chore(deps): update dependency gh to v2.102.0 - autoclosed - #158
Closed
renovate[bot] wants to merge 1 commit into
Closed
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
from
July 5, 2026 21:44
6395e80 to
f72c3cd
Compare
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
2 times, most recently
from
July 16, 2026 14:57
4275392 to
a2e4c21
Compare
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
from
July 21, 2026 01:48
a2e4c21 to
0c96de7
Compare
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
2 times, most recently
from
August 3, 2026 02:59
cc5692d to
b0ce23e
Compare
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
from
August 11, 2026 23:08
b0ce23e to
84b5446
Compare
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
2 times, most recently
from
August 23, 2026 22:52
a4580cc to
9b6ef58
Compare
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
from
September 4, 2026 21:32
9b6ef58 to
aa7f41f
Compare
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
from
September 6, 2026 16:42
aa7f41f to
285db63
Compare
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
from
September 8, 2026 00:13
285db63 to
79a33e0
Compare
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
8 times, most recently
from
September 18, 2026 16:03
77c0579 to
c5be415
Compare
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
2 times, most recently
from
October 3, 2026 05:04
8ff5ece to
1676ca8
Compare
renovate
Bot
force-pushed
the
renovate/gh-2.x
branch
from
October 3, 2026 16:28
1676ca8 to
e72271f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.94.0→2.102.0Release Notes
cli/cli (gh)
v2.102.0: GitHub CLI 2.102.0Compare Source
Security
Four security vulnerabilities have been identified, and fixed, in this release. Users are advised to update gh to version
v2.102.0as soon as possible.gh release download,gh run download,gh repo read-file --output, andgh attestation downloadcould write remote content to an unintended local file when the destination contained symbolic links.See GHSA-39wj-f2f4-978v for more information.
gh attestation verifycompared the--source-refvalue case-insensitively, so an attestation built from a branch whose name differs only in case could satisfy a policy that named a different branch.See GHSA-4mq3-hpgx-9cx8 for more information.
Interactive
gh skill searchpassed repository paths from search results togh skill installwithout an option separator, so a search result could inject installer options and change where skill files were written.See GHSA-qcwj-mr2r-2cx7 for more information.
gh attestation verifymatched the--signer-workflowvalue against only the start of the signing certificate's identity, so an attestation signed by a different workflow in the pinned repository could pass verification when its path began with the pinned value.See GHSA-wjmr-j3rp-mh2g for more information.
What's Changed
🐛 Fixes
ghu_tokens for supported actors to attach files by @BagToad in #14516📚 Docs & Chores
gh searchhelp by @waldyrious in #14519gh project item-listhelp by @BagToad in #14553Full Changelog: cli/cli@v2.101.0...v2.102.0
v2.101.0: GitHub CLI 2.101.0Compare Source
Linux package repository signing key rotation
GitHub CLI's APT and RPM repositories, along with individual RPM packages, are now signed only with the new PGP key (fingerprint:
7F38BBB59D064DBCB3D84D725612B36462313325)Copy authentication codes to the clipboard by default
gh auth loginandgh auth refreshnow copy OAuth device codes to the clipboard by default, saving a manual copy step during authentication.To persistently opt out, run:
gh config set clipboard disabledExplicit clipboard options still take precedence for an individual invocation.
What's Changed
✨ Features
🐛 Fixes
📚 Docs & Chores
New Contributors
Full Changelog: cli/cli@v2.100.0...v2.101.0
v2.100.0: GitHub CLI 2.100.0Compare Source
Experimental: Route GitHub API traffic through a custom host
Organizations can now route a GitHub host's API traffic through a gateway using the new per-host
api_hostconfiguration:The original host remains in use for authentication, Git remotes, and browser URLs.
What's Changed
✨ Features
api_hostrouting across GitHub API requests by @williammartin in #14104api_hostthroughgh config getandgh config setby @williammartin in #14332webhookas an official extension by @williammartin in #14326ghis invoked by a coding agent by @niik in #14198🐛 Fixes
📚 Docs & Chores
golang.org/x/cryptofrom 0.55.0 to 0.56.0 by @babakks in #14331github.com/cli/go-gh/v2from 2.15.0 to 2.16.0 by @williammartin in #14338Full Changelog: cli/cli@v2.99.0...v2.100.0
v2.99.0: GitHub CLI 2.99.0Compare Source
Attach images and videos to issues and pull requests
The repeatable
--attachflag uploads local images and videos and adds them to issue, pull request, or comment bodies. If a body already references the local path,ghreplaces it with the uploaded URL; otherwise it appends the attachment:Repeat the flag to attach multiple files in a single invocation. Attachments are available on GitHub.com and GitHub Enterprise Cloud.
For more information see https://gh.io/gh-attach and https://github.blog/changelog/2026-09-01-github-cli-media-in-issues-pull-requests-and-comments/
Worktree support extended to
gh issue developgh issue developcan now create a linked branch and check it out in a new Git worktree, leaving your current working copy unchanged:# Create a linked branch for an issue and check it out in a worktree gh issue develop 123 --checkout --worktree /path/to/wt-featureWhat's Changed
✨ Features
--attachflag parsing and upload orchestration by @BagToad in #14181--attachtogh pr commentandgh issue commentby @BagToad in #14182--attachtogh pr createandgh pr editby @BagToad in #14183--attachtogh issue createandgh issue editby @BagToad in #14184gh issue developby @sergiou87 in #14136ghis invoked by a coding agent by @niik in #14191PI_CODING_AGENT_DIRfor Pi user skills by @tommaso-moro in #14260🐛 Fixes
--delete-branchwith linked worktrees by @tidy-dev in #14007--commentswith--jsonby @BagToad in #14215~/.agents/skillsby @scarletkc in #14154📚 Docs & Chores
--attachstack by @BagToad in #14200ghskill by @BagToad in #14261gh issue develop --checkout --worktreein theghskill by @babakks in #14265go fixby @BagToad in #14278New Contributors
Full Changelog: cli/cli@v2.98.0...v2.99.0
v2.98.0: GitHub CLI 2.98.0Compare Source
Security
A security vulnerability has been identified, and fixed, that binds the local forwarded port to all available network interfaces by default.
Users of
gh codespace ports forwardare advised to updateghto versionv2.98.0as soon as possible.For more information see: GHSA-vfhh-p7hm-pxfh
Support worktrees in
pr checkoutUsers can now checkout a pull request into a git worktree by using the new
--worktree PATHflag ingh pr checkout:Add semantic search to
search issuesThe
gh search issuescommand now supports semantic search for issues. Users can select the search type by passing the--search-typeflag:For more information about semantic search see: "Improved Search for github issues is now generally available".
What's Changed
✨ Features
🐛 Fixes
RESTWithNexterror type, repairinggh statusand attestation retries by @williammartin in #13988gh release createby @williammartin in #14065📚 Docs & Chores
New Contributors
Full Changelog: cli/cli@v2.97.0...v2.98.0
v2.97.0: GitHub CLI 2.97.0Compare Source
Security
Four security vulnerabilities have been identified, and fixed, in this release. Users are advised to update gh to version
v2.97.0as soon as possible.Several commands (including
gh gist view,gh api,gh pr diff,gh release download --output -,gh codespace logs,gh skills preview, andgh agent-task view/create) printed externally controlled content without neutralizing terminal escape sequences, allowing escape sequence injection into a user's terminal.See GHSA-3m3g-3wcr-px46 for more information.
Some request URLs were built without escaping their variable path components, so a value containing URL path metacharacters could alter the request path and cause
ghto address a different resource than intended.See GHSA-4fjg-2h4q-fwg3 for more information.
gh auth status(without--show-token) could print a portion of the authentication token in plaintext for token types whose format contains an underscore after the prefix, such asgithub_pat_*,ghs_*, andghu_*.See GHSA-cg6r-mpgc-h9mm for more information.
gh attestation verifybuilt the certificate matcher from--signer-repoand--signer-workflowwithout escaping regex metacharacters, so a lookalike repository or workflow name could satisfy a matcher intended for a trusted signer and bypass attestation verification.See GHSA-mm27-mwq9-fr5g for more information.
Address project fields and items by name in
gh projectgh project item-editandgh project item-listcan now reference project fields and single-select options by name:What's Changed
✨ Features
gh project item-editby @zwick in #13807gh project item-listby @zwick in #13823gh skillagents by @tommaso-moro in #13987🐛 Fixes
📚 Docs & Chores
OWNER/REPOformat hint to thegh search --repoflag by @BagToad in #13922item-editas the first-class project flow in docs by @Solaris-star in #13927SITE_DEPLOY_PATwith the gh-cli-site-deployer App by @williammartin in #13492pkg/cmd/release/attestation/by @kobihikri in #13886ab275d0to309922bby @dependabot in #13878New Contributors
Full Changelog: cli/cli@v2.96.0...v2.97.0
v2.96.0: GitHub CLI 2.96.0Compare Source
Security
A security vulnerability has been identified, and fixed, that could allow command execution on a user's computer when connecting to a malicious Codespace via
gh codespace jupyter.Users of
gh codespace jupyterare advised to update gh to version v2.96.0 as soon as possible.For more information see: GHSA-8cg3-r6g9-fpg2
Download release assets without authentication
gh release downloadnow works against public repositories without authentication, matchinggh extension install. A token is still used when one is present:# Download assets from a public repository, no login required gh release download v2.96.0 --repo cli/cliWhat's Changed
✨ Features
gh release downloadwithout authentication on public repositories by @BagToad in #13723antigravity-cliandantigravity2.0ingh skillby @BagToad in #13784🐛 Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.