NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2239 most downloaded on npm
GitHub REST API client for Node.js
Last release 11 months ago
31 Oct 2025
Release timing varies
gaps range from 2 weeks to 5 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
302 releases · first in 2018
Node 8 is out of maintenance since Jan 2020: https://nodejs.org/en/about/releases/. We no longer test against it
One column per quarter.
TypeScript: named { Octokit } export
deprecate octokit.gitdata.*, octokit.pullRequests.*
## 16.42.2 (2020-02-03) ### Bug Fixes * recover Octokit.plugin
do not throw if using deprecated Octokit default export without options
deprecate const Octokit = require("@octokit/rest") in favor of const { Octokit } = require("@octokit/rest")
package: update @octokit/plugin-rest-endpoint-methods to version 2.3.0 (a10ef70), closes #1571
package: update @octokit/plugin-rest-endpoint-methods to version 2.2.0
typescript: types for latest Action endpoint methods
typescript: new auth strategy options
typescript: descripion & response types fixes
# 16.40.0 (2020-01-28) ### Features * Actions endpoint methdos
accessing response.data[namespacekey] in .paginate(options, mapFn) map function now logs a deprecation
## 16.38.3 (2020-01-25) ### Bug Fixes * typescript: .git.getTree types
add .endpoint() method to all deprecated endpoint methods
typescript: authStrategy key in Octokit constructor options
authStrategy key in Octokit constructor options (fb19f11)Setting auth to an object or a basic authentication string is now deprecated and will be removed in v17
@octokit/auth are now supported. Setting auth to an object or a basic authentication string is now deprecated and will be removed in v17 (4573ee2)rename & deprecation of endpoint methods using /teams/:team_id* path internally. The are being replaced by *ForOrg methods that use /orgs/:org/teams/:…
.apps.revokeInstallationToken() (ed31137).migrations.listReposForOrg(), .migrations.listReposForUser() (8777073).repos.listForOrg()'s type parameter can now be set to "internal" (GitHub Enterprise Cloud only) (9c71d18)visibility parameter for .repos.createForAuthenticatedUser() and .repos.createInOrg() (31b094b)delete_branch_on_merge parameter for .repos.createForAuthenticatedUser(), .repos.createInOrg(), .repos.update() (c783249).orgs.update(): members_can_create_internal_repositories, members_can_create_private_repositories, members_can_create_public_repositories (7be5174).repos.updateBranchProtection(): allow_deletions, allow_force_pushes, required_linear_history (c5632ff)/teams/:team_id* path internally. The are being replaced by *ForOrg methods that use /orgs/:org/teams/:team_slug* internally. With the next breaking version, the *ForOrg suffix will be removed using another deprecation. (faecc99)typescript: deprecate client options
## 16.35.2 (2019-12-13) ### Bug Fixes * correct typo in test/util.js
## 16.35.1 (2019-12-13) ### Bug Fixes * submitted_at for pr review
See also: https://developer.github.com/changes/2019-11-05-deprecated-passwords-and-authorizations-api/
.apps.checkAuthorization().apps.checkToken().apps.deleteAuthorization().apps.deleteToken().apps.resetAuthorization().apps.resetToken().apps.revokeAuthorizationForApplication().apps.revokeGrantForApplication().apps.checkAuthorization().apps.resetAuthorization().apps.revokeAuthorizationForApplication().apps.revokeGrantForApplication().oauthAuthorizations.checkAuthorization.oauthAuthorizations.createAuthorization.oauthAuthorizations.deleteAuthorization.oauthAuthorizations.deleteGrant.oauthAuthorizations.getAuthorization.oauthAuthorizations.getGrant.oauthAuthorizations.getOrCreateAuthorizationForApp.oauthAuthorizations.getOrCreateAuthorizationForAppAndFingerprint.oauthAuthorizations.listAuthorizations.oauthAuthorizations.listGrants.oauthAuthorizations.resetAuthorization.oauthAuthorizations.revokeAuthorizationForApplication.oauthAuthorizations.revokeGrantForApplication.oauthAuthorizations.updateAuthorizationSee also: https://developer.github.com/changes/2019-11-05-deprecated-passwords-and-authorizations-api/
.repos.listTopics() & .repos.replaceTopics(): required mercy preview header set by defaulttypescript: Include done callback in Paginate interface
remove obsolete plugin to normalize git reference responses
include details in server validation error
# 16.33.0 (2019-10-08) ### Features * options: add timeZone option
types: add deprecation jsdoc for deprecated methods
deprecated: Show a message for deprecated methods
search: remove extra octokit prefix (07514ae), closes #1481
typescript: allow mediaType option in endpoint methods (be7e388), closes probot/probot#1024
mediaType option in endpoint methods (be7e388), closes probot/probot#1024`octokit.pulls.createFromIssue() is deprecated. Use `octokit.pulls.create() instead
add deprecation messages for octokit.teams.{add,get,remove}Member()
luke-cage header is not required (9926988)restrictions.teams and restrictions.users are required for `octokit.repos.updateBranchProtection() (d68aa77)octokit.teams.{add,get,remove}Member() (f4e0a1b)privacy parameter for octokit.teams.edit() (71ba2ae)octokit.repos.getCommit() (9164417)page/per_page parameters from PATCh requests (6395735)page/per_page parameters from POST requests (a7a45ac)page and per_page parameters from octokit.repos.listProtectedBranchTeamRestrictions() (3c04006)octokit.pulls.createReviewCommentReply() (c7831d3)octokit.pulls.createCommentReply() has been renamed to octokit.pulls.createComment() (b59f0b5)octokit.repos.listProtectedBranchTeamRestrictions & octokit.repos.listTeamsWithAccessToProtectedBranch -> octokit.repos.getTeamsWithAccessToProtectedBranch (9e3b5b1)octokit.repos.listProtectedBranchUserRestrictions & octokit.repos.listUsersWithAccessToProtectedBranch -> octokit.repos.getUsersWithAccessToProtectedBranch (5896712)octokit.repos.addProtectedBranchAppRestrictions(), octokit.repos.removeProtectedBranchAppRestrictions(), octokit.repos.replaceProtectedBranchAppRestrictions() (542c7e7)octokit.repos.createDispatchEvent() (eee4ae6)octokit.repos.listAppsWithAccessToProtectedBranch() -> octokit.repos.getAppsWithAccessToProtectedBranch() (4d4fe03)package: update universal-user-agent to version 4.0.0
package: remove unused url-template dependency
normalize pagination for "List installations for a user" endpoint
name parameter is not required for .repos.update()
"owner" parameter is no longer conflicting in octokit.repos.createUsingTemplate()
package: update universal-user-agent to version 3.0.0
package: before-after-hook at v2.0.0
## 16.28.2 (2019-06-17) ### Bug Fixes * typo in deprecation warnings
add "rocket" and "eyes" to set of supported reactions
commit_sha parameter for repos.listCommentsForCommit() and repos.createCommitComment()`
typescript: Octokit#plugin argument type for plugins
author.* and committer.* parameter validation for .repos.deleteFile()
typo in deprecation message for .repos.getCommitRefSha()
octokit.repos.getCommitRefSha() is deprecated, use octokit.repos.getCommit() instead
.repos.enableVulnerabilityAlerts()
.repos.enableVulnerabilityAlerts().repos.disableVulnerabilityAlerts()source parameter for .repos.enablePagesSite()package: update @octokit/request to version 4.0.1
package: update deprecation to version 2.0.0
package: update @octokit/request to version 3.0.3
package: update @octokit/request to version 3.0.2
do not mutate options passed to endpoint methods
package: update @octokit/request to version 3.0.1
apps.deleteInstallation({ installation_id })
throw 400 Bad Request error when octokit.issues.get() without parameters
implement deprecation for parameters in .endpoint() and .endpoint.merge()
:commit_sha parameter for .git.getCommit(). Deprecates :sha
# ⚠️ This release has a bug, see #1323 Update to v16.24.1 instead.
.paginate() with results namespace (GET /installation/repositories, single page response)
Your coding agent can read these notes before it upgrades. Set up the MCP server →