What cli/cli shipped
Written by FoxPlug from public releases; not affiliated with GitHub CLI. An automatic summary of the public release, pull request and commit data of github.com/cli/cli. GitHub CLI did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- GitHub App user tokens (
ghu_) can now be used with the--attachflag for file uploads in supported scenarios. Pull request #14516 - README now mentions 'gh CLI' in the introduction to improve searchability for users looking for the project. Pull request #14517
- Security policy updated to prioritize HackerOne for vulnerability reports over private GitHub Security Advisories. Pull request #14497
- Pull request template guidance clarified to help reviewers by keeping descriptions focused on repository changes. Pull request #14509
- CLI recording rendering improved to handle font selection separately from command execution and capture. Pull request #14507
Why it matters
This week adds support for additional GitHub App token types in file attachments and improves project discoverability. The updates also strengthen security reporting processes and refine contribution guidelines to make reviews more efficient.
Changelog entry
- Allow
ghu_GitHub App user tokens to be used with the--attachflag for supported actors Pull request #14516 - Add 'gh CLI' to README introduction for improved search visibility Pull request #14517
- Prioritize HackerOne for vulnerability reports in security policy Pull request #14497
- Clarify pull request template guidance for reviewer-facing descriptions Pull request #14509
- Improve CLI recording rendering by separating font selection from execution Pull request #14507
GitHub CLI now accepts GitHub App user tokens (ghu_) for file attachments and improved discoverability in search results. Security reporting prioritized through HackerOne.
This week's updates to GitHub CLI improve token support for file attachments, making GitHub App user tokens (ghu_) available for upload scenarios. We've also strengthened our security reporting process by prioritizing HackerOne, updated the README for better discoverability, and refined contribution guidance to help reviewers evaluate changes more effectively.