NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #845 most downloaded on npm
Generated TypeScript definitions based on GitHub's OpenAPI spec for api.github.com
Last release 1 months ago
29 Aug 2026
Release timing varies
gaps range from 2 weeks to 9 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
6 years old
162 releases · first in 2020
One column per quarter.
29.0.1 (2026-08-29) Bug Fixes remove empty requestBody
GET /agents/repos/{owner}/{repo}/tasks
Full Changelog: v28.0.0...v29.0.0
add additional types to binary body endpoints
/orgs/{org}/projects/orgs/{org}/settings/billing/actions/orgs/{org}/settings/billing/packages/orgs/{org}/settings/billing/shared-storage/orgs/{org}/teams/{team_slug}/projects/orgs/{org}/teams/{team_slug}/projects/{project_id}/projects/columns/{column_id}/projects/columns/{column_id}/moves/projects/{project_id}/projects/{project_id}/collaborators/projects/{project_id}/collaborators/{username}/projects/{project_id}/collaborators/{username}/permission/repos/{owner}/{repo}/projects/teams/{team_id}/projects/teams/{team_id}/projects/{project_id}/user/projects/users/{username}/projects/users/{username}/settings/billing/actions/users/{username}/settings/billing/packages/users/{username}/settings/billing/shared-storageadd GHES 3.18, immutable releases, enterprise team membership, enterprise team organization, custom runner images, many type additions and improvement
remove GHES 3.13, new Projects v2 endpoints, new code scanning dismissal endpoints, many other endpoints
add GHES 3.17, new /credentials/revoke , /users/{username}/settings/billing/usage , /enterprises/{enterprise}/members/{username}/copilot endpoints, de
new /orgs/{org}/campaigns , /orgs/{org}/campaigns/{campaign_number} endpoints, remove Copilot usage endpoints, description updates
new /orgs/{org}/issue-types , /orgs/{org}/issue-types/{issue_type_id} enpoints, add issue type to responses, add dismissal request for code scanning f
…endpoints, deprecate Projects (classic), deprecate Copilot usage endpoints, description updates
epss_percentage sorting to advisories, new epss_percentage parameter for dependabot alerts, new dismissal_approved_by parameter to code scanning alerts, new /enterprises/{enterprise}/actions/hosted-runners, /orgs/{org}/actions/hosted-runners, /orgs/{org}/settings/network-configurations, /orgs/{org}/rulesets/{ruleset_id}/history, /repos/{owner}/{repo}/rulesets/{ruleset_id}/history endpoints, deprecate Projects (classic), deprecate Copilot usage endpoints, description updates (#455) (fbef6d1)new dismissed_comment and fixed_at attributes on code scanning alerts, description updates, remove GHES 3.10 and 3.11, remove GHAE
dismissed_comment and fixed_at attributes on code scanning alerts, description updates, remove GHES 3.10 and 3.11, remove GHAE (#451) (22dc3a0)replace missing component with inline definition
Deprecate /orgs/{org}/{security_product}/{enablement}
/enterprises/{enterprise}/copilot/billing/seats/enterprises/{enterprise}/settings/billing/cost-centers/enterprises/{enterprise}/settings/billing/usage/enterprises/{enterprise}/code-security/configurations/defaults/enterprises/{enterprise}/code-security/configurations/{configuration_id}/enterprises/{enterprise}/code-security/configurations/{configuration_id}/attach/orgs/{org}/actions/runner-groups/orgs/{org}/actions/runner-groups/{runner_group_id}/orgs/{org}/actions/runner-groups/{runner_group_id}/repositories/orgs/{org}/actions/runner-groups/{runner_group_id}/repositories/{repository_id}/orgs/{org}/actions/runner-groups/{runner_group_id}/runners/orgs/{org}/actions/runner-groups/{runner_group_id}/runners/{runner_id}/orgs/{org}/copilot/metrics/orgs/{org}/insights/api/route-stats/{actor_type}/{actor_id}/orgs/{org}/insights/api/subject-stats/orgs/{org}/insights/api/summary-stats/orgs/{org}/insights/api/summary-stats/users/{user_id}/orgs/{org}/insights/api/summary-stats/{actor_type}/{actor_id}/orgs/{org}/insights/api/time-stats/orgs/{org}/insights/api/time-stats/users/{user_id}/orgs/{org}/insights/api/time-stats/{actor_type}/{actor_id}/orgs/{org}/insights/api/user-stats/{user_id}/orgs/{org}/private-registries/orgs/{org}/private-registries/public-key/orgs/{org}/private-registries/{secret_name}/orgs/{org}/team/{team_slug}/copilot/metrics/orgs/{org}/team/{team_slug}/copilot/usage/orgs/{org}/{security_product}/{enablement}/repos/{owner}/{repo}/code-scanning/alerts/{alert_number}/autofix/repos/{owner}/{repo}/code-scanning/alerts/{alert_number}/autofix/commits/repos/{owner}/{repo}/code-security-configuration/repos/{owner}/{repo}/issues/{issue_number}/sub_issues/repos/{owner}/{repo}/issues/{issue_number}/sub_issues/priority/repos/{owner}/{repo}/secret-scanning/push-protection-bypasses/repos/{owner}/{repo}/secret-scanning/scan-historyadd copilot endpoints, add reusable components, description updates
remove all_of for issue, workflow_run, alert, release, pull_request, marketplace_purchase
description updates, new parameter for enterprise-admin/license-upload, default_value field can now also be string[] on custom_property
BREAKING CHANGES: renames [repository-rule-params-code-scanning-threshold to repository-rule-params-code-scanning-tool, security_alerts to security_al…
# 21.2.0 (2024-04-03) ### Features * security: Add provenance
creates a component for security-advisory-ecosystems, adds deprecated attribute to workflow-run-requested.hub_url, BREAKING CHANGES: [renames operatio…
empty commit to trigger a release
add GHES 3.11, GHES 3.12, remove GHES 3.7, many description updates and new enpoints
drop GHES 3.7 and OpenAPI updates
description and sample payload updates
## 19.0.1 (2023-10-24) ### Bug Fixes * description updates
new GitHub advisories, GitHub classroom, copilot endpoints, description updates, remove GHES 3.6, add GHES 3.10
new GitHub advisories, GitHub classroom, copilot endpoints, description updates, remove GHES 3.6, add GHES 3.10
schema updates on 'codespaces' endpoint and other minor updates
new merge group endpoints, description updates, GHES 3.9 support
remove "empty object" type from gists-update operation
update the types for the patch to fix occurences of never
new deployment protection rule endpoints, new private reporting of security vulnerability endpoint
empty commit to trigger a release
many unreleased OpenAPI updates
removes GHES 3.3 support as it was deprecated recently
Many unreleased changes (#286) (040e742), closes #286
Types for API operations only available to GitHub Enterprise Cloud (GHEC) customers will no longer appear in the @octokit/openapi-types package. These
@octokit/openapi-types package. These will only appear in the GHEC-specific @octokit/openapi-types-ghec package. The @octokit/openapi-types package now only includes APIs available to customers on GitHub.com using the Free, Pro and Teams plans.@octokit/openapi-types-ghec package, plus lots of API changes (29539cf)GET /repos/{owner}/{repo}/dependabot/alerts/{alert_number})PATCH /repos/{owner}/{repo}/dependabot/alerts/{alert_number})GET /repos/{owner}/{repo}/dependabot/alerts)GET /organizations/{org}/codespaces/secrets) Codespaces APIGET /organizations/{org}/codespaces/secrets/public-key) Codespaces APIGET /organizations/{org}/codespaces/secrets/{secret_name} ) Codespaces APIPUT /organizations/{org}/codespaces/secrets/{secret_name} ) Codespaces APIDELETE /organizations/{org}/codespaces/secrets/{secret_name}) Codespaces APIGET /organizations/{org}/codespaces/secrets/{secret_name}/repositories) Codespaces APIPUT /organizations/{org}/codespaces/secrets/{secret_name}/repositories) Codespaces APIPUT /organizations/{org}/codespaces/secrets/{secret_name}/repositories/{repository_id}) Codespaces APIDELETE /organizations/{org}/codespaces/secrets/{secret_name}/repositories/{repository_id}) Codespaces APIresolution_comment attribute returned on secret scanning alertsscope attribute returned by the "Get a diff of the dependencies between commits" (GET /repos/{owner}/{repo}/dependency-graph/compare/{basehead}) API### Fixes
GET /repos/{owner}/{repo}/stargazers, GET /users/{username}/starred and GET /user/starred) to clarify what Accept header to send to get information about when stars were createdGET /repos/{owner}/{repo}/community/profile) to clarify that it only works with public repos which are not forkssize attribute returned on repos across the API422 errors when an endpoint has been spammed with many requests301 status returned by labels-related APIs if the repo has been renamed or moved404 Not Found status returned by labels-related APIsrevert "feat: publish new GitHub Enterprise Cloud (GHEC) specific @octokit/openapi-types-ghec package, plus lots of API changes (#251)"
_This version was published accidentally as a minor version, when it should have been a major version._
This version was published accidentally as a minor version, when it should have been a major version.
add support for new display_title attribute returned on workflow runs across the API (e.g. in GET /repos/{owner}/{repo}/actions/runs)
feat: add new "List CodeQL databases for a repository" API (GET /repos/{owner}/{repo}/code-scanning/codeql/databases)
GET /repos/{owner}/{repo}/code-scanning/codeql/databases)GET /repos/{owner}/{repo}/code-scanning/codeql/databases/{language})PUT /repos/{owner}/{repo}/contents/{path}) and "Delete a file" (DELETE /repos/{owner}/{repo}/contents/{path}) APIs to clarify that calling them in parallel may lead to conflictsgithub advanced security to GitHub Advanced Security in descriptionsPATCH /repos/{owner}/{repo}/secret-scanning/alerts/{alert_number}) to clarify that a resolution must be provided when setting state to resolvedenums rather than string types with a list of accepted values in the description (e.g. the conclusion attribute returned in the "Get a job for a workflow run" API [GET /repos/{owner}/{repo}/actions/jobs/{job_id}])…singular github_com_enterprise_role attribute as deprecated
github_com_enterprise_roles attribute returned by the "List enterprise consumed licenses" API (GET /enterprises/{enterprise}/consumed-licenses), marking the old singular github_com_enterprise_role attribute as deprecatedGET /repos/{owner}/{repo}/collaborators) by permission using a query paramGET /enterprises/{enterprise}/consumed-licenses) as betaPUT /repos/{owner}/{repo}/contents/{path}) requires the workflow scopeGET /repos/{owner}/{repo}/hooks)tweak description for "Get a tree" API (GET /repos/{owner}/{repo}/git/trees/{tree_sha}) to clarify maximum limits on size and number of entries and do
fix: mark use_squash_pr_title_as_default attribute on repos as deprecated in favour of squash_merge_commit_title
POST /orgs/{org}/custom_roles, PATCH /orgs/{org}/custom_roles/{role_id}, DELETE /orgs/{org}/custom_roles/{role_id}, GET /orgs/{org}/fine_grained_permissions)description, base_role, permissions, organization, created_at and updated_at fields where custom repo roles are returned in the APIGET /orgs/{org}/packages/{package_type}/{package_name}/versions) to clarify that they returned paginated lists ("Get all..." -> "List...")use_squash_pr_title_as_default attribute on repos as deprecated in favour of squash_merge_commit_titleGET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs) API to the more indicative "List workflow runs for a workflow"sha request body parameter in the "Delete a file" API (DELETE /repos/{owner}/{repo}/contents/{path})Add support for filtering "List workflows runs for a repository" (GET /repos/{owner}/{repo}/actions/runs) and "List workflow runs [for a workflow]" (G
GET /repos/{owner}/{repo}/actions/runs) and "List workflow runs [for a workflow]" (GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs ) by head_shastate_reason attribute on issues to be a enum (completed, not_planned or reopened) rather than an unbounded stringAdd support for is_alphanumeric boolean attribute for autolinks, accepted in the request body of the "Create an autolink reference for a repository" (
is_alphanumeric boolean attribute for autolinks, accepted in the request body of the "Create an autolink reference for a repository" (POST /repos/{owner}/{repo}/autolinks) API and returned on autolinks across the APIrule.help_uri attribute returned on code scanning alerts across the API (GET /enterprises/{enterprise}/code-scanning/alerts, GET /orgs/{org}/code-scanning/alerts, GET /repos/{owner}/{repo}/code-scanning/alerts/{alert_number}, PATCH /repos/{owner}/{repo}/code-scanning/alerts/{alert_number})anonymous_access_enabled boolean attribute returned on repos across the APIPOST /repos/{owner}/{repo}/autolinks) to read more smoothlyPOST /repos/{template_owner}/{template_repo}/generate) doesn't require any special permissions with a public repo302 as a potential response status code for GET /orgs/{org}/members, which hasn't been returned for nearly 8 years503 as a potential response status code across various API operationsAdd support for new "Enable or disable a security feature for an organization" API (POST /orgs/{org}/{security_product}/{enablement})
POST /orgs/{org}/{security_product}/{enablement})advanced_security_enabled_for_new_repositories, dependabot_alerts_enabled_for_new_repositories, dependabot_security_updates_enabled_for_new_repositories, dependency_graph_enabled_for_new_repositories, secret_scanning_enabled_for_new_repositories and secret_scanning_push_protection_enabled_for_new_repositories read-write boolean attributes on organizationslast_known_stop_notice attribute on Codespace machines across the APIGET /user/ssh_signing_keys, POST /user/ssh_signing_keys, GET /user/ssh_signing_keys/{ssh_signing_key_id}, DELETE /user/ssh_signing_keys/{ssh_signing_key_id}, GET /users/{username}/ssh_signing_keys)Add support for sorting with sort and direction querystring parameters when listing a repo's code scanning analyses with GET /repos/{owner}/{repo}/cod
sort and direction querystring parameters when listing a repo's code scanning analyses with GET /repos/{owner}/{repo}/code-scanning/analysesdefault_branch_only boolean request body parameter when creating a fork with POST /repos/{owner}/{repo}/forksstate_reason request body parameter when updating an issue with PATCH /repos/{owner}/{repo}/issues/{issue_number}GET /organizations/{organization_id}/custom_roles to clarify required permissionsDELETE /repos/{owner}/{repo}/code-scanning/analyses/{analysis_id} to clarify how sets of analyses workGET /repos/{owner}/{repo}/contents/{path} to clarify that download links expireadd web_commit_signoff_required request body parameter in POST /orgs/{org}/repos, PATCH /repos/{owner}/{repo} and PATCH /repos/{owner}/{repo}
web_commit_signoff_required request body parameter in POST /orgs/{org}/repos, PATCH /repos/{owner}/{repo} and PATCH /repos/{owner}/{repo}web_commit_signoff_required response attribute where repositories and organizations are returned in the APIadd squash_merge_commit_title, squash_merge_commit_message, merge_commit_title and merge_commit_message request body parameters in POST /orgs/{org}/re
squash_merge_commit_title, squash_merge_commit_message, merge_commit_title and merge_commit_message request body parameters in POST /orgs/{org}/repos, PATCH /repos/{owner}/{repo}, POST /user/repossquash_merge_commit_title, squash_merge_commit_message, merge_commit_title and merge_commit_message response attributes where repositories are returned in the APIadd new permissions.organization_custom_roles response attribute in GET /app/installations, GET /app/installations/{installation_id}, POST /app/instal
permissions.organization_custom_roles response attribute in GET /app/installations, GET /app/installations/{installation_id}, POST /app/installations/{installation_id}/access_tokens, POST /applications/{client_id}/token, PATCH /applications/{client_id}/token, POST /applications/{client_id}/token/scoped, GET /orgs/{org}/installation, GET /orgs/{org}/installations, GET /repos/{owner}/{repo}/installation, GET /user/installations and GET /users/{username}/installationpermissions.organization_custom_roles request body parameter in POST /app/installations/{installation_id}/access_tokens and POST /applications/{client_id}/token/scopedmanifests passed in request body to POST /repos/{owner}/{repo}/dependency-graph/snapshotsadd new Enterprise licenses APIs (GET /enterprises/{enterprise}/consumed-licenses, GET /enterprises/{enterprise}/license-sync-status)
build: allow download script to handle more than 30 GitHub release assets
This removes support for the now-defunkt OAuth Authorizations APIs. These were disabled on GitHub.com at the end of 2020, but the OpenAPI specs were n
GET /orgs/{org}/code-scanning/alerts with public reposGET /orgs/{org}/security-managers, PUT /orgs/{org}/security-managers/teams/{team_slug} and DELETE /orgs/{org}/security-managers/teams/{team_slug})GET /repos/{owner}/{repo}/environments/{environment_name}/deployment-branch-policies, POST /repos/{owner}/{repo}/environments/{environment_name}/deployment-branch-policies, GET /repos/{owner}/{repo}/environments/{environment_name}/deployment-branch-policies/{branch_policy_id} , PUT /repos/{owner}/{repo}/environments/{environment_name}/deployment-branch-policies/{branch_policy_id}, DELETE /repos/{owner}/{repo}/environments/{environment_name}/deployment-branch-policies/{branch_policy_id})POST /repos/{owner}/{repo}/pages/deployment)GET /enterprise-installation/{enterprise_or_org}/server-statistics to reflect that it returns an array of resultsretention_period_minutes and retention_expires_at fields returned on CodespacesPOST /repos/{owner}/{repo}/statuses/{sha}) to reflect that target_url and description can be nulltype of items returned by the GET /repos/{owner}/{repo}/contents/{path} API as enum (dir, file, submodule, symlink)added_by and last_used attributes on Deploy Keys returned across the APIpermission request body parameter for PUT /orgs/{org}/teams/{team_slug}/repos/{owner}/{repo} and PUT /repos/{owner}/{repo}/collaborators/{username} to reflect that custom role names can be specified, not just values in a GitHub-set enumpage and per_page parameters for GET /repos/{owner}/{repo}/pulls/{pull_number}/requested_reviewers which are not actually supportedbuild_type parameter in POST /repos/{owner}/{repo}/pages and PUT /repos/{owner}/{repo}/pagescommit_id, path and line are in fact required for `POST /repos/{owner}/{repo}/pulls/{pull_number}/commentsPOST /repos/{owner}/{repo}/pulls/{pull_number}/reviews to reflect that event must be sent to DISMISSnew GET /enterprises/{enterprise}/code-scanning/alerts endpoint and description updates for multiple other endpoints
add example for use_squash_pr_title_as_default property when repositories are returned in the API
Add new GET /repos/{owner}/{repo}/codespaces/new API operation
GET /repos/{owner}/{repo}/codespaces/new API operationimprove parameter descriptions for GET /repos/{owner}/{repo}/pulls/{pull_number}/requested_reviewers
feat: improve operation descriptions when an API operation is not available in a particular context (e.g. GHAE or a GHES version)
POST /authorizations, PUT /authorizations/clients/{client_id} and PUT /authorizations/clients/{client_id}/{fingerprint}examples and annotations about strings' formats, where availablecache/feat: add support for returning dependency_snapshots-specific rate limits in GET /rate_limit
dependency_snapshots-specific rate limits in GET /rate_limitPOST /repos/{owner}/{repo}/actions/runs/{run_id}/pending_deployments is only available to required reviewersmark sort by number for GET /repos/{owner}/{repo}/code-scanning/alerts as deprecated
name for the forked repository when creating a fork with POST /repos/{owner}/{repo}/forks (f300f8a)GET /repos/{owner}/{repo}/code-scanning/analyses/{analysis_id}, handle it as JSONsort by number for GET /repos/{owner}/{repo}/code-scanning/alerts as deprecatedYour coding agent can read these notes before it upgrades. Set up the MCP server →