⬆️ Update dependency aqua:cli/cli to v2.97.0 - #27
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
January 21, 2026 21:48
a8acc9c to
f56d8aa
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
2 times, most recently
from
February 18, 2026 22:11
344fbf5 to
1caf435
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
February 20, 2026 22:08
1caf435 to
a84d337
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
February 23, 2026 19:49
a84d337 to
a7b6909
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
March 10, 2026 22:35
a7b6909 to
ca5bcbf
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
March 12, 2026 13:47
ca5bcbf to
7013049
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
March 26, 2026 17:01
7013049 to
4e3c455
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
April 16, 2026 20:09
4e3c455 to
a9e4bd3
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
April 22, 2026 17:51
a9e4bd3 to
ebaf078
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
April 28, 2026 16:36
ebaf078 to
60b33cf
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
May 27, 2026 18:35
60b33cf to
9612afd
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
June 11, 2026 02:43
9612afd to
5ad65b4
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
June 17, 2026 20:35
5ad65b4 to
3f1684e
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
July 3, 2026 01:00
3f1684e to
e04ecb0
Compare
renovate
Bot
force-pushed
the
renovate/aqua-cli-cli-2.x
branch
from
July 31, 2026 02:44
e04ecb0 to
0cd8306
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.2.0→2.97.0Release Notes
cli/cli (aqua:cli/cli)
v2.97.0: GitHub CLI 2.97.0Compare Source
Security
Four security vulnerabilities have been identified, and fixed, in this release. Users are advised to update gh to version
v2.97.0as soon as possible.Several commands (including
gh gist view,gh api,gh pr diff,gh release download --output -,gh codespace logs,gh skills preview, andgh agent-task view/create) printed externally controlled content without neutralizing terminal escape sequences, allowing escape sequence injection into a user's terminal.See GHSA-3m3g-3wcr-px46 for more information.
Some request URLs were built without escaping their variable path components, so a value containing URL path metacharacters could alter the request path and cause
ghto address a different resource than intended.See GHSA-4fjg-2h4q-fwg3 for more information.
gh auth status(without--show-token) could print a portion of the authentication token in plaintext for token types whose format contains an underscore after the prefix, such asgithub_pat_*,ghs_*, andghu_*.See GHSA-cg6r-mpgc-h9mm for more information.
gh attestation verifybuilt the certificate matcher from--signer-repoand--signer-workflowwithout escaping regex metacharacters, so a lookalike repository or workflow name could satisfy a matcher intended for a trusted signer and bypass attestation verification.See GHSA-mm27-mwq9-fr5g for more information.
Address project fields and items by name in
gh projectgh project item-editandgh project item-listcan now reference project fields and single-select options by name:What's Changed
✨ Features
gh project item-editby @zwick in #13807gh project item-listby @zwick in #13823gh skillagents by @tommaso-moro in #13987🐛 Fixes
📚 Docs & Chores
OWNER/REPOformat hint to thegh search --repoflag by @BagToad in #13922item-editas the first-class project flow in docs by @Solaris-star in #13927SITE_DEPLOY_PATwith the gh-cli-site-deployer App by @williammartin in #13492pkg/cmd/release/attestation/by @kobihikri in #13886ab275d0to309922bby @dependabot in #13878New Contributors
Full Changelog: cli/cli@v2.96.0...v2.97.0
v2.96.0: GitHub CLI 2.96.0Compare Source
Security
A security vulnerability has been identified, and fixed, that could allow command execution on a user's computer when connecting to a malicious Codespace via
gh codespace jupyter.Users of
gh codespace jupyterare advised to update gh to version v2.96.0 as soon as possible.For more information see: GHSA-8cg3-r6g9-fpg2
Download release assets without authentication
gh release downloadnow works against public repositories without authentication, matchinggh extension install. A token is still used when one is present:# Download assets from a public repository, no login required gh release download v2.96.0 --repo cli/cliWhat's Changed
✨ Features
gh release downloadwithout authentication on public repositories by @BagToad in #13723antigravity-cliandantigravity2.0ingh skillby @BagToad in #13784🐛 Fixes
~/.agents/skillsby @toller892 in #13681--dirwithout agent prompt by @happysnaker in #13766int64for GitHub database IDs by @williammartin in #13403📚 Docs & Chores
AGENTS.mdby @BagToad in #13720--cloneboolean flag behaviour ingh repo forkhelp by @BagToad in #13786TestHuhPrompterMultiSelectWithSearchPersistenceon slow architectures by @pdostal in #13675New Contributors
Full Changelog: cli/cli@v2.95.0...v2.96.0
v2.95.0: GitHub CLI 2.95.0Compare Source
Read repository files and directories with
gh repo read-fileandgh repo read-dirTwo new preview commands read repository contents without cloning:
Both commands default to the repository's default branch, accept
--refto target any branch, tag, or commit, and support--json,--jq, and--templatefor scripting. This makes it easy for agents and automation to inspect a repo without a full checkout.What's Changed
✨ Features
repo read-fileandrepo read-dirby @babakks in #13580🐛 Fixes
📚 Docs & Chores
Full Changelog: cli/cli@v2.94.0...v2.95.0
v2.94.0: GitHub CLI 2.94.0Compare Source
Issue types, sub-issues, and relationships in
gh issueThis release brings GitHub's advanced issue features to
gh issue create,edit,view, andlist. You can set and view an issue's type, organize work with sub-issues, and track blocked-by and blocking relationships without leaving the command line:Issue types and sub-issues are available on GitHub.com and GHES 3.17+; relationships require GHES 3.19+.
Manage discussions with
gh discussionThis release introduces the
discussioncommand set for working with GitHub Discussions ingh:Run
gh discussion --helpfor more information.Equip your agents with new
ghfeaturesTeach your agents how to leverage new GitHub CLI features on release day by installing the
ghskill:What's Changed
✨ Features
gh discussioncommand set (list,view,create,edit) as a preview by @babakks and @maxbeizer in #13541gh discussion commentto comment on and reply to discussions by @babakks in #13620gh skill listto inventory installed agent skills by @tommaso-moro in #13418--allflag togh skill installto install every skill in a repository by @tommaso-moro in #13471gh skill update --allby @tommaso-moro in #13469gh extension uninstalltogh extension removeby @BagToad in #13599🐛 Fixes
📚 Docs & Chores
gh discussionand Issues 2.0 reference to theghskill, plus a README note by @BagToad in #13631Full Changelog: cli/cli@v2.93.0...v2.94.0
v2.93.0: GitHub CLI 2.93.0Compare Source
Security
A security vulnerability has been identified, and fixed, that would incorrectly include authorization header in API requests to TUF repository mirrors via
gh attestation,gh release verify, andgh release verify-assetcommands.Users are advised to update
ghto versionv2.93.0as soon as possible.For more information see: GHSA-8xvp-7hj6-mcj9
Support agents in
gh secretcommand setThe
gh secretcommand set can now set agent secrets. For more information, see "Configuring secrets and variables for Copilot cloud agent".What's Changed
✨ Features
🐛 Fixes
gh auth refreshfor 401 returns by @333fred in #13068📚 Docs & Chores
gh copilottelemetry sampling to 100% by @williammartin in #13362New Contributors
Full Changelog: cli/cli@v2.92.0...v2.93.0
v2.92.0: GitHub CLI 2.92.0Compare Source
Security
A security vulnerability has been identified, and fixed, that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using
gh run view --logorgh run view --log-failed.Users are advised to update gh to version v2.92.0 as soon as possible.
For more information see: GHSA-crc3-h8v6-qh57
Support GitHub Enterprise Cloud (GHEC) in
skillcommandsetNow
gh skillsubcommands (install,preview,publish,search,update) are able to work with GHEC hosts with data residency.Add
--allow-hidden-dirsflag toskill previewFollowing the addition of
--allow-hidden-dirstoskill installin the previous release, now the flag is also supported inskill preview, allowing users to preview skills located in hidden (dot-prefixed) directories such as.claude/skills/,.agents/skills/, and.github/skills/.What's Changed
✨ Features
🐛 Fixes
📚 Docs & Chores
New Contributors
Full Changelog: cli/cli@v2.91.0...v2.92.0
v2.91.0: GitHub CLI 2.91.0Compare Source
GitHub CLI now collects pseudonymous telemetry
To better understand how features are used in practice, especially as agentic adoption grows, GitHub CLI now sends pseudonymous telemetry.
See Telemetry for more details on what's collected, why, and how to opt out.
Support more agents in
gh skillThanks to community feedback,
ghnow supports a large number of agent hosts. Rungh skill install --helpfor the list of available agents.Improve skill discovery
gh skill installnow adds the--allow-hidden-dirsflag to support discovering skills in hidden (dot-prefixed) directories such as.claude/skills/,.agents/skills/, and.github/skills/.Detect skills re-published from other sources
GitHub CLI now detects if the skill to be installed is re-published from an upstream source and offers the option to install it from there. The
--upstreamflag is also added for non-interactive use cases.What's Changed
✨ Features
gh skills installby @tommaso-moro in #13209skills/directories by @SamMorrowDrums in #13235🐛 Fixes
skills publish --fixto not publish by @SamMorrowDrums in #13237📚 Docs & Chores
Full Changelog: cli/cli@v2.90.0...v2.91.0
v2.90.0: GitHub CLI 2.90.0Compare Source
Manage agent skills with
gh skill(Public Preview)Agent skills are portable sets of instructions, scripts, and resources that teach AI coding agents how to perform specific tasks. The new
gh skillcommand makes it easy to discover, install, manage, and publish agent skills from GitHub repositories - right from the CLI.Skills are automatically installed to the correct directory for your agent host.
gh skillsupports GitHub Copilot, Claude Code, Cursor, Codex, Gemini CLI, and Antigravity. Target a specific agent and scope with--agentand--scopeflags.gh skill publishvalidates skills against the Agent Skills specification and checks remote settings like tag protection and immutable releases to improve supply chain security.Read the full announcement on the GitHub Blog.
gh skillis launching in public preview and is subject to change without notice.Official extension suggestions
When you run a command that matches a known official extension that isn't installed (e.g.
gh stack), the CLI now offers to install it instead of showing a generic "unknown command" error.This feature is available for github/gh-aw and github/gh-stack.
When possible, you'll be prompted to install immediately. When prompting isn't possible, the CLI prints the
gh extension installcommand to run.gh extension installno longer requires authenticationgh extension installpreviously required a valid auth token even though it only needs to download a public release asset. The auth check has been removed, so you can install extensions without being logged in.What's Changed
✨ Features
gh skillcommand group: install, preview, search, update, publish by @SamMorrowDrums and @tommaso-moro in #13165gh skill publish: auto-push unpushed commits before publish by @SamMorrowDrums in #13171gh extension installby @BagToad in #13176🐛 Fixes
gh release list --limit 0by @Bahtya in #13097apiandauthcommands record agentic invocations by @williammartin in #13046Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.