Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency cli/cli to v2.63.0 #313

Merged
merged 1 commit into from
Nov 28, 2024
Merged

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Sep 13, 2024

This PR contains the following updates:

Package Update Change
cli/cli minor v2.53.0 -> v2.63.0

Release Notes

cli/cli (cli/cli)

v2.63.0: GitHub CLI 2.63.0

Compare Source

What's Changed

Full Changelog: cli/cli@v2.62.0...v2.63.0

Security
  • A security vulnerability has been identified in the GitHub CLI that could leak authentication tokens when cloning repositories containing git submodules hosted outside of GitHub.com and ghe.com.

    For more information, see GHSA-jwcm-9g39-pmcw

New Contributors

v2.62.0: GitHub CLI 2.62.0

Compare Source

What's Changed

Full Changelog: cli/cli@v2.61.0...v2.62.0

Security

  • A security vulnerability has been identified in GitHub CLI that could allow remote code execution (RCE) when users connect to a malicious Codespace SSH server and use the gh codespace ssh or gh codespace logs commands.

    For more information, see GHSA-p2h2-3vg9-4p87

GitHub CLI notifies users about latest extension upgrades

Similar to the notification of latest gh releases, the v2.62.0 version of GitHub CLI will notify users about latest extension upgrades when the extension is used:

$ gh ado2gh
...

A new release of ado2gh is available: 1.7.0 → 1.8.0
To upgrade, run: gh extension upgrade ado2gh --force
https://github.com/github/gh-ado2gh
Why does this matter?

This removes a common pain point of extension authors as they have had to reverse engineer and implement a similar mechanism within their extensions directly.

With this quality of life improvement, there are 2 big benefits:

  1. Extension authors will hopefully see increased adoption of newer releases while having lower bar to maintaining their extensions.
  2. GitHub CLI users will have greater awareness of new features, bug fixes, and security fixes to the extensions used.
What do you need to do?

Extension authors should review their extensions and consider removing any custom logic previously implemented to notify users of new releases.

v2.61.0: GitHub CLI 2.61.0

Compare Source

Ensure users understand consequences before making repository visibility changes

In v2.61.0, gh repo edit command has been enhanced to inform users about consequences of changing visibility and ensure users are intentional before making irreversible changes:

  1. Interactive gh repo edit visibility change requires confirmation when changing from public, private, or internal
  2. Non-interactive gh repo edit --visibility change requires new --accept-visibility-change-consequences flag to confirm
  3. New content to inform users of consequences
    • Incorporate GitHub Docs content into help usage and interactive gh repo edit experience
    • Expanded help usage to call out most concerning consequences
    • Display repository star and watcher counts to understand impact before confirming

What's Changed

New Contributors

Full Changelog: cli/cli@v2.60.1...v2.61.0

v2.60.1: GitHub CLI 2.60.1

Compare Source

This is a small patch release to fix installing gh via go install which was broken with v2.60.0.

What's Changed

Full Changelog: cli/cli@v2.60.0...v2.60.1

v2.60.0: GitHub CLI 2.60.0

Compare Source

What's Changed
Acceptance Test Changes
New Contributors

Full Changelog: cli/cli@v2.59.0...v2.60.0

v2.59.0: GitHub CLI 2.59.0

Compare Source

What's Changed

New Contributors

Full Changelog: cli/cli@v2.58.0...v2.59.0

v2.58.0: GitHub CLI 2.58.0

Compare Source

What's Changed

New Contributors

Full Changelog: cli/cli@v2.57.0...v2.58.0

v2.57.0: GitHub CLI 2.57.0

Compare Source

What's Changed

New Contributors

Full Changelog: cli/cli@v2.56.0...v2.57.0

v2.56.0: GitHub CLI 2.56.0

Compare Source

Important note about renewed GPG key

The Debian and RedHat releases have been signed with a new GPG key. If you are experiencing issues updating your .deb or .rpm packages, please read cli/cli#9569.

What's Changed

New Contributors

Full Changelog: cli/cli@v2.55.0...v2.56.0

v2.55.0: GitHub CLI 2.55.0

Compare Source

What's Changed

New Contributors

Full Changelog: cli/cli@v2.54.0...v2.55.0

v2.54.0: GitHub CLI 2.54.0

Compare Source

What's Changed

New Contributors

Full Changelog: cli/cli@v2.53.0...v2.54.0


Configuration

📅 Schedule: Branch creation - "before 4am on Monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from a team as a code owner September 13, 2024 17:11
@renovate renovate bot changed the title Update dependency cli/cli to v2.56.0 Update dependency cli/cli to v2.57.0 Sep 16, 2024
@renovate renovate bot force-pushed the renovate/cli-cli-2.x branch from a5f8c1b to 484c2f5 Compare September 16, 2024 17:18
@renovate renovate bot changed the title Update dependency cli/cli to v2.57.0 Update dependency cli/cli to v2.58.0 Oct 1, 2024
@renovate renovate bot force-pushed the renovate/cli-cli-2.x branch from 484c2f5 to 6dcccf1 Compare October 1, 2024 21:11
@renovate renovate bot changed the title Update dependency cli/cli to v2.58.0 Update dependency cli/cli to v2.59.0 Oct 16, 2024
@renovate renovate bot force-pushed the renovate/cli-cli-2.x branch from 6dcccf1 to 71c8c0c Compare October 16, 2024 15:01
@renovate renovate bot force-pushed the renovate/cli-cli-2.x branch from 71c8c0c to 399b9c6 Compare October 24, 2024 18:28
@renovate renovate bot changed the title Update dependency cli/cli to v2.59.0 Update dependency cli/cli to v2.60.0 Oct 24, 2024
@renovate renovate bot force-pushed the renovate/cli-cli-2.x branch from 399b9c6 to cdb02c4 Compare October 25, 2024 19:44
@renovate renovate bot changed the title Update dependency cli/cli to v2.60.0 Update dependency cli/cli to v2.60.1 Oct 25, 2024
@renovate renovate bot changed the title Update dependency cli/cli to v2.60.1 Update dependency cli/cli to v2.61.0 Nov 7, 2024
@renovate renovate bot force-pushed the renovate/cli-cli-2.x branch from cdb02c4 to 9f2fd0a Compare November 7, 2024 13:38
@renovate renovate bot force-pushed the renovate/cli-cli-2.x branch from 9f2fd0a to cf03a00 Compare November 14, 2024 18:24
@renovate renovate bot changed the title Update dependency cli/cli to v2.61.0 Update dependency cli/cli to v2.62.0 Nov 14, 2024
@renovate renovate bot force-pushed the renovate/cli-cli-2.x branch from cf03a00 to 8d45c3d Compare November 28, 2024 00:38
@renovate renovate bot changed the title Update dependency cli/cli to v2.62.0 Update dependency cli/cli to v2.63.0 Nov 28, 2024
@garethahealy garethahealy merged commit 4c20fa1 into main Nov 28, 2024
1 check passed
@renovate renovate bot deleted the renovate/cli-cli-2.x branch November 28, 2024 10:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant