NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3544 most downloaded on npm
GitHub webhook events toolset for Node.js
Last release 10 months ago
03 Dec 2025
Release timing varies
gaps range from 9 days to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
9 years old
286 releases · first in 2017
types: new projects_v2_item event
types: webhooks types updates via `@octokit/webhooks` v5.6.0
@octokit/webhooks v5.6.0 (#677) (637603b)One column per quarter.
types: new repository_vulnerability_alert.reopen event, remove workflow_job.started event, and many other type updates for events via @octokit/webhook…
types: updates to deployment and deployment_status events, new deployment property for check_run event
types: new changes.base property on pull_request#edited, new merged_at property on issues common schema, new rerequestable property on check_suite#com
types: new pull_request_review_thread event
update @octokit/webhooks-types to v4.16
types: description updates for the workflow_run event
types: multiple updates from `@octokit/webooks-types@4.12.0`
@octokit/webooks-types@4.12.0 (#650) (aa9570e)types: add missing event workflow_job.in_progress, description updates for push event payload properties
types: add ability to remove onAny listeners again
types: add missing workflow_job.queued event
types: allow non-truthy values in generated output
## 9.14.1 (2021-09-05) ### Bug Fixes * handle invalid URL
# 9.14.0 (2021-09-03) ### Features * export emitterEventNames
types: new branch_protection_rule event
# 9.12.0 (2021-08-06) ### Features * add workflow_job event
types: updates to Installation and Commit common interfaces, updates to MemberAdded, RepositoryVulnerabilityAlertResolve, RepositoryEdited events
typescript: export the EmitterWebhookEventName type
types: new labeled & unlabeled actions for DiscussionEvent, Discussion#state can be converting, active_lock_reason can be null in DiscussionLockedEven
types: add new properties for the Container registry to PackageEvent
remove all whitespace when stringifying a webhook event payload object to a JSON string for verifycation
types: add changes object for IssuesTransferredEvent and for IssuesOpenedEvent when the issue is transferred (#592) (7d6a81d), closes #590 #591
bump @octokit/webhooks-methods to ^2.0.0
octokit.verifyAndReceive() accepts raw string payload
update {App, Installation}#permissions with additional permissions, add changes property to RepositoryRenamedEvent, ReleaseAsset#label can be null, In
{App, Installation}#permissions with additional permissions, add changes property to RepositoryRenamedEvent, ReleaseAsset#label can be null, Installation#suspended_{at, by} are always present, fix WorkflowRun#pull_requests is not PullRequest[] but a simpler type (01891fc)typescript: issue_comment event description update
types: add missing properties to events, update properties types (via `@octokit/webhooks-types` v3.75.1)
@octokit/webhooks-types v3.75.1) (#570) (a2fd414)types: PullRequest#body can be of type string or null, Release#{body, name} are only of type string
types: fix workflow_run#conclusion is not always null, add new app_id to MarketplacePurchase#account, add requester to installation_repositories.remov
types: an issue's body can be empty and thus be null (#562) (7cb03b3), closes #561
types: new withdrawn action for security_advisory event
types: requester in InstallationRepositoriesAddedEvent can be null and is now set as required, closed_at in IssueCommentEvent isn't always null
types: add missing permissions in Installation#removed, add null to various properties, list all events instead of string[] in Installation#events, ad
types: add new changes property to ProjectColumnEditedEvent and make ProjectCard#content_url optional
types: update properties in PullRequestReviewCommentEvent and WorkflowRunDispatchEvent
update some property types with new information
update package to use new packages split from @octokit/webhooks-defintions
middleware: pass on to the next middleware in case of express
deprecated path option for Webhooks constructor has been removed. Use createNodeMiddleware(webhooks, { path }) instead
createWebhooksApi() has been removed. Use new Webhooks() instead
webhooks.middleware has been removed. Use createNodeMiddleware() instead
createMiddleware has been removed. Use createNodeMiddleware() instead
deprecated path option for Webhooks constructor has been removed. Use createNodeMiddleware(webhooks, { path }) instead
all usage of debug has been removed. Use the log option instead
webhooks.sign now default to sha256 algorithm. In order to continue to use sha1, replace
webhooks.sign(secret, payload)
with
webhooks.sign({ secret, algorith: "sha1" }, payload)
webhooks.sign() and webhooks.verify() are now asynchronous
static sign and verify methods are no longer exported. Use @octokit/webhooks-methods package instead
testing deno compatibility be removing import from "http"
"http" (662f35c)webhooks.sign() and webhooks.verify() are now asynchronous
webhooks.sign() and webhooks.verify() are now asynchronoussign and verify methods are no longer exported. Use @octokit/webhooks-methods package insteaduse options.onUnhandledRequest in createNodeMiddleware(webhooks, options)
options.onUnhandledRequest in createNodeMiddleware(webhooks, options) (b2fbbb5)sign and webhooks.sign no default to sha256 algorithm. In order to continue to use sha1, replace
sign and webhooks.sign no default to sha256 algorithm. In order to continue to use sha1, replacesign(secret, payload)
with
sign({ secret, algorithm: "sha1" }, payload)
deprecated path option for Webhooks constructor has been removed. Use createNodeMiddleware(webhooks, { path }) instead
debug has been removed. Use the log option insteadpath option for Webhooks constructor has been removed. Use createNodeMiddleware(webhooks, { path }) insteadwebhooks.middleware has been removed. Use createNodeMiddleware() insteadcreateMiddleware has been removed. Use createNodeMiddleware() insteadcreateWebhooksApi() has been removed. Use new Webhooks() insteadcorrect spelling error in DiscussionTransferredEvent event name
typescript: username property on Committer can be not present #530)
typescript: add some missing properties to event payloads
typescript: add new is_one_time and is_custom_ammount to SponsorshipTier
types: allow IncomingMessage to have bodies of other types
use options.onUnhandledRequest in createNodeMiddleware(webhooks, options)
typescript: add new DiscussionEvent and DiscussionCommentEvent types, fix types for Installation#requester to be User and not null
typescript: remove description from objects in order to stop duplication
typescript: compile-time error when missing secret option
# 8.9.0 (2021-03-30) ### Features * createNodeMiddleware()
remove null override on IssueCommentEditedEvent#issue.closed_at
typescript: update description for GollumEvent
typescript: default TTransformed in Webhooks type parameter to unknown
# 8.8.0 (2021-03-28) ### Features * deprecate createWebhooksApi()
typescript: improve type of WorkflowRun#conclusion property
Your coding agent can read these notes before it upgrades. Set up the MCP server →