Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
668 commits
Select commit Hold shift + click to select a range
b7195a5
Merge pull request #13759 from cli/dependabot/github_actions/goreleas…
babakks Jun 30, 2026
0afaf6f
docs(search): reword raw qualifier examples
happysnaker Jul 1, 2026
ff4e4a2
Merge pull request #13756 from happysnaker/docs-search-qualifier-exam…
babakks Jul 1, 2026
e64de0c
Add dry_run flag to gate release publishing
niik Jul 1, 2026
0e3afb4
Fix macOS signing/notarization keychain and gating
niik Jul 1, 2026
57e8cce
Update deployment.yml
niik Jul 1, 2026
9e37641
Use workflow_dispatch for deployment flow
niik Jul 1, 2026
d6be637
Update deployment.yml
niik Jul 1, 2026
3b24ab7
Update deployment.yml
niik Jul 1, 2026
7dbc4b5
Add draft issue-triage gh-aw workflow (issue-intents starting point)
lukewar Jul 2, 2026
ecd7027
Retune issue-triage stub to the team's documented triage process
lukewar Jul 2, 2026
637455c
Let's try a different approach
niik Jul 2, 2026
86ded77
Add diagnostic step to list macOS signing identities
niik Jul 2, 2026
0d8d855
Try this then
niik Jul 2, 2026
52669eb
Don't see how this could have worked in the past
niik Jul 2, 2026
ef90664
Don't need this any more
niik Jul 2, 2026
eeb9a3c
Update release deep-dive doc for macOS signing and dry_run changes
niik Jul 2, 2026
070ed9b
Forward dry_run to deployment workflow from script/release
niik Jul 2, 2026
7441b07
Remove ref input from deployment workflow
niik Jul 2, 2026
7a6ed73
Pass macOS signing secrets via env instead of inline interpolation
niik Jul 2, 2026
b63b811
Gate macOS signing on DO_SIGN_ARTIFACTS
niik Jul 2, 2026
64840c7
Mark dry runs in the workflow run name
niik Jul 2, 2026
a79c060
Revert to missing var
niik Jul 2, 2026
f4ce1d9
chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0
dependabot[bot] Jul 2, 2026
b5b459a
Merge branch 'trunk' into niik/deploy
niik Jul 2, 2026
397876d
Merge pull request #13779 from cli/dependabot/github_actions/golangci…
sergiou87 Jul 2, 2026
326faaa
Support antigravity-cli and antigravity2.0 in gh skill (#13784)
Copilot Jul 2, 2026
f1d1121
fix(skills): honor --dir without agent prompt (#13766)
happysnaker Jul 2, 2026
fd8bbbd
docs: fix duplicated word in primer README (#13677)
s3onghyun Jul 2, 2026
5cb1b08
Clarify `--clone` boolean flag behaviour in `gh repo fork` help (#13786)
Copilot Jul 2, 2026
6dae307
docs: fix broken install command and link/grammar errors (#13690)
patrickwehbe Jul 2, 2026
74e7791
Fix concurrent map writes in codespace port forwarding (#13313)
williammartin Jul 2, 2026
b300f2e
Merge commit from fork
victoriamaciver Jul 2, 2026
ed04ff2
Gate publishing the site on the production environment
niik Jul 3, 2026
1b7da92
Fix pkg installer var in deep-dive code snippet
niik Jul 3, 2026
ee7fd9d
Correct pkg signing NOTE in deep-dive
niik Jul 3, 2026
7822e91
Quote $KEYCHAIN in notarytool submit invocation
niik Jul 3, 2026
0ca080d
Bump keyring operation timeout from 3s to 60s
kofuk Jul 3, 2026
c62577b
Merge branch 'trunk' into niik/deploy
niik Jul 3, 2026
9cde87c
Apply suggestions from code review
niik Jul 3, 2026
57a479f
Update deep-dive doc for final release workflow state
niik Jul 3, 2026
9bd8c74
chore(deps): bump charm.land/lipgloss/v2 from 2.0.4 to 2.0.5
dependabot[bot] Jul 3, 2026
62f01e7
chore(deps): bump github.com/klauspost/compress from 1.18.6 to 1.19.0
dependabot[bot] Jul 3, 2026
cfa2cad
Merge pull request #13790 from cli/dependabot/go_modules/charm.land/l…
babakks Jul 3, 2026
4abc935
chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.0
dependabot[bot] Jul 3, 2026
4e40c24
Merge pull request #13789 from cli/dependabot/go_modules/google.golan…
babakks Jul 3, 2026
27762fc
Merge pull request #13791 from cli/dependabot/go_modules/github.com/k…
sergiou87 Jul 3, 2026
94817b7
chore(deps): bump charm.land/bubbletea/v2 from 2.0.7 to 2.0.8
dependabot[bot] Jul 6, 2026
df0bd23
chore(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3
dependabot[bot] Jul 6, 2026
e9a621b
chore(deps): bump golang.org/x/text from 0.38.0 to 0.39.0
dependabot[bot] Jul 7, 2026
ca4604b
Bump Go to 1.26.5
web-flow Jul 8, 2026
12fb220
Merge pull request #13817 from cli/bump-go-1.26.5
babakks Jul 8, 2026
5b17281
chore(deps): bump golang.org/x/sys from 0.46.0 to 0.47.0
dependabot[bot] Jul 8, 2026
487aea5
Adopt skills-driven triage approach from desktop/desktop
tidy-dev Jul 9, 2026
03d2889
Remove medium-confidence instruction from Step 5
tidy-dev Jul 9, 2026
5d4c548
Merge pull request #13777 from lukewar/aw-issue-intents-triage-stub
tidy-dev Jul 9, 2026
6c61ee4
Use Actions token for Copilot inference instead of PAT
tidy-dev Jul 9, 2026
eb42db6
Merge pull request #13830 from cli/aw-copilot-requests-permission
tidy-dev Jul 9, 2026
5cce0a3
chore(deps): bump github/gh-aw-actions/setup from 0.81.6 to 0.82.2
dependabot[bot] Jul 9, 2026
0611eb6
Merge pull request #13800 from cli/dependabot/go_modules/charm.land/b…
tidy-dev Jul 9, 2026
73c6102
chore(deps): bump charm.land/bubbles/v2 from 2.1.0 to 2.1.1
dependabot[bot] Jul 9, 2026
53d9b44
chore(deps): bump codeql-action/init and upload-sarif to v4.36.3
tidy-dev Jul 9, 2026
9ea7e69
Merge pull request #13812 from cli/dependabot/go_modules/golang.org/x…
tidy-dev Jul 9, 2026
989c466
Merge pull request #13821 from cli/dependabot/go_modules/golang.org/x…
tidy-dev Jul 9, 2026
e9e13a8
chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0
dependabot[bot] Jul 9, 2026
9c980dc
Merge pull request #13801 from cli/dependabot/github_actions/github/c…
tidy-dev Jul 9, 2026
a483977
Merge pull request #13832 from cli/dependabot/github_actions/github/g…
tidy-dev Jul 9, 2026
fba5ab9
Merge pull request #13813 from cli/dependabot/go_modules/charm.land/b…
tidy-dev Jul 9, 2026
bd81afd
Merge pull request #13822 from cli/dependabot/go_modules/golang.org/x…
tidy-dev Jul 9, 2026
27d437e
chore(deps): bump actions/cache/restore from 5.0.5 to 6.1.0
dependabot[bot] Jul 10, 2026
1146c49
chore(deps): bump github/gh-aw-actions/setup from 0.82.2 to 0.82.3
dependabot[bot] Jul 10, 2026
180930b
Merge branch 'trunk' into handle-missing-trusted-root
malancas Jul 10, 2026
d58ad9c
drop notPanics assertion
malancas Jul 10, 2026
2a371b2
Merge branch 'handle-missing-trusted-root' of github.com:malancas/cli…
malancas Jul 10, 2026
d51b722
Merge pull request #13624 from malancas/handle-missing-trusted-root
malancas Jul 10, 2026
2b97099
Merge pull request #13843 from cli/dependabot/github_actions/github/g…
babakks Jul 13, 2026
d5f4bed
Add Grok skill host support
tommaso-moro Jul 13, 2026
10c3f78
Merge pull request #13841 from cli/dependabot/github_actions/actions/…
babakks Jul 13, 2026
37f5259
Clarify agent host examples
tommaso-moro Jul 13, 2026
9d95dd7
Merge pull request #13864 from cli/tommaso-moro-add-grok-skill-host
tommaso-moro Jul 13, 2026
70f1c08
chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0
dependabot[bot] Jul 13, 2026
ebaa7af
chore(deps): bump github/codeql-action/upload-sarif
dependabot[bot] Jul 13, 2026
90e850c
chore(deps): bump github/codeql-action/analyze from 4.36.3 to 4.37.0
dependabot[bot] Jul 13, 2026
c14cbaa
Merge pull request #13780 from cli/niik/deploy
tidy-dev Jul 13, 2026
b1e3bf6
chore(deps): bump github/gh-aw-actions/setup from 0.82.3 to 0.82.8
dependabot[bot] Jul 14, 2026
b84c906
chore: remove dead CODEOWNERS rule for non-existent pkg/cmd/release/a…
kobihikri Jul 15, 2026
2af8c11
Merge pull request #13787 from kofuk/bump-keyring-timeout
BagToad Jul 16, 2026
63636a4
docs(search): note OWNER/REPO format on --repo flag
BagToad Jul 20, 2026
d1897f8
Add name-based resolution to gh project item-edit (#13807)
zwick Jul 20, 2026
4007349
Merge pull request #13922 from cli/bagtoad/search-repo-flag-hint
babakks Jul 20, 2026
54a0440
Merge pull request #13867 from cli/dependabot/go_modules/golang.org/x…
babakks Jul 21, 2026
794bbb8
chore(deps): bump github.com/yuin/goldmark from 1.8.2 to 1.8.4
dependabot[bot] Jul 21, 2026
9493134
Merge pull request #13869 from cli/dependabot/github_actions/github/c…
babakks Jul 21, 2026
dcd1adc
Merge pull request #13868 from cli/dependabot/github_actions/github/c…
babakks Jul 21, 2026
f15b788
chore(deps): bump github/codeql-action/init from 4.36.3 to 4.37.1
dependabot[bot] Jul 21, 2026
e1a095c
Upgrade CodeQL action to version 4.37.1
babakks Jul 21, 2026
713fc70
Merge pull request #13870 from cli/dependabot/github_actions/github/c…
babakks Jul 21, 2026
64bc042
Merge pull request #13888 from cli/dependabot/go_modules/github.com/y…
babakks Jul 21, 2026
731fc4c
chore(deps): bump github.com/sigstore/sigstore-go from 1.2.1 to 1.2.2
dependabot[bot] Jul 21, 2026
34a264f
Merge pull request #13842 from cli/dependabot/go_modules/github.com/s…
babakks Jul 21, 2026
340c0de
Merge pull request #13877 from cli/dependabot/github_actions/github/g…
babakks Jul 21, 2026
567a0cc
chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0
dependabot[bot] Jul 21, 2026
8355114
chore(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1
dependabot[bot] Jul 21, 2026
9d3aeaa
chore(deps): bump actions/attest from 4.1.1 to 4.2.0
dependabot[bot] Jul 21, 2026
ee721e8
chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0
dependabot[bot] Jul 21, 2026
a694799
Merge pull request #13886 from kobihikri/rm-dead-codeowners
williammartin Jul 21, 2026
ab07d0c
Merge pull request #13933 from cli/dependabot/github_actions/actions/…
babakks Jul 22, 2026
4b04d7d
Merge pull request #13934 from cli/dependabot/go_modules/google.golan…
babakks Jul 22, 2026
a5a326f
Merge pull request #13936 from cli/dependabot/github_actions/actions/…
babakks Jul 22, 2026
3f0b328
chore(deps): bump github/gh-aw-actions/setup from 0.82.8 to 0.82.13
dependabot[bot] Jul 22, 2026
457f377
Merge pull request #13935 from cli/dependabot/github_actions/actions/…
babakks Jul 22, 2026
6769f9c
chore(deps): bump github.com/mattn/go-isatty from 0.0.22 to 0.0.23
dependabot[bot] Jul 22, 2026
ed60093
Merge pull request #13937 from cli/dependabot/go_modules/github.com/m…
babakks Jul 22, 2026
400e248
Merge pull request #13938 from cli/dependabot/github_actions/github/g…
babakks Jul 22, 2026
0492fd1
chore(typos): fix typos in code and documentation
pstoeckle Jul 22, 2026
bba0816
Merge pull request #13940 from pstoeckle/trunk
williammartin Jul 22, 2026
a047432
chore(deps): bump actions/checkout from 7.0.0 to 7.0.1
dependabot[bot] Jul 22, 2026
5d0f710
chore(deps): bump github/codeql-action/upload-sarif
dependabot[bot] Jul 22, 2026
82dc5ed
Merge pull request #13941 from cli/dependabot/github_actions/actions/…
williammartin Jul 22, 2026
dd45e5b
Merge pull request #13942 from cli/dependabot/github_actions/github/c…
williammartin Jul 22, 2026
4ff2adb
Group CodeQL Dependabot updates
williammartin Jul 22, 2026
0e277a0
Merge pull request #13943 from cli/williammartin-group-codeql-dependa…
babakks Jul 22, 2026
b130a9b
Add --worktree flag to gh pr checkout
tidy-dev Jul 22, 2026
2f012c2
chore(deps): bump github.com/gabriel-vasile/mimetype from 1.4.13 to 1…
dependabot[bot] Jul 22, 2026
975faa3
Refine PR checkout worktree flag help
tidy-dev Jul 22, 2026
3b7f5ab
tidying..
tidy-dev Jul 22, 2026
ae66a1c
chore(deps): bump nodeselector/setup-apple-codesign from ab275d0f6fb6…
dependabot[bot] Jul 22, 2026
9fc654e
Run submodule commands inside the worktree for pr checkout
tidy-dev Jul 22, 2026
9f14d1a
Simplify submodule worktree prefix to inline conditional
tidy-dev Jul 22, 2026
927f2dd
Preserve no-force safety when reusing a worktree for fork PRs
tidy-dev Jul 22, 2026
359fd10
Extract authenticatedCommand helper to dedupe -C handling
tidy-dev Jul 22, 2026
a5eea13
Create branch when reusing a worktree with a new --branch name
tidy-dev Jul 22, 2026
688751d
Harden worktree submodule prefixing and cover cmd.Dir stripping
tidy-dev Jul 22, 2026
efe3f16
Add named field columns to gh project item-list (#13823)
zwick Jul 22, 2026
c28f55d
docs(project): present by-name item-edit as the first-class flow (#13…
Solaris-star Jul 23, 2026
2c87c82
Fix duplicated-word typos in comments (#13900)
SORBELLOSTEFANIE Jul 23, 2026
57c67f1
Cover detach-reuse, worktree fetch dir, and symlink path resolution
tidy-dev Jul 23, 2026
0b5ccd1
Merge branch 'trunk' into tidy-dev-pr-checkout-worktree
tidy-dev Jul 23, 2026
d35ed89
chore(deps): bump github.com/klauspost/compress from 1.19.0 to 1.19.1
dependabot[bot] Jul 23, 2026
0d5ecc0
chore(deps): bump github/gh-aw-actions/setup from 0.82.13 to 0.82.14
dependabot[bot] Jul 23, 2026
e0eac3b
Merge pull request #13950 from cli/dependabot/go_modules/github.com/k…
babakks Jul 24, 2026
4369988
Merge pull request #13951 from cli/dependabot/github_actions/github/g…
babakks Jul 24, 2026
f405232
chore: refresh agentic workflows to stable gh-aw v0.82.14
alondahari Jul 23, 2026
8d87d17
chore: retarget agentic workflows to pre-release gh-aw v0.83.0
alondahari Jul 23, 2026
1722a87
feat(issue-triage): enable native issue-intent on supported safe outputs
alondahari Jul 23, 2026
6245b0e
chore(issue-triage): scope refresh to issue-triage; drop unrelated ma…
alondahari Jul 23, 2026
5212c37
chore: retarget issue-triage agentic workflow to stable gh-aw v0.83.1
alondahari Jul 23, 2026
1f32a02
chore(deps): bump the codeql-actions group with 3 updates
dependabot[bot] Jul 24, 2026
b75499b
chore: initialize agentic workflow tooling
alondahari Jul 24, 2026
01b79dd
Merge pull request #13949 from alondahari/alondahari-refresh-stable-g…
williammartin Jul 24, 2026
5922553
Add macos keyring security doc (#13960)
williammartin Jul 24, 2026
92da47f
Merge pull request #13965 from cli/dependabot/github_actions/codeql-a…
babakks Jul 27, 2026
ba9072a
chore(deps): bump github.com/gabriel-vasile/mimetype
dependabot[bot] Jul 27, 2026
00c9ac6
chore(deps): bump github.com/mattn/go-isatty from 0.0.23 to 0.0.24
dependabot[bot] Jul 27, 2026
8166c4f
chore(deps): bump the codeql-actions group with 3 updates
dependabot[bot] Jul 27, 2026
e580b3c
chore(deps): bump github/gh-aw-actions/setup from 0.83.1 to 0.83.2
dependabot[bot] Jul 27, 2026
d271707
chore(deps): bump github/gh-aw-actions/setup-cli from 0.83.1 to 0.83.2
dependabot[bot] Jul 27, 2026
cc1fba1
chore(deps): bump actions/checkout from 6 to 7
dependabot[bot] Jul 27, 2026
a3ff8e0
Merge pull request #13977 from cli/dependabot/go_modules/github.com/m…
babakks Jul 27, 2026
29792d3
Merge pull request #13978 from cli/dependabot/github_actions/codeql-a…
babakks Jul 27, 2026
8c20102
Merge pull request #13976 from cli/dependabot/go_modules/github.com/g…
sergiou87 Jul 28, 2026
9f7998c
Merge pull request #13979 from cli/dependabot/github_actions/github/g…
sergiou87 Jul 28, 2026
86ecf31
Merge pull request #13980 from cli/dependabot/github_actions/github/g…
sergiou87 Jul 28, 2026
b1a9f7b
Merge pull request #13981 from cli/dependabot/github_actions/actions/…
sergiou87 Jul 28, 2026
cb1d1eb
Replace Windsurf with Devin in skill agents
tommaso-moro Jul 28, 2026
fa6ddc0
chore(deps): bump github/gh-aw-actions/setup from 0.83.2 to 0.83.3
dependabot[bot] Jul 28, 2026
76cb983
chore(deps): bump github/gh-aw-actions/setup-cli from 0.83.2 to 0.83.3
dependabot[bot] Jul 28, 2026
1ded207
Rewrite the pull request template
BagToad Jul 28, 2026
511a45f
Merge pull request #13995 from cli/dependabot/github_actions/github/g…
sergiou87 Jul 29, 2026
b87e58a
Merge pull request #13996 from cli/dependabot/github_actions/github/g…
sergiou87 Jul 29, 2026
89f3699
Merge pull request #13987 from cli/tommaso-moro-rename-windsurf-to-devin
tommaso-moro Jul 29, 2026
9dd2235
Address review: restore TODO, flatten detachCmds, guard worktree symlink
tidy-dev Jul 29, 2026
c7adcce
Detect worktrees via git rev-parse and reject the current worktree
tidy-dev Jul 29, 2026
c891429
Fix worktree toplevel stub to match Windows absolute paths
tidy-dev Jul 29, 2026
d17503e
Resolve worktree target once instead of re-querying git
tidy-dev Jul 29, 2026
4678dcf
Trim redundant comments and clarify worktree field names
tidy-dev Jul 29, 2026
95863ce
Drop docs on self-explanatory worktree helpers
tidy-dev Jul 29, 2026
08b5bf2
Return ok bool from revParseFacts to satisfy nilerr
tidy-dev Jul 29, 2026
f9e0ab3
Clarify current-worktree rejection message
tidy-dev Jul 29, 2026
36a30c5
Bail out early on unusable --worktree paths
tidy-dev Jul 29, 2026
b1c84bb
Merge pull request #14004 from cli/bagtoad/pr-template-anti-slop
williammartin Jul 30, 2026
11a5ef8
Merge pull request #13985 from cli/williammartin-dependabot-triage-dr…
williammartin Jul 30, 2026
c2ad3b0
Fix skill picker label wrapping (#13967)
tommaso-moro Jul 30, 2026
45db9b2
chore(deps): bump github/gh-aw-actions/setup-cli from 0.83.3 to 0.83.4
dependabot[bot] Jul 30, 2026
c6aa327
Merge pull request #14018 from cli/dependabot/github_actions/github/g…
tidy-dev Jul 30, 2026
ba0b7d9
Add a code review agent skill (#14003)
BagToad Jul 30, 2026
2a1409f
Merge commit from fork
BagToad Jul 31, 2026
0c2eea6
Merge commit from fork
babakks Jul 31, 2026
3f6a16a
Merge commit from fork
babakks Jul 31, 2026
55dbb4d
Merge commit from fork
ajbeattie Jul 31, 2026
b46289c
Wrap RESTWithNext errors as api.HTTPError
williammartin Jul 28, 2026
4dee7a5
Slim down dependabot triage comments (#14019)
williammartin Jul 31, 2026
2914e2f
Require explicit PR review ownership (#14028)
williammartin Jul 31, 2026
adc0d7a
chore(deps): bump github.com/yuin/goldmark from 1.8.4 to 1.8.5
dependabot[bot] Jul 31, 2026
c96f0db
Merge pull request #14029 from cli/dependabot/go_modules/github.com/y…
sergiou87 Jul 31, 2026
08973c9
Run Dependabot triage hourly
sergiou87 Jul 31, 2026
5131aaf
Collapse spam triage into the agentic issue-triage workflow (#14027)
williammartin Jul 31, 2026
ad2a338
Merge pull request #14030 from cli/workflow/dependabot-triage-hourly
sergiou87 Jul 31, 2026
e83adbc
Merge pull request #13988 from cli/williammartin-fix-restwithnext-err…
williammartin Aug 1, 2026
2556dac
Route deploy key requests through api.Client
williammartin Jul 28, 2026
4d9aefa
Generate unique acceptance SSH keys
williammartin Jul 28, 2026
bf117b8
chore(deps): bump github.com/sigstore/sigstore-go from 1.2.2 to 1.3.0
dependabot[bot] Aug 3, 2026
9ff6ab2
chore(deps): bump actions/attest from 4.2.0 to 4.2.1
dependabot[bot] Aug 3, 2026
83ebb8c
test(pr/checkout): add acceptance tests for worktree checkout
babakks Aug 3, 2026
ddc7d46
Route deploy key requests through api.Client (#13989)
williammartin Aug 4, 2026
c437c9d
Route ssh key requests through api.Client
williammartin Jul 28, 2026
29a4d8b
Use generated key in ssh-key acceptance test
williammartin Jul 28, 2026
8d81d03
Route ssh key requests through api.Client (#13994)
williammartin Aug 4, 2026
a3ed50a
Route gpg key requests through api.Client (#13997)
williammartin Aug 4, 2026
d2f477e
chore(pr checkout): polish worktree related tests
babakks Aug 4, 2026
8181d21
docs(skills): mention pr checkout worktree support
babakks Aug 4, 2026
cd635d8
docs(pr/checkout): add worktree usage example to help text
babakks Aug 4, 2026
5e6aa5a
fix(pr/checkout): pass -- before worktree path so dash paths work
babakks Aug 4, 2026
980366b
Match worktree rev-parse stub against absolute path on Windows
tidy-dev Aug 4, 2026
8f7afbd
Merge pull request #13946 from cli/tidy-dev-pr-checkout-worktree
tidy-dev Aug 4, 2026
92ae1de
fix(release create): trim spaces when parsing X-Oauth-Scopes
williammartin Aug 4, 2026
8e8a69d
chore(deps): bump the codeql-actions group across 1 directory with 3 …
dependabot[bot] Aug 4, 2026
8f22883
Trim spaces when parsing X-Oauth-Scopes in `gh release create` (#14065)
williammartin Aug 4, 2026
fdad95f
Route autolink requests through api.Client (#14013)
williammartin Aug 4, 2026
0f0e7fd
Route extension requests through api.Client (#14059)
williammartin Aug 4, 2026
c6f4067
Merge pull request #14062 from cli/williammartin-wp-08-release-create
williammartin Aug 4, 2026
77103e3
Tell agents to use the PR template in AGENTS.md
williammartin Aug 5, 2026
408534a
Set GH_EXTENSION=1 when gh invokes an extension
williammartin Aug 5, 2026
ff28e72
Merge pull request #14074 from cli/williammartin-agents-md-pr-templat…
williammartin Aug 5, 2026
5ccd971
Merge pull request #14072 from cli/williammartin-gh-extension-env-var
williammartin Aug 5, 2026
54f33ff
Merge branch 'trunk' into dependabot/github_actions/codeql-actions-43…
williammartin Aug 5, 2026
eb9843b
Gate Dependabot triage on deterministic pre-flight check
williammartin Aug 5, 2026
e576ed3
Gate triager confidence on required evidence
williammartin Aug 5, 2026
6b8adce
Key direct/indirect off the // indirect comment
williammartin Aug 5, 2026
7e29edd
Keep pre-flight dedup out of the integrity proxy
williammartin Aug 5, 2026
3a73d39
Grant the gate the scopes its CI read needs
williammartin Aug 5, 2026
ae253a8
Merge pull request #14079 from cli/williammartin-congenial-bassoon
williammartin Aug 5, 2026
1df3650
Merge pull request #14047 from cli/dependabot/go_modules/github.com/s…
babakks Aug 5, 2026
7216976
chore(deps): bump github.com/google/go-containerregistry
dependabot[bot] Aug 5, 2026
d43da49
chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.0
dependabot[bot] Aug 5, 2026
1d46768
Merge pull request #14049 from cli/dependabot/github_actions/codeql-a…
babakks Aug 5, 2026
50b1933
Merge pull request #14048 from cli/dependabot/go_modules/google.golan…
babakks Aug 5, 2026
8b72a8e
Merge pull request #14066 from cli/dependabot/go_modules/github.com/g…
babakks Aug 5, 2026
608dff7
Route release deletions through api.Client (#14077)
williammartin Aug 6, 2026
5c39f80
Give Dependabot triage a real reachability check (#14087)
williammartin Aug 6, 2026
1cb245f
Restore automatic spam issue closure (#14088)
williammartin Aug 6, 2026
83c6321
Merge pull request #14050 from cli/dependabot/github_actions/actions/…
tidy-dev Aug 6, 2026
4c5f76f
Add a scheduled tech debt burndown skill (#14095)
williammartin Aug 7, 2026
a9223aa
Use reflect.Pointer instead of deprecated reflect.Ptr
williammartin Aug 7, 2026
e4b4931
Clarify PR testing section expectations
williammartin Aug 7, 2026
696fc1c
Use reflect.Pointer instead of deprecated reflect.Ptr (#14098)
williammartin Aug 7, 2026
ad0c74e
Bump golangci-lint in CI to v2.12.2
williammartin Aug 7, 2026
08cf999
Run lint workflow when the lint workflow changes
williammartin Aug 7, 2026
62efc15
Merge pull request #14103 from cli/williammartin-scaling-guacamole
williammartin Aug 7, 2026
9fc0f70
Merge pull request #14102 from cli/williammartin-bump-golangci-lint-ci
williammartin Aug 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"image": "mcr.microsoft.com/devcontainers/go:1.25",
"image": "mcr.microsoft.com/devcontainers/go:1.26",
"features": {
"ghcr.io/devcontainers/features/sshd:1": {}
},
Expand Down
73 changes: 73 additions & 0 deletions .experiments/tech-debt-burndown/memory.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
# Tech debt burndown: agent memory

Standing corrections for the [`tech-debt-burndown` skill](../../.github/skills/tech-debt-burndown/SKILL.md).
This file is loaded at the start of every run and is binding.
Both humans and agent runs write here, and nothing distinguishes the two once
written. Assume any entry may be an unreviewed conclusion from a previous run.
Entries are binding on what to avoid; factual claims in them should be
re-verified before you lean on them, and corrected when stale. Date-stamp
anything you add.

**Budget: 150 lines of entries**, counted from the end of Current focus to the end
of the file. The header and Current focus do not count, and must never be trimmed
to get under budget: they are instructions, not findings. If an append would
exceed the budget, consolidate existing entries first, in the same pull request.

The budget exists so this file stays worth reading, not to save tokens - the
skill file is several times longer. A memory file that has become a run log is
one nobody reads carefully, including you.

## Current focus

**Human-owned. Agent runs must not edit this section.** Propose changes in the
pull request body instead.

Empty. With no focus set, runs fall back to the tier order in the skill.

<!-- Examples of what can go here:
- "Work on pkg/cmd/pr/edit until staticcheck is clean, then add the exclusion."
- "Prefer skipped tests and stale nolints over linter findings for now."
- "Leave staticcheck alone, it is all cosmetic. Focus on errcheck." -->

## Off limits

- Generated code and mocks. See the Never touch section of the skill.
- Removing a feature-detection gate (`// TODO <cleanupIdentifier>`). Whether a
gate can come out depends on the supported GHES version window, which is not
discoverable from the repo and cannot be resolved unattended.

## Known scale of the linter backlog

Counts measured by an agent run on 2026-08-06 against `trunk`, not verified by a
human, and stale as soon as anything lands. Use them to choose between linters,
not as a target count. Command: `--no-config --default=none
--max-issues-per-linter=0 --max-same-issues=0`, so this repo's exclusions are
*not* applied and these are upper bounds: errcheck 1245, staticcheck 221,
gosec 435.

`gosec` is the least tractable, because `.golangci.yml` already excludes G110,
G204, G301, G302, G304, G307, and G404, plus all `gosec` findings in `_test.go`
files, and a `--no-config` run reports all of those anyway. Always cross-check
`gosec` output against `.golangci.yml` before acting on it.

## Staticcheck shape

2026-08-06: repo-wide staticcheck has **no `SA` (correctness) findings**. It is
all style: QF1008 (70), QF1012 (50), ST1005 (29), QF1003 (24), ST1012 (16), rest
single digits. Staticcheck targets are mechanical and safe, but low value.

Most-affected packages: `pkg/cmd/pr/edit` (23), `pkg/cmd/issue/edit` (19),
`pkg/cmd/auth/status` (16), `pkg/cmd/extension` (11). `pkg/cmd/alias/imports` was
cleared 2026-08-06.

## Rejected targets

None yet.

## False positives

None yet.

## Failed attempts

None yet.
2 changes: 2 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -1 +1,3 @@
.github/actions/*/lib/* linguist-generated

.github/workflows/*.lock.yml linguist-generated=true merge=ours
20 changes: 11 additions & 9 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,15 +1,17 @@
* @cli/code-reviewers

pkg/cmd/codespace/ @cli/codespaces
internal/codespaces/ @cli/codespaces
pkg/cmd/codespace/ @cli/codespaces @cli/code-reviewers
internal/codespaces/ @cli/codespaces @cli/code-reviewers

# Limit Package Security team ownership to the attestation command package and related integration tests
pkg/cmd/attestation/ @cli/package-security
pkg/cmd/release/attestation/ @cli/package-security
pkg/cmd/release/verify/ @cli/package-security
pkg/cmd/release/verify-asset/ @cli/package-security
pkg/cmd/release/shared/ @cli/package-security
pkg/cmd/attestation/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/verify/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/verify-asset/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/shared/ @cli/package-security @cli/code-reviewers

test/integration/attestation-cmd @cli/package-security
test/integration/attestation-cmd @cli/package-security @cli/code-reviewers

pkg/cmd/attestation/verification/embed/tuf-repo.github.com/ @cli/tuf-root-reviewers
pkg/cmd/attestation/verification/embed/tuf-repo.github.com/ @cli/tuf-root-reviewers @cli/code-reviewers

pkg/cmd/skills/ @cli/skills @cli/code-reviewers
internal/skills/ @cli/skills @cli/code-reviewers
72 changes: 70 additions & 2 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,72 @@
<!--
Thank you for contributing to GitHub CLI!
To reference an open issue, please write this in your description: `Fixes #NUMBER`
Thank you for contributing to GitHub CLI!

If you are proposing a fix for a security issue, STOP and follow .github/SECURITY.md instead.
-->

<!-- List related issues here. Use `fixes` or `closes` keywords to associate an issue number. -->

### Description

<!--
What's the problem? How are we addressing it?

Write for a reviewer who has not worked in this part of the codebase. Give them the
background they need before the problem makes sense, and avoid jargon.
-->

### How did you test this change?

<!--
Show how you exercised the change yourself, as a user of `gh` would.

Automated test results do not belong here. Passing unit tests, `go test ./...` output, and
coverage numbers tell a reviewer nothing they cannot see from CI, so do not paste them.

Use one or more of these, whichever communicates best:

1. Screenshots or GIFs of the real command running. Preferred whenever the change is visible
in terminal output. If output changed, show it before and after.
2. Given/When/Then scenarios. For example:
Given I am in a repo with no open pull requests
When I run `gh pr list`
Then I see "no open pull requests in cli/cli"
3. A natural language walkthrough of what you did by hand, the states you covered, and what
you saw, including error and edge cases.

If you leave this empty, your pull request will very likely be closed.
-->

### Key points

<!--
Tradeoffs you accepted, alternatives you rejected, and anything a reviewer would otherwise have to guess at.
-->

### Notes for reviewers

<!--
Where should review start, and what should be read next? Call out anything you are unsure about.

Link related issues or prior discussion, with one sentence on why each matters.
-->

### Authorship and follow-up

<!--
REQUIRED - If you are an AI agent filling in this template, answer "Who wrote this" for yourself and answer honestly. For "Who answers review comments," use only a choice the human has explicitly made in the conversation. If no choice has already been established, pause and ask the human to choose one of the three options before creating or updating the pull request. Do not infer the choice from repository ownership, authorship, assignees, prior interactions, or the current operator. After the human answers, check exactly the option they chose; the last option is valid when the human explicitly chooses nobody.

Check exactly one box in each list.
-->

Who wrote this:

- [ ] A human wrote it.
- [ ] An agent wrote it under close human direction.
- [ ] An agent wrote it independently, and no human has guided the implementation beyond the initial prompt.

Who answers review comments:

- [ ] @username will read and reply directly. Name the account.
- [ ] An agent will draft replies and @username will read them before they are posted.
- [ ] Nobody has explicitly committed to replying.
Loading