- Add test for MultiSelectWithSearch error propagation
- Add test for legacy assignee flow on GHES
- Remove unused Viewer struct from SuggestedAssignableActors
- Add comments to assigneeSearchFunc for clarity
- Simplify variables map in SuggestedAssignableActors
- Simplify suggested assignable actors
- Fix linter and mock prompter signature
- Apply suggestions from code review
- Apply suggestions from code review
- Clarify TODO comment for reviewer search function
- Only support assignee searchfunc on GitHub.com
- Update edit tests
- Refactor MultiSelectWithSearch to use result struct
- Add comment describing logger
- Pass editable to assigneeSearchFunc and update metadata
- Add dynamic assignee search to PR edit flow
- MultiSelectWithSearch initial implementation
- prshared: named prompt interface parameters
- typo: dont to don't
- chore(deps): bump goreleaser/goreleaser-action from 6.0.0 to 6.4.0
- chore: update licenses
- chore(deps): bump github.com/sigstore/rekor from 1.4.3 to 1.5.0
- chore(deps): bump github.com/theupdateframework/go-tuf/v2
- chore: update licenses
- chore(deps): bump github.com/sigstore/sigstore from 1.10.0 to 1.10.4
- docs: lint source.md
- fix(pr/shared): improve
ParseFullReferenceerror message - Fix fmt.Errorf format argument in ParseFullReference
- chore(deps): bump actions/upload-artifact from 5 to 6
- chore(deps): bump actions/download-artifact from 6 to 7
-
Update to version 2.86.0:
- refactor: address review comments
- Update contributing guidelines for clarity
- test(copilot): fix windows asset URL
- fix(cache delete): add unit tests and expand help doc
- feat(cache delete): allow for delete all caches for a ref
- Fix OS name in test archive filename to 'win32'
- fix(copilot): replace
windowswithwin32to match asset names - fix(root): avoid command name collision when registering extensions
- chore(root): register
copilotcommand - feat: add
copilotcommand - refactor(run download): extract zip extraction func into a separate package
- fix: error when head and base refs are identical in pr create
-
Update to version 2.85.0:
- fix: simplify set-default remote parsing
- Handle repo argument before remote name
- chore: update licenses
- chore(deps): bump github.com/yuin/goldmark from 1.7.13 to 1.7.16
- chore: update licenses using
go-licenses@v2 - chore: install
go-licenses@v2in scripts - Update go-licenses for 1.25
- chore: update licenses
- chore: bump
github.com/sigstore/sigstore-gotov1.1.4 - chore: remove redundant comment
- ci: enable noop linters
- Add shell specification for temporary tag creation
- ci: shorten
runblock - ci: improve step name
- ci: tag per build job
- Update Azure Code Signing endpoint URL
- Update Azure Code Signing client to 1.0.95
- Update actions/checkout to v6 in extension workflow templates
- feat: allow git remote names in gh repo set-default
- Add test to ensure null values are skipped
- ci: disable create storage record for artifacts
- chore(deps): bump actions/attest-build-provenance from 3.0.0 to 3.1.0
- chore: run
go mod tidy - chore: update licenses
- chore: upgrade
github.com/cli/oauthtov1.2.1 - fix: prevent panic when processing null project items
- ci: fix binary artficat dirs used in macos job
- ci: fix binary artifact dir paths used in Windows job
- ci: upgrade to GoReleaser v2 CLI syntax for
--skip - ci: limit deb/rpm packages to
linuxbuild - ci: replace
archives.formatwitharchives.formatsarray - ci: remove redundant
archives.rlcp - ci: replace
archives.buildswitharchives.ids - ci: quote 386 arch
- ci: upgrade
.goreleaser.ymlto v2 - ci: upgrade to GoReleaser v2
- chore: update licenses
- chore(deps): bump golang.org/x/crypto from 0.45.0 to 0.46.0
- chore: update licenses
- chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.2 to 2.13.4
- chore(deps): bump golangci/golangci-lint-action from 9.1.0 to 9.2.0
- chore: update licenses
- chore: update licenses
- chore(deps): bump github.com/spf13/cobra from 1.10.1 to 1.10.2
- chore: update licenses
- chore(deps): bump golang.org/x/term from 0.37.0 to 0.38.0
- chore: update licenses
- chore(deps): bump golang.org/x/text from 0.31.0 to 0.32.0
- chore: update licenses
- chore(deps): bump golang.org/x/sync from 0.18.0 to 0.19.0
- Fix Debian CLI package link in installation guide
- Add tests of browse --actions
- Add gh browse --actions flag
- chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.1 to 2.13.2
-
Update to version 2.83.2:
- Update licences
- Bump dev-tunnels SDK 0.1.13 to 0.1.19
- Bump Go to 1.25.5
- Update licenses for go-containerregistry-0.20.7 bump
- chore(deps): bump github.com/google/go-containerregistry
- Update licenses for go-version-1.8.0 bump
- chore(deps): bump github.com/hashicorp/go-version from 1.7.0 to 1.8.0
- Update licenses for tcell-2.13.1 bump
- chore(deps): bump github.com/gdamore/tcell/v2 from 2.9.0 to 2.13.1
- chore: make licenses
- refactor: drop multierror in favor of std
- Bump Go to 1.25.4
- Update licenses for huh 0.8.0 bump
- Fix accessible prompter tests with huh 0.8.0 upgrade
- chore(deps): bump github.com/charmbracelet/huh from 0.7.0 to 0.8.0
- Update licenses with grpc-1.76.0 bump
- chore(deps): bump google.golang.org/grpc from 1.75.0 to 1.76.0
- Update licenses for mimetype 1.4.11 bump
- chore(deps): bump github.com/gabriel-vasile/mimetype
- chore(deps): bump github.com/theupdateframework/go-tuf/v2
- chore(deps): bump golangci/golangci-lint-action from 9.0.0 to 9.1.0
- Update licenses for protobuf 1.36.10 bump
- chore(deps): bump google.golang.org/protobuf from 1.36.9 to 1.36.10
- Error if go-licenses is not on the PATH
- chore(deps): bump actions/checkout from 5 to 6
- Update licenses for crypto-0.45.0 bump
- chore(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0
- Alphabetize Ubuntu section
- Add Debian/Ubuntu to unofficial packages
- Add PGP key rotation PoC (#12176)
- refactor(pkg/search): rename
KeywordsVerbatimtoImmutableKeywords - refactor(pkg/search): rewrite returns in a more verbose way
- fix(pr/shared): delegate query compilation to
searchpackage - test(pkg/search): assert verbatim keywords are respected
- fix(pkg/search): add
KeywordsVerbatimfield toQuerytype - Remove extra flag default from help usage
- Refactor cfg out of CAPI Client
-
Update to version 2.83.1:
- chore(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.0.0
- Check user and teams nil state instead of length
- Update third-party licenses and dependencies
- Ensure empty arrays for reviewers in PR API calls
- Update .github/workflows/lint.yml
- Annotate go-licenses install with version tag
- Integrate license checks back into lint workflow
-
Bump go from 1.24 to 1.25
-
Update to version 2.83.0:
- chore(deps): bump github.com/cli/go-gh/v2 from 2.12.2 to 2.13.0
- Apply suggestions from code review
- Add note on govulncheck source mode for Go 1.25
- docs(pkg/search): fix typo
- docs(repo garden): improve func godoc
- fix: ignore
nilerron intentionally swallowed error - fix: resolve
nilerrissues - fix: resolve
copyloopvarissues - fix: resolve
gocriticissue - test(pkg/httpmock): ignore
bodycloseon mock response value - refactor(repo garden): return pagination link instead of resp
- fix: close resp body (bodyclose)
- refactor: remove returned resp from
api.EndpointNeedsScopes - refactor(pkg/search): remove passing resp for pagination
- ci: enable basic linters
- Update lint govulncheck to use source mode
- chore: add
workflow_dispatchto govulncheck triggers - Add example for --custom-agent usage
- Update error messages in job creation tests
- Update pkg/cmd/agent-task/capi/job.go
- Add shorthand flag for custom-agent option
- Fix: do not swallow job creation error
- Clarify custom agent flag description
- Add custom agent support to job creation
- docs(release list): fix typo
- docs(release list): reword comment
- feat(release list): add
isImmutableJSON field - fix(featuredetection): add
ReleaseFeaturesmethod - docs(api): add example for
--inputoption - docs(api): mention use of
@<path>and@-for--field - docs: update go version 1.25
- refactor: replace backport with
strings.CutSuffix - chore: exclude
third-partyfrom Golangci-lint formatting paths - chore: bump Go in devcontainer
- chore: apply
go fixto remove deprecated// +buildtags - fix: --interval flags docs in gh pr checks
- test(gist/edit): add tests for single file edit and interactive multi-file selection
- Update Go toolchain version to 1.24.9
- docs(run list): mention
pr checksin help docs - ci: bump Golangci-lint to v2.6.0
- chore(deps): bump golang.org/x/crypto from 0.42.0 to 0.43.0
- chore(deps): bump golang.org/x/text from 0.29.0 to 0.30.0
- test(gist): fix failing tests
- fix(gist): prevent fetching full content for already edited files
- fix(gist): only include files that have changed in request
- fix(gist): fetch full content for truncated files during editing
- ✅ (repo delete) remove comprehensive assertions on check stderr output
- Fix typo in comment for gh issue develop branch checkout command
- 💡 (gh repo delete) Add warning when
--yesis ignored without a repository, Closes: #12033 - chore(deps): bump github.com/rivo/tview
- chore(deps): bump actions/download-artifact from 5 to 6
- chore(deps): bump actions/upload-artifact from 4 to 5
- Remove skipped tests
- Make verifier choice more explicit
- Return only basic pull request info when reverting a PR
- chore(deps): bump mislav/bump-homebrew-formula-action from 3.4 to 3.6
- chore(deps): bump goreleaser/goreleaser-action from 6.3.0 to 6.4.0
- test fixup
- Update release verify commands to use sentinel value
- Initial plan
- Make PGI verifier initialization non-fatal to allow GitHub attestation verification
- Initial plan
- improve docstring for release-create
- Bump Go to 1.25.3
- Address remaining PR comments for revert implementation
- Adjust PR revert based on new acceptance criteria
- Return nil when err is nil
- Fix revert unit tests by using renamed helper
- feat: include revert PR info in message output
- Undo autoformat changes
- feat: implement
pr revert - test(gist): add tests for handling truncated files in view command
- test(gist): add tests for editing truncated gist files
- test(gist): add tests for
GetRawGistFilefunction - feat(gist): retrieve full content for truncated gist files
- feat(gist): retrieve full content for truncated gist files
- feat(gist): add
GetRawGistFilefunction to retrieve raw gist content - feat(gist): add
RawURLandTruncatedfields toGistFile
-
Update to version 2.82.1:
- Add test for non-interactive projects v1 unsupported
- Inject Detector mock in edit command tests
- Pass ProjectsV1Support to FetchOptions functions
- chore(deps): bump github.com/gabriel-vasile/mimetype
- Update .github/workflows/govulncheck.yml
- chore(deps): bump github/codeql-action from 3 to 4
- chore(deps): Bump github.com/sigstore/sigstore-go from 1.1.0 to 1.1.3
- chore(deps): bump actions/attest-build-provenance from 2.4.0 to 3.0.0
-
Update to version 2.82.0:
- chore: run
go mod tidy - refactor(auth refresh): use
PlainHttpClientinstead of zerohttp.Client - refactor(auth login): use
PlainHttpClientfor OAuth flow - refactor(authflow): receive HTTP client via args
- fix(factory): add
PlainHttpClientto factory - test(api): assert
SkipDefaultHeadersis honoured - fix(api): expose
SkipDefaultHeadersoption - test(api): improve
NewHTTPClienttest assertions - Fix agentTaskCmd to use repoResolvingCmdFactory
- Add new displaying message to test expectation
- Fix --follow not killing the progress indicator
- Apply suggestion from @babakks
- Apply suggestion from @babakks
- Fix argument order in httpStubs test functions
- docs(cache delete): remove redundant comment
- docs(cache delete): add godoc for
deleteCacheByKey - Remove default empty slices in RemovePullRequestReviews
- Fix typo in error message for required flags
- Refactor reviewer partitioning in PR edit command
- Escape repo owner and name in PR reviewer API paths
- Remove unused ghIds function and githubv4 import
- fix(cache): report correct deleted count for key and key+ref deletions
- Refactor PR reviewer editing to use REST API and optimize team fetch
- chore: run
-
Update to version 2.81.0:
- test(auth status): correctly replace JSON-escaped paths
- update the description
- refactor: use strings.FieldsFuncSeq to reduce memory allocations
- fix(pr checkout): add alias
co - remove hidden value for release verify cmd
- fix latest tag for relase verify asset
- docs(auth status): explain
--jsonwill always exit with zero - fix(auth status): return JSON entries under
hosts - fixup! examples
- fix error missing in json output
- examples
- remove showToken from authEntry
- address copilot comment on parameter order
- add examples
- simplify exporter usage
- remove includeScope
- do not mutate opts.ShowToken
- move displayToken to String method
- move flag validation to RunE
- refactor without VisitAll
- introduce AddJSONFlagsWithoutShorthand
- fix show token when using json
- fix exit code
- revert showToken change
- mutually exclusive flags
- flag duplicate check
- add ExpectCommandToSupportJSONFields
- do not export authState
- handle -t conflict
- do not fetch scope if not necessary
- json flags
- auth state enum
- Refactor entry to a single type
- Fix missing assertions
-
Packaging improvements:
- Update to BuildRequires: golang(API) >= 1.24 matching go.mod
-
Update to version 2.80.0:
- chore: update third-party licenses
- ci: pin release runner to Windows 2022
- Add math package import to sessions.go
- Add TODO for better integer handling in GetPullRequestDatabaseID
- chore: update third-party licenses
- update the test
- Update pkg/cmd/attestation/api/client.go
- add initiator_type for attestations
- fix(agent-task/capi): return proper error message when resp is not a JSON
- test(agent-task view): populate
Session.Namein all test cases - fix(agent-task view): improve session overview
- refactor(agent-task view): merge empty println calls with next
- fix(agent-task view): re-fetch session to get all pieces of data
- fix(agent-task/capi): remove fallback to viewer when user id is zero
- test(agent-tassk/capi): update
ListSessionsByResourceIDtests - docs(agent-task/capi): add TODO note for dropping local ID generation
- fix(agent-task/capi): fetch viewer when resource session user id is zero
- fix(agent-task/capi): handle unpopulated resource session
LastUpdatedAt - refactor(agent-task/capi): keep
resourceprivate - update agents resource route
- fix(agent-task view): improve session error
- fix(agent-task view): display session error
- fix(agent-task/capi): add
WorkflowRunIDfield toSession - refactor(agent-task/capi): remove unused slice
- fix(agent-task/capi): add
Errorfield toSession - fix(agent-task create): block empty problem statement arg
- fix(agent-task create): use pager when following logs
- fix(agent-task create): avoid prompting when problem statement is provided
- fix(agent-task list): show capitalised session state
- fix(agent-task/shared): fix session state value
- docs(agent-task list): add "(preview)" note to cmd docs
- chore(agent-task/shared): regenerate
LogRenderermock - test(agent-task/capi): assert session with zero resource ID are kept
- fix(agent-task/capi): keep sessions with no resource attached
- refactor(agent-task list): remove unused
BaseRepofromListOptions - docs(agent-task/capi): fix test case explanation
- Fix session deduplication and add test for paging
- Remove repo-scoped session listing and related code
- docs(agent-task): use
heredoc.Doc - docs(pr/shared): add a
TODOon decoupling PR finder from IO - fix(agent-task view): display zero premium requests
- fix(agent-task/shared): make capitalised status names consistent
- Update pkg/cmd/agent-task/agent_task.go
- Update pkg/cmd/agent-task/agent_task.go
- Enhance agent-task command help and usage info
- Refactor comments in stripDiffFormat function
- Remove obsolete log-3 test data files
- fix(agent-task view): omit session overview in log mode
- fix(agent-task view): display premium requests used
- fix(agent-task/capi): add
PremiumRequestsfield toSession - fix(agent-task view): display session duration
- fix(agent-task view): display completed sessions as "Ready for review"
- fix(agent-task view): disable PR finder progress indicator
- test(pr/shared): assert
FindOptions.DisableProgressis respected - fix(pr/shared): add
DisableProgressfield toFindOptions - Refactor stripDiffFormat guard clause logic
- Use filepath.Ext to detect file extension in markdown renderer
- Improve log rendering error handling and test coverage
- Prefix rendered shell commands with '$ ' in logs
- Clarify comment on CRLF normalization in tests
- Refactor generic tool call titles map to package scope
- Add pager support to log output in printLogs
- test(agent-task create): add test for
--follow - docs(agent-task create): add example for
--followflag - feat(agent-task create): add
--followflag - refactor(agent-task create): extract session URL polling into a func
- Add TODO for bash-related tool call details
- Update comment for reasoning text formatting
- Enable Bash session tool handling in log rendering
- Rename testdata log files for clarity
- Normalize line endings in log testdata files too
- Fix line ending conversion in tests
- Add note for updating testdata files in log tests
- Make log tests OS-agnostic by normalizing line endings
- Fix comment for GetSessionLogs method
- Add and improve function documentation in log.go
- Update log test expectation files
- Rename renderToolCall to renderToolCallTitle
- Rename relativePath to relativeFilePath in log rendering
- Refactor markdown rendering helper function names
- Improve log rendering and tool call handling
- Refactor JSON content rendering in log entries
- Various log rendering improvements
- feat(agent-task view): add
--logand--followflags - feat(agent-task view): add
--logand--followflags - fix(agent-task/shared): add log renderer
- feat(agent-task/capi): add
GetSessionLogsmethod - Add error type assertion to createRun tests
- Add test for non-interactive problem statement input
- Update test to use edited task description
- Remove unused stdin field from create command tests
- Refactor create command tests and add base branch case
- refactor(pr/shared): rename
resttotail - refactor(agent-task/shared): enhance symbol names
- Update command examples for agent-task create
- Refactor agent-task create to improve file input handling
- fix(pr/shared): ensure
ParseURLregexp is backward-compatible - refactor(agent-task/shared): extract uuid pattern
- refactor(agent-task view): rename
resourceIDtoprID - feat(agent-task view): support PR
/agent-sessions/*URL as argument - fix(agent-task/shared): add
ParsePullRequestAgentSessionURL - fix(pr/shared): add rest return value to
ParseURL - docs(agent-task view): improve
--helpdocs - refactor(agent-task create): assign
Configat instantiation - fix(agent-task create): only prompt for problem statement if not provided
- fix(agent-task view): stop progress indicator before opening browser
- test(agent-task view): enhance naming and stubs
- test(agent-task view): add
--webmode tests - feat(agent-task view): add
--webmode - refactor: move Copilot Agents home URL to capi
- fix(agent-task/capi): also return PR URL from
GetPullRequestDatabaseID - Still prompt for task desc with -F
- Add interactive prompt for task description in agent-task create
- Fix default value in session selection prompt
- Show session name instead of ID in agent-task list
- docs(agent-task view): explain test case rationale
- docs(agent-task view): explain when condition is met
- docs(agent-task/capi): remove redundant comment
- test(agent-task/capi): fix test case args
- fix(agent-task/capi): skip unpopulated resource ID when hydrating
- docs(agent-task/shared): add godoc to
SessionStateString - test(agent-task view): update tests
- fix(agent-task view): use lower limit for fetching sessions
- fix(agent-task view): use
CapiClient.GetPullRequestDatabaseID - fix(agent-task/capi): add
GetPullRequestDatabaseIDtoCapiClientinterface - test(agent-task/capi): add tests for
GetPullRequestDatabaseID - feat(agent-task/capi): add
GetPullRequestDatabaseIDmethod - test(agent-task/capi): add tests for
GetSessionByResourceID - feat(agent-task view): support PR arg
- fix(agent-task/shared): add
SessionSymbolfunc - test(agent-task/shared): add test for
IsSessionID - fix(agent-task/shared): add
IsSessionID - test(pr/shared): add test for
ParseFullReference - fix(pr/shared): add
ParseFullReferencefunc - feat(agent-task/capi): add
ListSessionsByResourceIDmethod toCapiClientinterface - feat(agent-task/capi): add
ListSessionsByResourceID - test(agent-task view): add tests for the
viewcommand - feat(agent-task view): add
viewcommand - test(agent-task list): remove unused
stubs - feat(agent-task/capi): add
GetSessionmethod toCapiClientinterface - test(agent-task/capi): add tests for
GetSession - feat(agent-task/capi): add
GetSessionmethod - refactor(agent-task/capi): populate PRs
IsDraft - refactor(agent-task/capi): hydrate user data
- test(agent-task create): quote file paths to pass CI on Windows
- refactor(agent-task list): simplify cmd initialisation
- refactor(agent-task create): remove redundant
if - test(agent-task create): use
CapiClientMock - fix(agent-task create): simplify command initialisation
- test(agent-task list): update
TestNewCmdCreate - fix(agent-task create): allow no positional arg
- test(agent-task list): apply test args anyway
- test(agent-task list): use
CapiClientMock - test(agent-task list): update
TestNewCmdList - refactor(agent-task/capi): drop embedding of unexported struct
- test(agent-task/capi): add
CapiClientMock - test(agent-task/capi): add
go:generatedirective to gen mock - test(agent-task/capi): add tests for job-related methods
- test(agent-task/capi): add tests for session-related methods
- fix(agent-task/capi): handle non-JSON error response
- fix(agent-task/capi): improve returned errs
- refactor(agent-task/capi): improve pagination
- refactor(agent-task list): use shared
CapiClientFunc - fix(agent-task/shared): add
CapiClientFunchelper - Improve agent-task create command help text
- Refactor test case struct in create_test.go
- Add base branch option to agent task creation
- Support reading task description from stdin
- Increase backoff timing for agent task creation
- Add file input support to agent-task create command
- Update error messages and test repo handling in agent-task create
- Simplify error handling in CreateJob response
- Simplify stdout assertion in createRun test
- Improve job error handling and update tests
- Use Job struct in request
- Escape URL path parameters in GetJob request
- Escape owner and repo in job creation URL
- Escape URL path segments in agent session links
- Remove nil check for job in agentSessionWebURL
- Update test to expect 500 error response
- Update error message in createRun test
- Remove redundant 'error:' prefix from repo error
- Update command usage for agent task creation
- Update agent-task create command argument handling
- Add agent task creation command and job API
- Add pager support to agent-task list output
- Replace panic with require.FailNow in test
- Add test for web mode with repo flag in listRun
- Add comment on web dashboard filtering limitation
- Add test case for negative limit in list command
- Return NoResultsError when no agent tasks found
- Add comment explaining error handling in listRun
- Simplify time calculation in listRun test
- Simplify BaseRepo assignment in list command
- Handle repo resolution errors gracefully in agent-task list
- Add --web flag to agent-task list command
- Show default limit in agent-task list flag help
- Add limit flag to agent-task list command
- Add repo-scoped agent session listing support
- Refactor session state color logic to shared package
- Optimize session pull request hydration logic
- Refactor error handling in generatePullRequestNodeID
- Update API query name for session PR fetch
- Refactor variable names in ListSessionsForViewer
- Remove commented-out fields from sessionPullRequest
- Refactor agent-task list command client initialization
- Refactor session filtering in listRun function
- Fix import alias for shared package in agent-task list
- Add agent task listing command and CAPI client
- Refactor agent task tests into table-driven format
- Refactor test to use require.Empty assertion
- Show help on agent-task command execution
- Add agent-task command with OAuth token validation
-
Update to version 2.79.0:
- fix(featuredetection): remove redundant
AdvancedIssueSearchWebInIssuesTabfield - docs(featuredetection): remove unknown dates
- docs(search prs): mention advanced issue search syntax support
- docs(search issues): mention advanced issue search syntax support
- docs(pr list): mention advanced issue search syntax support
- docs(issue list): mention advanced issue search syntax support
- refactor(search): rename
Query.StringtoStandardSearchString - test(search): improve test cases
- chore(deps): bump actions/stale from 9 to 10
- chore(deps): bump actions/setup-go from 5 to 6
- Bump sigstore/rekor to v1.4.1
- Remove mention of public preview in trustedroot.go
- docs(featuredetection): add godoc for min GHES version for advanced issue search
- docs(issue pr): fix incorrect formatting
- docs(issue list): fix incorrect formatting
- docs: add cleanup/future TODO marks for advanced issue search changes
- docs(pr list): explain use of advanced issue search syntax
- docs(issue list): explain use of advanced issue search syntax
- test(issue/pr list): assert integration with advanced issue search
- test(pr shared): assert
ListURLWithQueryworks with advanced search syntax - refactor(issue/pr list): support advanced issue search
- docs(search): improve
Searcher.URLmethod docs - docs(search prs): mention advanced issue search takeover
- docs(search issues): mention advanced issue search takeover
- docs(search): improve docs for
Query.StringandQuery.AdvancedIssueSearchStringmethods - refactor(search): improve special qualifier grouping
- test(search): test advanced search support
- fix(search): use advanced issue search when available
- refactor: improve mock feature detector names
- refactor(search): sort qualifiers in query
- test(search): provide feature detection dependency
- fix(search): add feature detection dependency
- test(search): explain why
is:andin:qualifiers used in test case - fix(search): sort qualifiers in advacned issue search syntax
- test(search): add tests for
AdvancedIssueSearchStringmethod - fix(search): add
AdvancedIssueSearchStringmethod - test(featuredetection): add tests for advanced issue search detection
- fix(featuredetection): add feature detection for advanced issue search
- test(cache delete): combine test cases for invalid/non-existent refs
- test(cache delete): replace
HTTP 204with200to match API behaviour - docs(cache delete): explain different API responses
- test(cache delete): add test case for key arg and
--all - refactor(cache delete): simplify error handling
- refactor(cache delete): simplify condition
- fix(cache): validate
--refflag usage with cache ID - fix(cache): prevent using
--refflag with cache ID - refactor(cache): extract cache ID parsing logic
- fix(cache): update error message for missing cache key with
--refflag - chore(cache): improve help text for
--refflag in cache deletion - test(cache): add tests for
--refflag in cache deletion - feat(cache): add support for
--refflag in cache deletion - refactor: use slices.Equal to simplify code (#11364)
- feat:
gh authAutomatically copy one-time OAuth code to clipboard (#11518) - docs(release create): difference
--generate-notesand--notes-from-tag(#11534)
- fix(featuredetection): remove redundant
-
Update to version 2.78.0:
- Add
--forceflag togh run cancel(#11513) - Update third-party license versions (#11557)
- chore(deps): bump github.com/go-viper/mapstructure/v2 (#11556)
- Merge pull request #11536 from cli/copilot/fix-11535
- chore(deps): bump github.com/cli/go-gh/v2 from 2.12.1 to 2.12.2
- Update pkg/cmd/release/verify/verify.go
- Update pkg/cmd/release/verify-asset/verify_asset.go
- Hidden trusted root flag for release verify
- Update Go dependencies to latest versions
- chore(deps): bump actions/checkout from 4 to 5
- udpate the test
- replace /git/refs/tags/ to /git/ref/tags/
- Update feature_detection.go
- Update PR tests for v2 projects
- Base changes for PR project items
- Update
gh issue viewto show v2 projects - PR feedback from @bagtoad
- Update v1 project detection logic
- Update govulncheck workflow to scan source code
- add test for FetchRefSHA
- Apply suggestion from @Copilot
- Update docs/install_windows.md
- Consolidate repo profile, fix headings
- chore(deps): bump google.golang.org/grpc from 1.73.0 to 1.74.2
- chore(deps): bump github.com/yuin/goldmark from 1.7.12 to 1.7.13
- Update docs on contributing new install methods
- markdown lint fixes
- Formatting
- Initial installation doc refactor
- Pushing empty commit to run CI
- Bump Go to 1.24.6
- Fix linter
- Update pkg/cmd/search/search.go
- chore(deps): bump actions/download-artifact from 4 to 5
- Update docs/triage.md
- Update docs/triage.md
- Update issue triage guidelines and label usage
- fix error for ErrReleaseNotFound when fetching ref
- Apply suggestion from @Copilot
- Update .github/workflows/scripts/spam-detection/process-issue.sh
- docs(search): move search syntax note to
gh search --help - Update spam detection to comment on and close issue
- Update permissions and events for workflow
- ci: use
help wantedlabel link in comment - ci: anchor regexp for
help wantedlabel - Improve spam detection evals (#11419)
- v1 project feature detection spike using version
- docs(help): rename
search-syntaxhelp topic - docs(search): add reference to
gh help search - Add help topic for search syntax in gh commands
- docs(search): add note for exclusion search syntax
- Regenerate third-party licenses on trunk pushes
- chore(deps): bump github.com/spf13/pflag from 1.0.6 to 1.0.7
- Add
-
Update to version 2.76.2:
- Refactor tab completion test
- Test
gh pr create --reviewertab completion - Include org teams for PR reviewers
- docs(ci): delete obsolete comment
-
Update to version 2.76.1:
- Updated third-party license compliance content
- Add tests for reviewer team handling in PR creation
- Refactor and improve RepoMetadata teams test
- Refactor error assertion in Test_RepoMetadataTeams
- FIX: conditionally fetching team reviewers
- Add TeamReviewers flag to RepoMetadataInput
- Update .github/workflows/scripts/spam-detection/generate-sys-prompt.sh
- Use gh go templating for user prompt
- Update eval script comments
- Remove unnecessary file for heredoc
- First pass to optimize and improve
- Limit permissions of govulncheck workflow
- Incorporate govulncheck into workflows
- update ownership of pkg/cmd/release/shared/
- Run Lint and Tests on
pushtotrunkbranch - ci: echo spam detection result
- ci: add
models: readpermission - ci: correct
sedusage to remove Markdown front matter - docs: fix typo in script docs
- ci: fix potentially confusing typo in system prompt
- ci: use
issue.html_urlinstead ofissue.url - ci: remove unused env vars
- ci: add spam issue detection workflow
- ci: add spam issue detection scripts
- chore(deps): bump github.com/sigstore/sigstore-go from 1.0.0 to 1.1.0
- chore(deps): bump advanced-security/filter-sarif from 1.0.0 to 1.0.1
- Improve
api--previewdocs - add tenancy aware for san matcher
-
Update to version 2.76.0:
- Copilot Pro+ / Enterprise subscribers can now assign issues to Copilot during issue creation
- Display immutable field in release view command
- Do not fetch logs for skipped jobs
- Transform extension and filename qualifiers into path qualifier for web code search
-
Update to version 2.75.0:
- Quote Windows rsyso script global hook
- test(search): verify
URLreturns quoted query - test(search): test pagination with multi-word quoted queries
- fix(search): fix mutating query state fields
- Add setup-go to bump-go
- Update contribution design link
- test(pr merge): always assert stderr
- test(pr merge): verify
deleteRemoteBranchbehaviour when API returns error - fix(pr merge): ignore 404 as error when deleting remote branch
- Ensure go mod tidy is run in bump-go
- Inject token into bump-go workflow
- Reformat gh run view help
- docs(run view): explain restrictions of fallback API calls
- test(run view): delete unused ZIP archive
- refactor(run view): remove
Logfield from DTO types - test(run view): update tests
- refactor(run view): use API as fallback to fetch job logs
- test: add
BinaryResponsehelper function - Ensure bump go script has git user configured
- Support --no-repos-selected on secret set
- docs: consistently use apt in installation instructions
- Consume dependabot minor versions for go modules
- test: add test for
ParseURL - Update microsoft dev-tunnels to v0.1.13
- Bump all dependencies except dev-tunnels
- Fix inconsistent use of tabs and spaces
- docs: explain PR URL parsing reason
- test: improve test case to highlight host name override
- test: remove references to
AssignedActorsUsedfield - test: verify providing a URL arg affects the base repo
- refactor: select PR fields based on detected features
- test: remove tests verifying assigne-related behaviour
- fix: remove assignee-related intervention
- fix: remove
AssignedActorsUsedfield - Add workflow to automate go version bumping
- fix: expose
ParseURLas a public func - Remove unused GH_TOKEN env variable from workflow
- Add
workflow_dispatchsupport to PR Help Wanted check (#11179) - chore: improve error message when
versioninfo.jsonis not found - Fix:
gh pr createprioritize--titleand--bodyover--fillwhen--webis present (#10547) - chore: create
.sysolibs only on Windows - chore: delete
script/winres.json - chore: add
versioninfo.template.json - refactor: switch to
github.com/josephspurrier/goversioninfo - chore: exclude generated
.sysofiles from git repo - Ensure automation uses pinned go-licenses version
- Fix missing newline in install_linux.md
- Apply suggestions from code review
- Update missed Go 1.23 references
- chore: update Go version to 1.24 in devcontainer configuration
- Use
makefor license generation and checks - Use temp directory for license checks
- Update 3rd party licenses
- Restored original test setup, clarified
- Enhance Activetoken prioritize test
- improve the description for gh release verify cmd
- chore: fix function name
- Push up
- Use active token stubbing on auth config
- refactor to simplify implementation
- Primer formatting
- Fix spacing
- Add missing files
- Rename READMEs
- Initial restore of Primer CLI docs
- use standardize color roles logic for the logging
- moved to shared lib
- moved to shared lib
- update the artifact and bundle for testing
- empty commit
- clean the code
- revert the workflow
- debug windows env
- debug windows env
- debug windows env
- chore: fix variable name casing
- Avoid analyzing 3rd party license content with CodeQL
- chore: ensure output path is a directory
- clean the path
- clean the path
- Update 3rd party license information
- Adopt license compliance scripts into workflows, docs
- clean the path
- improve test
- fix test
- add unit test
- chore: prepare Windows resources
.sysofiles before build - chore: add script to create Windows resources
- Cleanup
- fix: get token for active user instead of blank if possible
- remove filepath test
- update Sprintf
- removed unused file
- added the unit test
- add json format
- change verify-asset logic
- minor fix
- clean up the code
- update the lng
- wip
- remove comment
- wip
- init
- docs: install_linux.md: add Solus linux install instructions
-
Update to version 2.74.2:
- Update docs/install_linux.md
- Fix step order for CodeQL workflow
- docs: update install command for Debian
- chore(deps): bump github.com/google/go-containerregistry
- Use t.Chdir in tests
- Bump to Go 1.24
- Merge pull request #11121 from cli/11101-use-golangci-lint-version-2
- Apply suggestion from @Copilot
- Improve help wanted check skipping logic
- Ensure gh executes in workflow check script
- Fix repo checkout in help-wanted check
- Fixes #11126
- Fix script path for help-wanted check
- Quote filenames suggested at the end of worklow run
- chore(deps): bump github.com/in-toto/attestation from 1.1.1 to 1.1.2
- Quote workflow conditional
- Add workflow to check
help wantedlabelling (#11105) - chore(deps): bump actions/attest-build-provenance from 2.3.0 to 2.4.0
- Add accurate context when
run rerunfails (#10774) - Avoid requesting PR reviewer twice
- chore(deps): bump github.com/sigstore/protobuf-specs from 0.4.2 to 0.4.3
- chore(deps): bump mislav/bump-homebrew-formula-action from 3.2 to 3.4
- test(pr): Add tests for actor assignees
- Fix test, remove partial standalone test
- Iterate on
pr editproblems with existing assignees - chore(deps): bump google.golang.org/grpc from 1.72.0 to 1.72.2
- Fix expected error output of TestRepo/repo-rename-transfer-ownership
- Add instructions for MidnightBSD installation
-
Update to version 2.74.1:
- test: fix test data const
- Document support for
@copilotingh [pr|issue] edit --add-assigneeand--remove-assignee(#11056) - Fix pr edit when URL is provided
-
Update to version 2.74.0:
- Update
go-ghto v2.12.1 - fixup release asset digest tests
- remove nolint comment for release header
- Update pkg/cmd/release/view/view.go
- chore(deps): bump github.com/sigstore/protobuf-specs from 0.4.1 to 0.4.2
- chore(deps): bump github.com/yuin/goldmark from 1.7.8 to 1.7.12
- fix:
gh gist editpanic when no file in a gist (#10627) - docs(pr list): mention
--headdoes not support<owner>:<branch>syntax - add Digest to ReleaseAsset struct
- doc(update): improve comments on updaterEnabled
- Refactor build tag logic
- replace deprecated func
- replace deprecated type
- update sigstore-go to v1
- feat(update): add
updateablebuild tag for update notifications - Update README.md
- test(run): add tests for
RenderJobsandRenderJobsCompact - Add
--compactflag torun watch(#10629) - test: improve test case naming
- chore: run
go mod tidy - test: ensure proper usage of pipes in docs
- Revert "[gh config] Escape pipe symbol in Long desc for website manual"
- doc(pr): format allowed values and defaults in help
- Mention created PR's URL will be printed upon success
- Add example usage of
--headoption - doc(preview): add long description
- fix(prompter): print to iostreams stdout
- fix(prompter): update prompter create for changes in trunk
- fix(preview): remove needless newlines
- import sigstore-go at a more recent commit
- use constructor
- include http client in verifier setup
- add missing http client field in sigstoreConfig
- simplify test
- alphabetize fields
- move live inspect test to integration test file
- fetch http client from factory
- set custom fetcher in options
- pass http client for use with tuf
- get the latest go-tuf release
- get latest go-tuf version
- create fetcher with custom http client and retry options
- chore(deps): bump github.com/gabriel-vasile/mimetype from 1.4.8 to 1.4.9
- feat(preview): enforce fixed order for prompts
- feat(preview): add
preview promptercommand
- Update
-
Fixing boo#1237669 - CVE-2025-27144 - Go JOSE's Parsing Vulnerable to Denial of Service
-
Do not skip the TestAccessiblePrompter tests
-
Update to version 2.73.0:
- refactor(api): inline struct definitions in RepoAssignableActors
- refactor(api): change CopilotActorLogin to constant
- fix(editable): include DefaultLogins in EditableAssignees clone
- doc(params): incorrect func name in comment
- refactor(api): use constant for Copilot login
- doc(issue/pr edit): clarify @copilot usage
- doc(issue/pr edit): doc
@copilotassignee - test(params): enhance Copilot replacer tests for edge cases
- fix(params): remove needless err return
- doc(editable): remove needless comment
- test(editable): prompts use assignee display names
- fix(pr edit): clarify error messages for assignee actors and users
- doc(pr edit): condense comment for reviewer/user filtering
- test(pr edit): fix typo in test name
- refactor(pr edit): move httpclient initialization
- feat(issue/pr edit): support @copilot in assignee flags
- doc(pr edit): Add comments describing the use of DefaultLogins
- fix(issues): fix non-interactive assignee matching to logins&IDs
- fix(pr edit): remove merge conflict artifact, extra detector
- feat(pr edit): fetch assignable actors
- feat(pr edit): fetch assigned actors
- fix(api): correct var name capitalization
- refactor(api): remove needless parenthesis
- fix(api): correct var name capitalization
- refactor(api): remove needless parenthesis
- doc(api): code comment typo
- feat(editable): update assigned actors to use display names
- feat(pr edit): fetch assignable actors
- feat(pr edit): fetch assigned actors
- doc(issue edit): clarify synchronous handling of assignees
- feat(issue edit): replacing actor assignee is done synchronously with updateIssue
- doc(api): remove needless comment
- refactor(api): rename assignable user types and methods
- fix(issue edit): revert rename of ActorAssignees
- fix(issue edit): use double quotes for assignedActors
- refactor(issue edit): add assignedActors to lookupFields
- refactor(issue edit): rename loop variable for clarity
- refactor(issue edit): rename AssignedActors to ActorAssignees
- Increase
beforePasswordSendTimeoutto 100 us (#10977) - Update test case for removing all reviewers
- doc(repo queries): clarify reviewer actor fetching logic
- doc(issue): comment why assignable actors disabled
- refactor(issue edit): improve actor type handling
- Add test to verify removing all reviewers
- fix bug when removing all PR reviwers
- fix(issue edit): resolve race condition in actor assignment
- chore(issue edit): comments cleanup
- feat(issue edit): support assigning actors to issues
- feat(issue edit): fetch assignable actors
- feat(issue edit): fetch currently assigned actors
- Improve assertion for disabled echo mode (#10927)
- fix(a11y prompter): remove invalid defaults
- Release download handles missing archive URLs
- Fix release download test http stubbing
- feat(fd): add ActorIsAssignable to IssueFeatures
- Feature detect v1 projects on pr edit
- Add
closedByPullRequestsReferencesJSON field toissue view(#10941) - fix(a11y prompter): confirm prompt default is readable
- fix(a11y prompter): multi select defaults are readable
- doc(prompter): remove TODO about default value panic
- fix(a11y prompter): select prompt default value is readable
- refactor(a11yprompter): shared method for prompt defaults
- fix(a11y prompter): Select prompt respects defaults
- fix(a11y prompter): input prompt default value is readable
- test(prompter): add timeout before password input
- Feature detect v1 projects for preview URL
- Feature detect v1 projects on interactive pr create
- Feature detect v1 projects on web mode pr create
- Feature detect v1 projects on non-interactive pr create
- Cleanup run command stubbed finders in tests
- Fix
StatusJSONResponseusage (#10810) - Feature detect v1 projects on pr view
- Add
--delete-lastoption topr commentandissue comment(#10596) - Apply code review changes
- chore(deps): bump actions/attest-build-provenance from 2.2.2 to 2.3.0
- chore(deps): bump github.com/cpuguy83/go-md2man/v2 from 2.0.6 to 2.0.7
- Update the test code to align with latest changes
- test pr number 0
- handle find pr number 0
- restore deleted file
- move filterAttestations function
- getAttestations unit tests
- add test for predicate type filtering
- add missing nil struct checks and udpate error messages
- add check for nil api client
- clean up test fixtures
- reduce test duplication
- comment
- restructure api client methods
- simplify client methods
- remove duplicate predicate filtering code
- create single fetch by digest client method
- dedpulicate if else logic
- pass params object to api client methods
- move local and oci registry attestation filtering
- reorganize getAttestations func to check for remote gh api fetching first
- pass predicate type to get attestation api methods
-
Fix the package tests:
- Ignore TestNewInspectCmd
https://github.com/cli/cli/issues/10926
- Ignore TestAccessiblePrompter https://github.com/cli/cli/issues/10916
- Ignore TestNewInspectCmd
https://github.com/cli/cli/issues/10926
-
Update to version 2.72.0:
- Introduce gh accessibility help topic highlighting GitHub CLI accessibility experiences
- [gh pr view] Support closingIssuesReferences JSON field
- Fix expected error output of TestRepo/repo-set-default
- Ensure accessible password and auth token prompters disable echo mode
- Fix: Accessible multiselect prompt respects default selections
-
Update to version 2.71.2:
- Fix pr create when push.default tracking and no merge ref
-
Update to version 2.71.1:
- Fix pr create when branch name contains slashes
-
Update to version 2.71.0:
- gh pr create: Support Git's @{push} revision syntax for determining head ref
- Introduce option to opt-out of spinners
- Update configuration support for accessible colors
- gh config: add config settings for accessible prompter and disabling spinner
- Fix multi pages search for gh search
- Fix: project commands use shared progress indicator
- Issue commands should parse args early
- Feature detect v1 projects on issue view and edit
- Feature detect v1 projects on web and non web-mode issue create
- Refactor Sigstore verifier logic
- bump deps
-
Update to version 2.70.0:
- Explain job log resolution reason
- Document UNKNOWN STEP in run view
- Add
$anchor to log file regexps - Test normal job run log is preferred over legacy one
- Prefer normal job run log file over legacy one
- Explain when a negative number prefix appears
- Improve explanation for missing step logs
- Explain the
UNKNWON STEPplaceholder - Replace
UNKNOWNwithUNKNOWN STEPin job run log - Explain why step logs are preferred
- test(prompter): fix invalid comment
- test(prompter): fix race condition
- Ensure markdown confirm prompt shows editor name
- fix(prompter): remove needless default value assignment
- test(prompter): doc how accessible prompter tests work
- test(prompter): describe why echo is editorcmd
- test(prompter): use *testing.T instead
- Add missing
gc.AssertExpectationscalls - Add tests for
IsPinnedmethod - Simplify cosign verification example by not using a regex.
- chore: go mod tidy
- fix(prompter): pass io to
huhand refactor tests - fix(prompter): update
huhand fix tests - refactor(prompter): rename speechSynthesizerFriendlyPrompter to accessiblePrompter
- doc(prompter env): accessible prompter includes braille reader
- chore: go mod tidy
- Merge pull request #10749 from malancas/update-to-sigstore-go-v0.7.1
- Update pkg/cmd/run/shared/presentation.go
- Apply suggestions from code review
- Test for explicit config disable of label colors
- Use truthy value for
GH_COLOR_LABELS - test(prompter): re-add skipped test for accessible confirm default
- doc(help): label GH_ACCESSIBLE_PROMPTER as preview
- fix(prompter): rename GH_ACCESSIBLE_PROMPTER
- refactor(prompter): explicit return values
- doc(prompter): remove senseless comment
- refactor(prompter): remove unused variable
- test(prompter): timeout for tests is 1s
- fix(prompter): use os.lookupenv for accessible prompter
- test(prompter): remove needless NO_COLOR set
- test: use example.com in tests
- doc: comment typos and formatting
- test(prompter): add basic survey prompter test
- test(prompter): fix race conditions
- doc(envs): speech synthesis prompter
- Escape dots in regexp pattern in example command
- Verify fallback to job run logs when step logs are missing
- Verify job run logs attached in
attachRunLogtest - Update
run_log.zipfixture - Fallback to print entire job run log if step logs are missing
- Add
LogtoJobdata structure - Add
jobLogFilenameRegexpfunction - Extract job name sanitization as a separate function
- Deprecate ColorScheme.Gray for ColorScheme.Muted
- ci: pin third party actions to commit sha
- doc(prompter): clarify comments
- refactor(prompter): less magic strings
- fix(prompter): remove impossible condition
- fix(prompter): notes about Confirm default
- fix(prompter): input returns default when blank
- test(prompter): more tests for bad input
- Refactor ColorScheme initializer
- Add label color env var to help topic, unused fix
- refactor(prompter): rename env var for speech synthesizer friendly prompter
- docs(prompter): doc prompter interface
- fix(linter): linter errors
- test(prompter): move to external package
- test(prompter): skip vt10x tests on Windows
- Fix comment language
- Introduce
color_labelssupport, update commands - test(prompter): remove needless variable declaration
- tests(prompter): rename huhprompter
- test(prompter): replace assert with require
- fix(prompter): rename huhprompter
- test(prompter):
go-expectbased prompter tests - feat(prompter): include
noas false-y value - test(prompter): remove t.parallel calls
- fix(md prompter): accessible prompt allows blank
- feat(md prompter): md prompt respects blankAllowed
- feat(prompter): add accessible prompter support
- Remove deprecated note on gray color functions
- Regenerate mocks
- Remove configuration setting vestage
- Remove out of scope configuration setting change
- Implement tests for muted logic, standardize reset
- Remove out of scope changes, update list commands
- Accessible color config boilerplate, colors update
- Acceptance test issue/pr create/edit with project
- Update pkg/cmd/attestation/verify/verify.go
- test(release view): fix indentation
- doc(formatting): add line breaks for readability
- Renaming tabl eheader variables for maintainability
- doc(formatting): update sprig func descriptions
- test(many): fix whitespace in tests expectations
- updated test
- added minor caveat
- Tweaked language a bit, improved error message.
- Rewrote the gh at verify --help text to a) clarify and b) document the verificationResult object.
- doc(run shared): clarify 404 handling
- Fixes #10590
- docs: add Sprig library functions to help topics
- chore: update go-gh to v2.12.0
- Implement and fix tests for table headers
- test(run list): update rulesets test name
- doc(run list): add enterprise ruleset notes
- refactor(tests): update test name for org workflows
- docs(run list): doc runs without workflow names
- fix(run list): do not fail on org workflows
- Fix typos in CONTRIBUTING.md
- Underline table headers if colors enabled but no theme
- Ensure table headers are thematically contrasting
- [gh ext] Fix
GitKindextension directory path - More cleanup
./script/signcleanup- Add initial test
- Show host name in repo creation prompts
-
Update to version 2.69.0:
- Curly bracket wrapping acceptance tests
- Refactor commentable logic
- Clean up pr/issue comment test names
- Bring issue/PR comment tests up to par, correct
- Revert "Merge pull request #10384 from iamazeem/9798-gh-api-encode-package-name"
- Initial pass fixing gh issue and gh pr comment
- Bump golang.org/x/net from 0.34.0 to 0.36.0
- chore: remove redundant word in comment
- Make missing workflow regexp aware of GitHub App
- Change issueauto and prauto actions to use the cli-automation env
- Add environment to prauto and issueauto workflows
- Add cli-discuss-automation environment to triage.md
- Separate partitioning from globbing in cmdutil/args package and consumers (#3)
- Add
excludecallback function - Add tests for - and label args
- Remove slicing
- Support globbing for all platforms
- Add testing to GlobWindowsPaths (#2)
- Fix
gh gist createfor multiple filenames and glob patterns - [gh release create/upload] Expand glob patterns on Windows
-
Update to version 2.68.1:
- Fix secret command panic when base repo from cwd
- Fix(ci): base64 decode GPG passphrase
- Update pkg/cmd/attestation/verification/attestation.go
- Update pkg/cmd/attestation/verification/attestation.go
- Fix acceptance test descriptions
- Fix gh secret disambiguity test
- Expand gh secret acceptance tests
- Expand gh secret base repo tests
- [gh secret] Check
GH_REPOtoo in addition to--repofor disambiguation - Deep Dive Document Release Process (#10503)
- Fix unhandled panic in FindWorkflow and add tests
- Bump actions/attest-build-provenance from 2.2.0 to 2.2.2
- Fix checkout when URL arg is from fork and cwd is upstream
- Update
projecthelp text; fixunlinkusage - Inconsistent format of examples in help text
- Inconsistent format of description of flags (starting with lowercase letter) (#10507)
- Update Go version to 1.23 in CONTRIBUTING.md
- Fix minor auth login help typo
- Add docs; rename function name
- Bump github.com/go-jose/go-jose/v4 from 4.0.2 to 4.0.5
- docs: OAuth doc link moves to newline
- fix expected test output
- undo regex changes
- remove signer-ref option
- chore: update go version in devcontainer
- docs: warn about process revoking all tokens
- docs: document how to revoke
ghOAuth tokens - refactor: use a more straightforward return value
- Test pr checkout force on different branch
- [gh pr checkout] Add --no-tags option to git fetch commands in checkout logic
- Allow injection of TUFMetadataDir in tests
- Refactor remote resolver caching tests
- Fix
remoteResolvercaching issue - Address pr comments
- Add test for item-edit --number 0
- Support setting project item number to 0
- Wrap error
- Rename flag to
--fail-on-no-commits - Update tests
- Fix non-TTY case
- Suggestions to enhance upstream default handling
- Use API REST Client
- Use subtests in attestation verification integration tests
- update default upstream when forking repo
- Update usage to lower-kebab-case
- Fix typo in README
- Add missing <> in gh auth login docs
- Add mutex to fix race in attestation test client
- Update tests
- Remove trailing whitespace
- Standardize URLs
- [gh issue/pr comment] Create a comment if no comment already
- Update tests
- Address review comments
- Align no default repo message with other uses
- [gh release create] Fail when there are no new commits since the most recent release
- Use API without shorthand flag
- Update tests
- [gh api] Escape package name (URL encoding) for packages endpoint
- remove custom transport
- var naming
- dedup local bundle err handling
- Update tests
- Add test cases for succeed on no cache and api errors for --all (#1)
- Remove short (abbreviated) flag support
- Address PR review comments
- add checks to cert extensions func
- fix option ordering
- fix issues causing tests to fail
- add signer and source ref, commit options
- Bump github.com/spf13/pflag from 1.0.5 to 1.0.6
- [gh repo view] Improve error message for forked repo
- [gh cache delete --all] Add
--succeed-on-no-cachesflag to return exit code 0 - set new options in enforcement criteria
- reorder fields
- add new signing options
-
Update to version 2.67.0:
- Exit with error if no matching predicate type exists
- Fix logic error in contributing docs
- Improve http error test cases
- Handle non-TTY behavior
- Do not try to parse bodies for HEAD requests
- Update pkg/cmd/pr/status/status.go
- Collapse related instructions
- Remove redundant instructions
- Update language
- [gh pr status] Mention
gh pr checksin theLongsection - Update release doc content
- Doc: Clarify guidelines for
help wantedissues and prs - Bump google.golang.org/protobuf from 1.36.4 to 1.36.5
- Update tests
- [gh project item-edit] Fix number type
- Address review comments
- Address review comments
- Revert breaking change
- Revert "[gh repo edit] Allow setting commit message defaults"
- Use HTML numeric code instead of escaping with slash
- [gh config] Escape pipe symbol in Long desc for website manual
- Ensure item iteration field is populated in tests
- Drop accidental help text change
- Error when
gh repo renameis used with a new repo name that contains an owner - [gh repo edit] Allow setting commit title defaults
- Rename staggler
- Formatting
- AuoLink -> Autolink
- Use http constants
- refac and some spacing in output
- More consistency
- whitespace
- clean up
- Autolink delete http tests
- Revert change to deps
- Autolink delete tests
- Initial working implementation
- remove duplicated Prompter type
- revert isEqualSet to private
- Revert color changes
- [docs/releasing.md] Add basic info for homebrew update flow
- consolidate tests around getBundle func when possible
- change permanent backoff error condition
- Remove unused env var, PRID
- dont retry when parsing fails
- Update test
- [gh issue/pr list] Improve help text
- [gh extensions install] Improve help text and error message
- [gh api] Fix mutual exclusion messages of
--slurpflag - Remove v1 project 'add to board' automation from prauto workflow
- [gh project item-list] Add
iterationIdfield in ProjectV2ItemFieldIterationValue - [gh workflow run] Improve error handling for
--refflag - update tests
- add missing return statement
- method update
- update no attestations found err
- remove old tests
- drop unneeded methods
- deduplicate get attestation code
- fix tests
- update testing
- chore: remove unused file
- feat: integrate new PRLister into pr list command
- issue #2329: create shared PRLister
- fix: tab format may break checkout prompts
- issue #2329: handle empty list of PR
- issue #2329: include PR status in the prompt's options
- issue #2329: fix prompt header getting duplicated
- issue #2329: simplify the UI of the prompt
- issue #2329: update the prompt's format
- issue #2329: fix unit tests
- issue cli#2329: Fix linter
- issue cli#2329: fix unsufficent properties required for PR checkout
- issue #2329: move Interactive check to RunE
- fix: update the copy
- issue #2329: return error when not running interactively
- issue #2329: fix missing stub
- issue #2329: improve UI/UX
- issue #2329: add happy path unit test
- issue #2329: fix the linting issue
- issue #2329: fix the unit tests issue - ensure its backward compatible
- feat: let user select pr to checkout
-
Update to version 2.66.1:
- Address PR comments
- Remove unused ErrNoGitRepository error
- Handle error from ParsePRRefs when the selector is provided
- Add comment to status recognizing when we require a repo
- Refactor finder to work with URL selectors
- Add tests for using the pr Finder outside of repo
- Update deployment.yml
- update tests to account for logic flip
- flip bundle fetching logic
- Update formatting for autolink output
- Rename PRRefs to PullRequestRefs and PR comment cleanup
- Remove redundant error check
- Keeping autolink IDs the same in all test cases
- Expand test case
- Remove unused test field
- Remove unused test field
- Use
deferinstead - Error case test for viewRun
- Autolink view HTTP tests
- Shorten description
- Updates following renaming domain to shared
- Partial testing for view
- Initial, working implementation
- Stop progress indicator on failure (
gh run list --workflow) - Cleaned up some naming and comments
- Minor refactoring autolink create help and logic
- Bump github.com/in-toto/attestation from 1.1.0 to 1.1.1
- Cleanup comment
- Fix pr create tests
- Fix breaking changes from sigstore-go v0.7.0 upgrade
- go mod tidy
- Upgrade sigstore-go to v0.7.0: fixes #10114 formatting issue
- Refactor pr status to use the ParsePRRefs helper on the Finder
- Moved remote.pushDefault out of ReadBranchConfig and into finder
- Remove @{push} from branch config
- Add PushDefault method to git client
- WIP: push default defaults to simple
- Error if push revision doesn't match a remote
- Bump google.golang.org/protobuf from 1.36.3 to 1.36.4
- Refactor finder.Find and replace parseCurrentBranch with parsePRRefs
- Bump actions/attest-build-provenance from 2.1.0 to 2.2.0
- remove bolding from bullet point output
- Update test to be compatible with latest Glamour v0.8.0
- reorder policy enforcement criteria print out
- bold bullet point list header text
- Enable MSI building for Windows arm64
- chore: fix some comments
- Bump go module version to 1.23
- Bump github.com/google/go-containerregistry from 0.20.2 to 0.20.3
- Remove unncessary printf usage
- Bump golang ci lint to work with go 1.24
- Fix: Ensure constant format strings in fmt and printf calls
- Change back to exponential backoff
- Linter
- Better handling for codespace state polling
- Add affected version to bug report form
- fix: tiny typo fix
- Fix: accidental whitespace in gist edit
- Fix: gist edit test name
- Fix: gist edit/view tests var name consistency
- Fix: Gist edit tests for interactivity
- Add small wait to extension update tests
- Refactor test based on PR feedback
- fixup! Add comments and a bit of code cleanup
- Use PushRemoteURL instead of RemoteURL in prSelectorForCurrentBranch
- Add comments and a bit of code cleanup
- skip check
- add tty check
- formatting
- delete unused function
- drop unused handler method
- print attestation output info as bullet points instead of table
- Bump google.golang.org/protobuf from 1.36.2 to 1.36.3
- Fix typo in secret base repo selection comment
- Change wording on secret repo prompt
- Print informative message before prompting for secret repo
- Secret base repo prompting should not use resolved remote
- Move secret base repo prompting earlier
- Add acceptance test for secrets remote disambiguation
- Remove validated TODO and add review warning
- Rename secret BaseRepo func
- Use smarter base repo funcs for secret commands
- Move secret repo validation into secrets subpackage
- Always prompt on secret set when multiple remotes
- Update setdefault test
- Update docs for set-default
- Prompt for secret commands
- Add tests for secret commands
- Add remote check to secret commands
- Add missing git stubs to tests
- Add tests for deleteGist
- Make extension update check non-blocking
- Update pkg/cmd/attestation/verify/verify.go
- add install instructions for Manjaro Linux
- Bump github.com/gabriel-vasile/mimetype from 1.4.7 to 1.4.8
- #10042: Attempt to add a new test scenario for handling error messages when TTY is unavailable
- Rename domain pkg to shared
- #10042: Applied code review suggestions to view_test.go
- show error message for rerun workflow older than a month ago
- Enhance help docs on ext upgrade notices
- fix tests
- fix tests
- gist delete - check no gists
- removed unnecessary space
- Update pkg/cmd/gist/edit/edit.go
- chore: fix some function names in comment
- drop description from prompts, fix tests
- Expand docs on cleaning extension update dir
- Simplifying cleanExtensionUpdateDir logic
- Separate logic for checking updates
- Capture greater detail on updaterEnabled
- Restore old error functionality of prSelectorForCurrentBranch
- Change error handling on ReadBranchConfig to respect git Exit Codes
- fix: add back colon that I removed
- fix: actually read how MaxFunc work and simplify the code
- fix: padded display
- Collapse dryrun checks in ext bin upgrade
- Bump github.com/mattn/go-colorable from 0.1.13 to 0.1.14
- Bump github.com/sigstore/protobuf-specs from 0.3.2 to 0.3.3
- gist delete - use in confirmation and success info
- Rename test user in tests
- Change pr number in test
- Surface and handle error from ReadBranchConfig in parseCurrentBranch
- Directly stub headBranchConfig in Test_tryDetermineTrackingRef
- Refactor error handling in ReadBranchConfig to avoid panic
- Refine error handling of ReadBranchConfig
- Add test for empty BranchConfig in prSelectorForCurrentBranch
- #10042 removed unnecessary field
- Correct help documentation around template use in
gh issue create - #10042: Add error messages for 'gh gist view/edit' prompts when no TTY is detected
- Comment exported functions
- fix gist description in tests
- gist delete prompt with gist description
- Remove shadowed errors from prSelectorForCurrentBranch and cover with tests
- Added tests to cover prSelectorForCurrentBranch for confidence in refactor
- Refactor prSelectorForCurrentBranch and tests
- Add missing test for RemoteURL in parseBranchConfig
- update table column headers
- Change ReadBranchConfig error message in gh pr create
- Remove private readBranchConfig method and remove parseBranchConfig from Client
- update test fixtures to include buildConfigURI
- add check for invalid attestation
- tentative updates for acceptance criteria - pending confirmation re description in prompt
- PR review edits
- Refactor Test_readGitBranchConfig for easier parsing
- update tests to use new function name
- Update pkg/cmd/attestation/api/client.go
- Update pkg/cmd/attestation/api/client.go
- Remove named return values from prSelectorForCurrentBranch
- Refactor ReadBranchConfig for test coverage of newly returned erros
- Remove named returns from ReadBranchConfig and surface errors
- remove old comment
- remove commented out code
- comment
- undo more name chanages
- undo other name change
- remove spaces
- undo name change for now
- more mock http client cleanup
- Update triage.md to reflect FR experiment outcome
- simplify mock http client
- use mock to assert number of http calls
- add http client test constructors
- setup testing struct for test cases
- feat: make the extension upgrade fancier
- Fix up intra-org fork test setup
- Add renamed acceptance tests
- Reflect coverage for view and status subcommands
- Expand with gh pr status
- Add base gh pr view acceptance tests for changes
- Find push remote using branch..pushRemote and remote.pushDefault
- Only find PRs w/ branch..merge if push.default = upstream/tracking
- Find PRs using @{push}
- add mutex for test field
- add test case for bundle url fetch failure
- add tests for bundle url fetch and fallback
- fetch bundles in parallel
- return fetch attestations err directly
- provide additional logging and fallback
- Update pkg/cmd/auth/login/login.go
- Clear up --with-token fine grained PAT usage
- Fix typos
- feat: Add support for creating autolink references
- cleanup
- gist delete prompt for confirmation
- undo extra move
- rearrange struct vals for consistency
- add gist delete tests for blank gist id
- gh gist delete: prompt for gist id
- Escape '.' in version validation regex in deployment workflow
- Add job to deployment workflow to validate the tag name for a given release
- update verify output table
- simplify func params
- add more verification integration tests
- fix failing tests
- add mock http client
- update error messages
- var naming
- go mod tidy
- add httpClient field to LiveClient struct
- remove unused method
- fetch bundles with sas url
- Fix failig local extension tests
- Implement remaining PR feedback
- Implement partial feedback before trunk update
- Add build constraint for non-Windows systems
- Add build constraint for non-Windows systems
- Refactor local installation manager test by OS
- #10042 fixed test
- fixing gh gist view prompts with no TTY
- Remove unnecessary Extension.FullName()
- Expand update tests for local extensions
- Test whether extension update should be checked
- Remove Extension.FullName() from interface
- Enhance extension manager and tests
- Initial extension update check testing
- Refactor extension command testing
- Bring extension update check in line with gh check
- initial pass at fetching bundles with sas urls
-
Update to version 2.65.0:
- Bump cli/go-gh for indirect security vulnerability
- Panic mustParseTrackingRef if format is incorrect
- Move trackingRef into pr create package
- Make tryDetermineTrackingRef tests more respective of reality
- Rework tryDetermineTrackingRef tests
- Avoid pointer return from determineTrackingBranch
- Doc determineTrackingBranch
- Don't use pointer for determineTrackingBranch branchConfig
- Panic if tracking ref can't be reconstructed
- Document and rework pr create tracking branch lookup
- Upgrade generated workflows
- Fixed test for stdout in non-tty use case of repo fork
- Fix test
- Alternative: remove LocalBranch from BranchConfig
- Set LocalBranch even if the git config fails
- Add test for permissions check for security and analysis edits (#1)
- print repo url to stdout
- Update pkg/cmd/auth/login/login.go
- Move mention of classic token to correct line
- Separate type decrarations
- Add mention of classic token in gh auth login docs
- Update pkg/cmd/repo/create/create.go
- docs(repo): make explicit which branch is used when creating a repo
- fix(repo fork): add non-TTY output when fork is newly created
- Move api call to editRun
- Complete get -> list renaming
- Better error testing for autolink TestListRun
- Decode instead of unmarshal
- Use 'list' instead of 'get' for autolink list type and method
- Remove NewAutolinkClient
- Break out autolink list json fields test
- PR nits
- Refactor autolink subcommands into their own packages
- Whitespace
- Refactor out early return in test code
- Add testing for AutoLinkGetter
- Refactor autolink list and test to use http interface for simpler testing
- Apply PR comment changes
- Introduce repo autolinks list commands
- Remove release discussion posts and clean up related block in deployment yml
- Extract logic into helper function
- add pending status for workflow runs
- Feat: Allow setting security_and_analysis settings in gh repo edit
- Upgrade golang.org/x/net to v0.33.0
- Document SmartBaseRepoFunc
- Document BaseRepoFunc
- Update releasing.md
- Document how to set gh-merge-base
-
Update to version 2.64.0:
- add test for different SAN and SourceRepositoryURI values
- add test for signerRepo and tenant
- add some more fields to test that san, sanregex are set properly
- Bump github.com/cpuguy83/go-md2man/v2 from 2.0.5 to 2.0.6
- update san and sanregex configuration for readability
- reduce duplication when creating policy content
- tweak output of build policy info
- Name conditionals in PR finder
- Support pr view for intra-org forks
- Return err instead of silentError in merge queue check
- linting pointed out this var is no longer used
- Removed fun, but inaccessible ASCII header
- further tweaks to the long description
- Exit on pr merge with
-dand merge queue - Addressed PR review feedback; expanded Long command help string, used ghrepo, clarified some abbreviations
- Update pkg/cmd/attestation/inspect/inspect.go
- Update gh auth commands to point to GitHub Docs
- Reformat ext install long
- Mention Windows quirk in ext install help text
- Fix error mishandling in local ext install
- Assert on err msg directly in ext install tests
- Clarify hosts in ext install help text
- Bump golang.org/x/crypto from 0.29.0 to 0.31.0
- Removed now redundant file
- minor tweak to language
- go mod tidy
- Deleted no-longer-used code.
- deleted now-invalid tests, added a tiny patina of new testing.
- Tightened up docs, deleted dead code, improved printing
- fix file name creation on windows
- wording
- hard code expected digest
- fix download test
- use bash shell with integration tests
- simplify var creation
- update integration test scripts
- fix: list branches in square brackets in gh codespace
- try nesting scripts
- run all tests in a single script
- windows for loop syntax
- use replaceAll
- update expected file path on windows
- run integration tests with windows specific syntax
- run all attestation cmd integration tests automatically
- Bump actions/attest-build-provenance from 1.4.4 to 2.1.0
- Improve error handling in apt setup script
- use different file name for attestation files on windows
- test(gh run): assert branch names are enclosed in square brackets
- docs: enhance help text and prompt for rename command
- Revert "Confirm auto-detected base branch"
- Confirm auto-detected base branch
- Merge changes from #10004
- Set gh-merge-base from
issue develop - Open PR against gh-merge-base
- Refactor extension executable error handling
- fix: list branches in square brackets in gh run view (#10038)
- docs: update description of command
- style: reformat files
- docs: update sentence case
- use github owned oci image
- docs: add mention of scopes help topic in
auth refreshcommand help - docs: add mention of scopes help topic in
auth logincommand help - docs: add help topic for auth scopes
- docs: improve help for browse command
- docs: improve docs for browse command as of #5352
- fix package reference
- add gh attestation verify integration test for oci bundles
- add integration test for bundle-from-oci option
- update tests
- update tests
- move content of veriy policy options function into enforcement criteria
- comment
- try switch statement
- remove duplicate err checking
- get bundle issuer in another func
- more logic updating to remove nesting
- inverse logic for less nesting
- remove unneeded nesting
- wip, linting, getting tests to pass
- wording
- var naming
- drop table view
- order policy info so relevant info is printed next to each other
- Update pkg/cmd/attestation/verification/policy.go
- Update pkg/cmd/attestation/verification/policy.go
- Update pkg/cmd/attestation/verification/policy.go
- wip: added new printSummaryInspection
- Improve error handling for missing executable
- experiment with table output
- Assert stderr is empty in manager_test.go
- Update error message wording
- Change: exit zero, still print warning to stderr
- wording
- Improve docs on installing extensions
- Update language for missing extension executable
- Update test comments about Windows behavior
- wording
- wording
- wording
- add newlines for additional policy info
- Document requirements for local extensions
- Warn when installing local ext with no executable
- wording
- formatting
- print policy information before verifying
- add initial policy info method
- more wip poking around, now with table printing
- wip, gh at inspect will check the signature on the bundle
- wip: inspect now prints various bundle fields in a nice json
-
Update to version 2.63.2:
- include alg with digest when fetching bundles from OCI
- Error for mutually exclusive json and watch flags
- Use safepaths for run download
- Use consistent slice ordering in run download tests
- Consolidate logic for isolating artifacts
- Fix PR checkout panic when base repo is not in remotes
- When renaming an existing remote in
gh repo fork, log the change - Improve DNF version clarity in install steps
- Fix formatting in client_test.go comments for linter
- Expand logic and tests to handle edge cases
- Refactor download testing, simpler file descends
- Bump github.com/gabriel-vasile/mimetype from 1.4.6 to 1.4.7
- Improve test names so there is no repetition
- Second attempt to address exploit
-
Update to version 2.63.0:
- Bump cli/go-gh for codespace fix
- Update git/client_test.go
- Update git/client_test.go
- Update git/client_test.go
- Add checkout test that uses ssh git remote url
- Rename backwards compatible credentials pattern
- Fix CredentialPattern doc typos
- Remove TODOs
- Fix typos and add tests for CredentialPatternFrom* functions
- Add SSH remote todo
- General cleanup and docs
- Allow repo sync fetch to use insecure credentials pattern
- Allow client fetch to use insecure credentials pattern
- Allow client push to use insecure credential pattern
- Allow client pull to use insecure credential pattern
- Allow opt-in to insecure pattern
- Support secure credential pattern
- Refactor error handling for missing "workflow" scope in createRelease
- ScopesResponder wraps StatusScopesResponder
- Refactor
workflowscope checking - pr feedback
- pr feedback
- Update pkg/cmd/attestation/verify/attestation_integration_test.go
- Apply suggestions from code review
- Refactor command documentation to use heredoc
- pr feedback
- remove unused test file
- undo change
- add more testing testing fixtures
- update test with new test bundle
- naming
- update test
- update test
- Fix README.md code block formatting
- clean up
- wrap sigstore and cert ext verification into a single function
- Adding option to return
baseRefOidinpr view - verify cert extensions function should return filtered result list
- pr feedback
- Update pkg/cmd/attestation/download/download.go
- fix function param calls
- Update pkg/cmd/attestation/verification/extensions.go
- Formatting fix
- Updated formatting to be more clear
- Updated markdown syntax for a
note. - Added a section on manual verification of the relases.
- Handle missing "workflow" scope in createRelease
- Modify push prompt on repo create when bare
- Doc push behaviour for bare repo create
- Push --mirror on bare repo create
- Add acceptance test for bare repo create
- Doc isLocalRepo and git.Client IsLocalRepo differences
- Use errWithExitCode interface in repo create isLocalRepo
- Backfill repo creation failure tests
- Support bare repo creation
- use logger println method
- simplify verifyCertExtensions
- rename type
- refactor fetch attestations funcs
-
Update to version 2.62.0
- CVE-2024-52308: remote code execution (RCE) when users connect to a malicious Codespace SSH server and use the gh codespace ssh or gh codespace logs commands (boo#1233387, GHSA-p2h2-3vg9-4p87)
- Check extension for latest version when executed
- Shorten extension release checking from 3s to 1s
-
includes changes from 2.61.0:
- Enhance gh repo edit command to inform users about consequences of changing visibility and ensure users are intentional before making irreversible changes
-
Update to version 2.60.1:
- Update testscript to use hard fork
- Note token redaction in Acceptance test README
- Refactor gpg-key delete to align with ssh-key delete
- Add acceptance tests for org command
- Adjust environment help for host and tokens (#9809)
- Add SSH Key Acceptance test
- Add Acceptance test for label command
- Add acceptance test for gpg-key
- Update go-internal to redact more token types in Acceptance tests
- Address PR feedback
- Clarify
ghis available for GitHub Enterprise Cloud - Remove comment from gh auth logout
- Add acceptance tests for auth-setup-git and formattedStringToEnv helper func
- Use forked testscript for token redaction
- Use new GitHub preview terms in working-with-us.md
- Use new GitHub previews terminology in attestation
- Test json flags for repo view and list
- Clean up auth-login-logout acceptance test with native functionality
- Add --token flag to
gh auth loginto accept a PAT as a flag - Setup acceptance testing for auth and tests for auth-token and auth-status
- Update variable testscripts based on secret
- Check extOwner for no value instead
- Fix tests for invalid extension name
- Refactor to remove code duplication
- Linting: now that mockDataGenerator has an embedded mock, we ought to have pointer receivers in its funcs.
- Minor tweaks, added backoff to getTrustDomain
- added test for verifying we do 3 retries when fetching attestations.
- Fix single quote not expanding vars
- Added constant backoff retry to getAttestations.
- Address @williammartin PR feedback
- wip: added test that fails in the absence of a backoff.
- add validation for local ext install
- feat: add ArchivedAt field to Repository struct
- Refactor
gh secrettestscript - Wrap true in '' in repo-fork-sync
- Rename acceptance test directory from repos to repo
- Remove unnecessary flags from repo-delete testscript
- Replace LICENSE Makefile README.md acceptance api bin build cmd context docs git go.mod go.sum internal pkg script share test utils commands with
- Wrap boolean strings in '' so it is clear they are strings
- Remove unnecessary gh auth setup-git steps
- Cleanup some inconsistencies and improve collapse some functionality
- Add acceptance tests for repo deploy-key add/list/delete
- Add acceptance tests for repo-fork and repo-sync
- Add acceptance test for repo-set-default
- Add acceptance test for repo-edit
- Add acceptance tests for repo-list and repo-rename
- Acceptance testing for repo-archive and repo-unarchive
- Add acceptance test for repo-clone
- Added acceptance test for repo-delete
- Added test function for repos and repo-create test
- Implement acceptance tests for search commands
- Remove . from test case for TestTitleSurvey
- Clean up Title Survey empty title message code
- Add missing test to trigger acceptance tests
- Add acceptance tests for
gh variable - Minor polish / consistency
- Fix typo in custom command doc
- Refactor env2upper, env2lower; add docs
- Update secret note about potential failure
- Add testscripts for
gh secret, helper cmds - Remove stdout assertion from release
- Rename test files
- Add acceptance tests for
releasecommands - Implement basic API acceptance test
- Remove unnecesary mkdir from download Acceptance test
- Remove empty stdout checks
- Adjust sleeps to echos in Acceptance workflows
- Use regex assert for enable disable workflow Acceptance test
- Watch for run to end for cancel Acceptance test
- Include startedAt, completedAt in run steps data
- Rewrite a sentence in CONTRIBUTING.md
- Add filtered content output to docs
- sleep 10s before checking for workflow run
- Update run-rerun.txtar
- Create cache-list-delete.txtar
- Create run-view.txtar
- Create run-rerun.txtar
- Create run-download.txtar
- Create run-delete.txtar
- Remove IsTenancy and relevant tests from gists as they are unsupported
- Remove unnecessary code branches
- Add ghe.com to tests describing ghec data residency
- Remove comment
- auth: Removed redundant ghauth.IsTenancy(host) check
- Use go-gh/auth package for IsEnterprise, IsTenancy, and NormalizeHostname
- Upgrade go-gh version to 2.11.0
- Add test coverage to places where IsEnterprise incorrectly covers Tenancy
- Fix issue creation with metadata regex
- Create run-cancel.txtar
- Create workflow-run.txtar
- Create workflow-view.txtar
- implement workflow enable/disable acceptance test
- implement base workflow list acceptance test
- Add comment to acceptance make target
- Resolve PR feedback
- Acceptance test issue command
- Support GH_ACCEPTANCE_SCRIPT
- Ensure Acceptance defer failures are debuggable
- Add acceptance task to makefile
- build(deps): bump github.com/gabriel-vasile/mimetype from 1.4.5 to 1.4.6
- Ensure pr create with metadata has assignment
- Document sharedCmds func in acceptance tests
- Correct testscript description in Acceptance readme
- Add link to testscript pkg documentation
- Add VSCode extension links to Acceptance README
- Fix GH_HOST / GH_ACCEPTANCE_HOST misuse
- Acceptance test PR list
- Support skipping Acceptance test cleanup
- Acceptance test PR creation with metadata
- Suggest using legacy PAT for acceptance tests
- Add host recommendation to Acceptance test docs
- Don't append remaining text if more matches
- Highlight matches in table and content
- Split all newlines, and output no-color to non-TTY
- Print filtered gists similar to code search
- Show progress when filtering
- Simplify description
- Disallow use of --include-content without --filter
- Improve help docs
- Refactor filtering into existing
gist list - Improve performance
- Add
gist searchcommand - Fix api tests after function signature changes
- Return nil instead of empty objects when err
- Fix license list and view tests
- Validate required env vars not-empty for Acceptance tests
- Add go to test instructions in Acceptance README
- Apply suggestions from code review
- Error if acceptance tests are targeting github or cli orgs
- Add codecoverage to Acceptance README
- Isolate acceptance env vars
- Add Writing Tests section to Acceptance README
- Add Debug and Authoring sections to Acceptance README
- Acceptance test PR comment
- Acceptance test PR merge and rebase
- Note syntax highlighting support for txtar files
- Refactor acceptance test environment handling
- Add initial acceptance test README
- Use txtar extension for testscripts
- Support targeting other hosts in acceptance tests
- Use stdout2env in PR acceptance tests
- Acceptance test PR checkout
- Add pr view test script
- Initial testscript introduction
- While we're at it, let's ensure VerifyCertExtensions can't be tricked the same way.
- Add examples for creating
.gitignorefiles - Update help for license view
- Refactor http error handling
- implement
--webflag for license view - Fix license view help doc, add LICENSE.md example
- Update help and fix heredoc indentation
- Add SPDX ID to license list output
- Fix ExactArgs invocation
- Add
Longfor license list indicating limitations - Update function names
- Reverse repo/shared package name change
- If provided with zero attestations to verify, the LiveSigstoreVerifier.Verify func should return an error.
- Bump cli/oauth to 1.1.1
- Add test coverage for TitleSurvey change
- Fix failing test for pr and issue create
- Make the X in the error message red and print with io writer
- Handle errors from parsing hostname in auth flow
- Apply suggestions from code review
- Refactor tests and add new tests
- Move API calls to queries_repo.go
- Allow user to override markdown wrap width via $GH_MDWIDTH from environment
- Add handling of empty titles for Issues and PRs
- Print the login URL even when opening a browser
- Apply suggestions from code review
- Update SECURITY.md
- Fix typo and wordsmithing
- fix typo
- Remove trailing space from heading
- Revise wording
- Update docs to allow community submitted designs
- Implement license view
- Implement gitignore view
- implement gitignore list
- Update license table headings and tests
- Fix ListLicenseTemplates doc
- fix output capitalization
- Cleanup rendering and tests
- Remove json output option
- Divide shared repo package and add queries tests
- First pass at implementing
gh repo license list - Emit a log message when extension installation falls back to a darwin-amd64 binary on an Apple Silicon macOS machine
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1233387
- SUSE Bug 1234566
- SUSE Bug 1235345
- SUSE Bug 1237669
- SUSE Bug 1239496
- SUSE Bug 1241837
- SUSE Bug 1243930
- SUSE Bug 1251464
- SUSE Bug 1251666
- SUSE Bug 1253929
- SUSE Bug 1258617
- SUSE Bug 1260271
- SUSE Bug 1262339
- SUSE Bug 1262943
- SUSE Bug 1265405
- SUSE Bug 1265777
- SUSE Bug 1266173
- SUSE Bug 1266618
- SUSE Bug 1266975
Описание
The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been patched in the cli v2.62.0. Developers connect to remote codespaces through an SSH server running within the devcontainer, which is generally provided through the [default devcontainer image]( https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-... https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-configuration/introduction-to-dev-containers#using-the-default-dev-container-configuration) . GitHub CLI [retrieves SSH connection details]( https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/inv... https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/invoker.go#L230-L244 ), such as remote username, which is used in [executing `ssh` commands]( https://github.com/cli/cli/blob/e356c69a6f0125cfaac782c35acf77314f18908d/pkg/cmd/codespace/ssh.go#L2... https://github.com/cli/cli/blob/e356c69a6f0125cfaac782c35acf77314f18908d/pkg/cmd/codespace/ssh.go#L263 ) for `gh codespace ssh` or `gh codespace logs` commands. This exploit occurs when a malicious third-party devcontainer contains a modified SSH server that injects `ssh` arguments within the SSH connection details. `gh codespace ssh` and `gh codespace logs` commands could execute arbitrary code on the user's workstation if the remote username contains something like `-oProxyCommand="echo hacked" #`. The `-oProxyCommand` flag causes `ssh` to execute the provided command while `#` shell comment causes any other `ssh` arguments to be ignored. In `2.62.0`, the remote username information is being validated before being used.
Затронутые продукты
Ссылки
- CVE-2024-52308
- SUSE Bug 1233387
Описание
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE could use excessive memory. The code used strings.Split(token, ".") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of `.` characters. An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service. Version 4.0.5 fixes this issue. As a workaround, applications could pre-validate that payloads passed to Go JOSE do not contain an excessive number of `.` characters.
Затронутые продукты
Ссылки
- CVE-2025-27144
- SUSE Bug 1237608
- SUSE Bug 1237609