Skip to content

GitHub CLI 2.102.0

Latest

Choose a tag to compare

@github-actions github-actions released this 30 Sep 02:40
Immutable release. Only release title and notes can be modified.
fc4b137

Security

Four security vulnerabilities have been identified, and fixed, in this release. Users are advised to update gh to version v2.102.0 as soon as possible.

gh release download, gh run download, gh repo read-file --output, and gh attestation download could write remote content to an unintended local file when the destination contained symbolic links.

See GHSA-39wj-f2f4-978v for more information.

gh attestation verify compared the --source-ref value case-insensitively, so an attestation built from a branch whose name differs only in case could satisfy a policy that named a different branch.

See GHSA-4mq3-hpgx-9cx8 for more information.

Interactive gh skill search passed repository paths from search results to gh skill install without an option separator, so a search result could inject installer options and change where skill files were written.

See GHSA-qcwj-mr2r-2cx7 for more information.

gh attestation verify matched the --signer-workflow value against only the start of the signing certificate's identity, so an attestation signed by a different workflow in the pinned repository could pass verification when its path began with the pinned value.

See GHSA-wjmr-j3rp-mh2g for more information.

What's Changed

🐛 Fixes

📚 Docs & Chores

:dependabot: Dependencies

  • chore(deps): bump the codeql-actions group with 3 updates by @dependabot in #14486
  • chore(deps): bump nodeselector/setup-apple-codesign from 0.0.2 to 0.0.3 by @dependabot in #14487
  • chore(deps): bump charm.land/bubbletea/v2 from 2.0.9 to 2.0.10 by @dependabot in #14541
  • chore(deps): bump github.com/klauspost/compress from 1.20.0 to 1.20.1 by @dependabot in #14542
  • chore(deps): bump the codeql-actions group with 3 updates by @dependabot in #14543

Full Changelog: v2.101.0...v2.102.0