NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3910 most downloaded on npm
See https://github.com/Redocly/redocly-cli
Last release 4 days ago
30 Sep 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
777 releases · first in 2020
One column per quarter.
Updated @redocly/openapi-core to v2.57.0.
Added const checking to the no-enum-type-mismatch rule: a const value must conform to the schema's type, the same way every enum value does.
Note: linting output may include new errors for schemas whose const value doesn't match their type.
no-enum-type-mismatch dropped violations and reported a wrong location when type was written as an array.Updated @redocly/openapi-core to v2.56.1.
Updated undici to the 6.29.0 version.
undici to the 6.29.0 version.respect failed with an unexpected error when a step used an operationId without the $sourceDescriptions.<name>. prefix and the Arazzo file also listed an arazzo source description.operationIds are looked up in the openapi source descriptions only.bundle command output.--overlay option or list them under overlays for an API in redocly.yaml.copy action field, the $self field, and reusable actions in components.actions.spec-ref-siblings rule now checks the fields next to a reusable action $ref in Overlay documents.Added the --replace option to the push command. --replace removes the files under the mount path that are not part of the push.
--replace option to the push command.--replace removes the files under the mount path that are not part of the push.respect so known secrets are masked in non-JSON request bodies, such as application/x-www-form-urlencoded token requests.respect so a step fails with a clear error when a runtime expression embedded in a string has no value, such as Bearer {$outputs.accessToken}.workflow-dependsOn rule reported a duplicate when different workflows listed the same workflow in dependsOn.--replace option to the push command.--replace removes the files under the mount path that are not part of the push.respect so known secrets are masked in non-JSON request bodies, such as application/x-www-form-urlencoded token requests.respect so a step fails with a clear error when a runtime expression embedded in a string has no value, such as Bearer {$outputs.accessToken}.workflow-dependsOn rule reported a duplicate when different workflows listed the same workflow in dependsOn.Added the value of the REDOCLY_ENVIRONMENT environment variable to the user-agent header of the login , push , and push-status requests.
REDOCLY_ENVIRONMENT environment variable to the user-agent header of the login, push, and push-status requests.application/gzip, application/x-tar), PDF files, Office documents, audio, video and font responses as JSON instead of decoding them as binary.REDOCLY_ENVIRONMENT environment variable to the user-agent header of the login, push, and push-status requests.Updated @redocly/config to v0.57.0.
Nothing published for this version
Nothing published for this version
Fixed respect so a same-workflow goto no longer cleared $steps outputs from steps that already ran. Previously, this broke $steps expressions in the t
respect so a same-workflow goto no longer cleared $steps outputs from steps that already ran.Added start and end line and column positions to each problem location in the --format=json lint output.
start and end line and column positions to each problem location in the --format=json lint output.Added a deprecation warning to the build-docs command about the upcoming switch to Redoc 3.
build-docs command about the upcoming switch to Redoc 3.Updated @redocly/openapi-core to v2.53.0.
disallowDefault option to the operation-2xx-response rule, which requires an explicit 2xx response when enabled.disallowDefault option to the operation-2xx-response rule, which requires an explicit 2xx response when enabled.Updated @redocly/openapi-core to v2.52.1.
redoc to the 2.5.4 version to fix accessibility problems in the HTML produced by build-docs.lang attribute to the default build-docs template.Updated @redocly/openapi-core to v2.52.0.
strategy option to the component-name-unique rule, matching the --component-names-strategy option of the bundle command.redocly-cli for everyday CLI usage, redocly-lint-rules for writing configurable rules and custom plugins.npx skills add https://redocly.com.inspect-node-types command to navigate the Redocly's node type tree of an API description.inspect-node-types helps pick the correct subject types for a configurable rule or the correct visitor for a custom plugin.strategy option to the component-name-unique rule, matching the --component-names-strategy option of the bundle command.introspect-mcp command that analyzes a running MCP server and records its tools, prompts, resources, and capabilities.introspect-mcp records its findings in the x-mcp extension of an OpenAPI description.Updated @redocly/openapi-core to v2.51.2.
fast-uri to the 3.1.7 version to resolve CVE-2026-75931, CVE-2026-75975, CVE-2026-75899, and CVE-2026-76172.drift and coverage failing to match a path template whose segment mixes literal text with parameters, such as /instances/{worldId}:{instanceId}.Fixed an issue where generate-arazzo produced a malformed remote description URL in sourceDescriptions ( https:// collapsed to https:/ ) when --output
generate-arazzo produced a malformed remote description URL in sourceDescriptions (https:// collapsed to https:/) when --output-file was provided.$faker.string.email() used without options generated addresses at the undefined.com domain.@faker-js/faker to the 10.6.0 version to resolve the high severity advisory GHSA-qxc2-j82w-r537.Fixed an issue where respect and the x-security-scheme-required-values rule incorrectly rejected x-security HTTP schemes written with non-lowercase ca
respect and the x-security-scheme-required-values rule incorrectly rejected x-security HTTP schemes written with non-lowercase casing (such as Basic, Bearer, or Digest).generate-arazzo command to print a ready-to-run respect command after generation, including an --input placeholder for every workflow input.--with-ai, --ai-provider, --ai-model, --ai-concurrency, and --max-workflows options to the generate-arazzo command.--with-ai uses a local AI CLI (claude, codex, or cursor) and OpenAPI descriptions to redesign the generated one-workflow-per-operation skeleton into multi-step workflows.--max-workflows workflows (default 10), and the generated file is marked as AI-inferred.respect and the x-security-scheme-required-values rule incorrectly rejected x-security HTTP schemes written with non-lowercase casing (such as Basic, Bearer, or Digest).Updated @redocly/openapi-core to v2.50.0.
schema assertion for configurable rules.schema assertion for configurable rules.Updated @redocly/openapi-core to v2.49.1.
$refs pointed to the same path item.Added the no-illogical-composition-keywords rule.
Added the no-illogical-composition-keywords rule.
Note: the rule is set to warn in the recommended ruleset and to error in recommended-strict. Existing API descriptions may report new problems.
npm was not available.Updated @redocly/openapi-core to v2.48.0.
bundle command didn't resolve $refs inside an AsyncAPI 3 Multi Format Schema Object.python, go, php, and cli generators beside the TypeScript client, each self-documenting with --docs, configurable per generator, and available as source in your own repository through eject-generator.bundle command didn't resolve $refs inside an AsyncAPI 3 Multi Format Schema Object.respect --har-output recorded an empty postData for every request.drift can have their request bodies validated instead of silently passing.Updated @redocly/openapi-core to v2.47.0.
stats command that reports how many distinct x- extensions a description file uses and how often each one occurs.stats command reporting wrong parameter count for AsyncAPI descriptions.stats command that reports how many distinct x- extensions a description file uses and how often each one occurs.stats command reporting wrong parameter count for AsyncAPI descriptions.Updated @redocly/openapi-core to v2.46.2.
Improved the error message raised when a configurable rule is missing the assertions block.
Fixed an issue where the no-duplicated-enum-values rule didn't report duplicated enum values that are objects or arrays.
Fixed an issue where the no-duplicated-enum-values rule printed [object Object] when reporting duplicate values.
Updated @redocly/ajv to ^8.18.3.
@redocly/ajv to ^8.18.3.Updated @redocly/openapi-core to v2.46.0.
spec-ref-siblings rule that reports properties placed next to a $ref which the specification does not allow.spec-ref-siblings rule that reports properties placed next to a $ref which the specification does not allow.Updated @redocly/openapi-core to v2.45.0.
bundle command losing schema keywords (such as title, properties, or required) written next to a $ref when the referenced schemas started with their own $ref.bundle command losing schema keywords (such as title, properties, or required) written next to a $ref when the referenced schemas started with their own $ref.Updated @redocly/openapi-core to v2.44.2.
security-defined rule for AsyncAPI 2.x and 3.x in the recommended ruleset from error to warn.
AsyncAPI descriptions with undefined or unresolved security no longer fail linting by default.security-defined rule for AsyncAPI 2.x and 3.x in the recommended ruleset from error to warn.
AsyncAPI descriptions with undefined or unresolved security no longer fail linting by default.Updated @redocly/openapi-core to v2.44.1.
operation-4xx-problem-details-rfc7807 rule incorrectly reported the type and title properties inherited through allOf as missing.undici to the 6.28.0 version.operation-4xx-problem-details-rfc7807 rule incorrectly reported the type and title properties inherited through allOf as missing.Updated @redocly/openapi-core to v2.44.0.
Added the no-duplicated-enum-values rule that requires all values in an enum to be unique.
The rule is enabled at the warn level in the recommended ruleset.
Note: linting output may include new warnings for API descriptions that contain duplicated enum values.
Added the no-unsafe-markdown rule that disallows potentially executable content in description fields.
The rule is enabled at the warn level in the recommended ruleset.
Note: linting output may include new warnings for description fields that contain potentially executable content.
Added security-defined rule for AsyncAPI 2.x and 3.x.
Warning: this rule is enabled at error severity in the recommended ruleset, so AsyncAPI documents that previously linted clean may now fail. The rule flags security $refs that target an undefined scheme or a path outside components.securitySchemes, and operations that declare no security of their own when the applicable servers don't supply one either.
Added the no-duplicated-enum-values rule that requires all values in an enum to be unique.
The rule is enabled at the warn level in the recommended ruleset.
Note: linting output may include new warnings for API descriptions that contain duplicated enum values.
Added the no-unsafe-markdown rule that disallows potentially executable content in description fields.
The rule is enabled at the warn level in the recommended ruleset.
Note: linting output may include new warnings for description fields that contain potentially executable content.
Fixed an issue where secrets masking did not cover encoded secrets in har-output.
har-output.Updated @redocly/openapi-core to v2.43.2.
Updated @redocly/openapi-core to v2.43.1.
skipPluginEval to keep extends unresolved instead of failing when the config extends a plugin preset.Updated @redocly/openapi-core to v2.43.0.
skipPluginEval option to loadConfig that resolves plugin paths without importing or executing plugin code — the returned plugins contain only their absolutePath.Updated @redocly/openapi-core to v2.42.0.
generate-client command that generates a typed, zero-dependency TypeScript client from an OpenAPI description — auth, retries, middleware, typed SSE streaming, pagination, and multipart included — plus optional companion generators for Zod validation, TanStack Query and SWR hooks, MSW mocks, and date transformers.
See the generate-client command reference and the Use the generated client guide.generate-client command that generates a typed, zero-dependency TypeScript client from an OpenAPI description — auth, retries, middleware, typed SSE streaming, pagination, and multipart included — plus optional companion generators for Zod validation, TanStack Query and SWR hooks, MSW mocks, and date transformers.
See the generate-client command reference and the Use the generated client guide.Added support for the Arazzo spec-compliant workflow reference form $sourceDescriptions. . in dependsOn, step workflowId, and success/failure action w
Added support for the Arazzo spec-compliant workflow reference form $sourceDescriptions.<name>.<workflowId> in dependsOn, step workflowId, and success/failure action workflowId.
Unresolvable workflow references fail only the affected workflow with a clear error message, and no longer abort the whole run or pass unnoticed.
Updated @redocly/openapi-core to v2.41.2.
5.2.1 to 5.2.2 to resolve a vulnerability in YAML parsing.Updated js-yaml from 5.2.1 to 5.2.2 to resolve a vulnerability in YAML parsing.
Added support for the Arazzo spec-compliant workflow reference form $sourceDescriptions.<name>.<workflowId> in dependsOn, step workflowId, and success/failure action workflowId.
Unresolvable workflow references fail only the affected workflow with a clear error message, and no longer abort the whole run or pass unnoticed.
Updated @redocly/openapi-core to v2.41.2.
Updated @redocly/respect-core to v2.41.2.
Updated @redocly/openapi-core to v2.41.1.
drift command's schema-consistency rule reported false-positive findings for oneOf schemas with a discriminator.
Payloads are validated only against the branch selected by the discriminator value instead of every oneOf branch.
Schemas whose discriminator does not meet Ajv's structural requirements keep the previous behavior.drift command's built-in undocumented-header ignore list with x-amz-, x-amzn- and x-github- prefixes, and the x-hub-signature / x-hub-signature-256 webhook signature headers.Fixed an issue in respect where the execution of parent workflow's steps didn't halt after a step that referenced another workflow had failed.
respect where the execution of parent workflow's steps didn't halt after a step that referenced another workflow had failed.security-scopes-defined that requires every scope used in a security requirement to be defined in the corresponding OAuth2 security scheme.
The rule supports OpenAPI 2.0/3.x and AsyncAPI 2.6/3.0, suggests the closest defined scope for typos, and has an opt-in requireScopes option that requires OAuth2 security requirements to list at least one scope.security-scopes-defined that requires every scope used in a security requirement to be defined in the corresponding OAuth2 security scheme.
The rule supports OpenAPI 2.0/3.x and AsyncAPI 2.6/3.0, suggests the closest defined scope for typos, and has an opt-in requireScopes option that requires OAuth2 security requirements to list at least one scope.respect where the execution of parent workflow's steps didn't halt after a step that referenced another workflow had failed.cursor AI provider of the generate-spec command sent only the instructions to the model and the operation to refine never reached it.Updated @redocly/openapi-core to v2.40.0.
dataValue field.Updated @redocly/config to v0.52.0.
Updated js-yaml from 4.2.0 to 5.2.1.
Fixed an issue where strings that look like numbers with underscores (for example '12_34') had quotation marks removed by the bundle command.
These strings stay quoted in the output.
Note: YAML parsing is stricter: a multi-line flow collection whose closing bracket is not indented deeper than its parent key is now a parse error. Parse errors are reported at the offending token instead of the end of the document.
Fixed an issue where the bundle command rewrote internal $refs pointing to other $refs.
The issue caused AsyncAPI 3 operation messages references to point to components instead of channel messages.
--ignore-headers option to the experimental drift and proxy commands.
It takes a comma-separated list of header names to skip in undocumented-header checks, and a trailing * matches by prefix (for example x-consumer-*).
Use it to silence headers a gateway or proxy adds that are not part of the API contract.generate-spec command that infers an OpenAPI description from recorded HTTP traffic.Fixed the drift command's schema-consistency rule reporting false-positive "Undocumented query parameter" findings for deepObject-style query parameters.
Traffic keys like namespace[id]=...&namespace[name]=... are now matched to the documented namespace parameter, and the reconstructed object is validated against the parameter schema.
Fixed an issue where the drift command's schema-consistency rule reported false-positive request findings for exchanges the server rejected with a 4xx client error.
For example: missing required parameter, missing required body, request-body schema mismatch.
A 4xx response means the server never accepted the request.
Validating it against the operation's success-path contract flagged the server's own correct rejection as drift.
Response-side validation still runs, so a documented error response whose shape differs from reality is still reported.
Fixed an issue where the join command silently dropped path-level x-* extensions with non-string values.
Updated js-yaml from 4.2.0 to 5.2.1.
Fixed an issue where strings that look like numbers with underscores (for example '12_34') had quotation marks removed by the bundle command.
These strings stay quoted in the output.
Note: YAML parsing is stricter: a multi-line flow collection whose closing bracket is not indented deeper than its parent key is now a parse error. Parse errors are reported at the offending token instead of the end of the document.
Fixed an issue where the drift command's security-baseline rule reported false-positive "credential exposure over insecure HTTP transport" warnings for traffic captured against loopback hosts, for example: localhost, *.localhost, 127.0.0.0/8, [::1].
Sandboxed recordings no longer produce transport warnings.
Fixed an issue where the bundle command rewrote internal $refs pointing to other $refs.
The issue caused AsyncAPI 3 operation messages references to point to components instead of channel messages.
Updated @redocly/openapi-core to v2.40.0.
Updated @redocly/openapi-core to v2.39.0.
struct rule to validate the contents of AsyncAPI protocol-specific bindings.
Added typed definitions for the sns, sqs, ibmmq, googlepubsub, pulsar and ros2 bindings.struct rule to validate the contents of AsyncAPI protocol-specific bindings.
Added typed definitions for the sns, sqs, ibmmq, googlepubsub, pulsar and ros2 bindings.Updated @redocly/openapi-core to v2.38.0.
drift command that compares recorded HTTP traffic (HAR, Kong, Nginx/Apache JSON, NDJSON) against an OpenAPI description and reports undocumented endpoints, schema mismatches, and security findings.proxy command that captures live HTTP traffic through a reverse proxy into a HAR file and optionally validates it against an OpenAPI description in real time.Updated @redocly/openapi-core to v2.37.0.
.graphql / .gql)..graphql / .gql).Updated @redocly/config to v0.49.1.
build-docs, ensuring the script's integrity.Updated @redocly/openapi-core to v2.35.1.
Updated @redocly/openapi-core to v2.35.0.
lint command.spec-step-mutually-exclusive-fields Arazzo rule to flag steps that use more than one mutually exclusive operation field (operationId, operationPath, workflowId, channelPath, or x-operation).Updated @redocly/openapi-core to v2.34.0.
Improved CLI install speed by bundling the CLI into a dependency-free package.
Warning: The published package no longer ships runtime dependencies in node_modules.
Plugins that relied on importing packages hoisted from the CLI (such as @redocly/openapi-core) must now declare those packages as their own dependencies.
Updated @redocly/openapi-core to v2.33.2.
split command that might have written files outside the chosen --outDir.Updated @redocly/openapi-core to v2.33.1.
4.1.1 to 4.2.0.Fixed a remote code execution vulnerability where a crafted $faker expression in an Arazzo description could execute arbitrary JavaScript during Redoc…
$faker expression in an Arazzo description could execute arbitrary JavaScript during Redocly Respect runs.
Reported by Hamza Haroon (GitHub: @thegr1ffyn).--component-names-strategy option to the bundle command.
This option allows a choice of how inline Schema components are named: basename (default) or title (from each schema's title field).--component-names-strategy option to the bundle command.
This option allows a choice of how inline Schema components are named: basename (default) or title (from each schema's title field).Fixed respect schema checks to honor readOnly and writeOnly based on context.
Fixed respect schema checks to honor readOnly and writeOnly based on context.
Warning: writeOnly properties in responses are reported as errors.
Updated @redocly/openapi-core to v2.32.2.
Updated @redocly/openapi-core to v2.32.1.
Added support for junit output in the lint command.
junit output in the lint command.junit output in the lint command.Updated @redocly/openapi-core to v2.31.6.
lint --format=checkstyle to produce a single combined XML document when multiple APIs are passed to the command, instead of concatenated per-file documents.Updated @redocly/openapi-core to v2.31.5.
Updated the no-unused-components rule to validate unused security schemes.
Fixed the remove-unused-components decorator to remove unused security schemes.
Warning: The bundler may now remove more unused components than before.
Updated the no-unused-components rule to validate unused security schemes.
Pinned the official Docker image base to node:24-alpine.
Fixed the remove-unused-components decorator to remove unused security schemes.
Warning: The bundler may now remove more unused components than before.
Updated @redocly/openapi-core to v2.31.5.
Fixed an issue where running respect on multiple Arazzo files in a single invocation could surface false-positive struct lint errors.
respect on multiple Arazzo files in a single invocation could surface false-positive struct lint errors.Updated @redocly/openapi-core to v2.31.3.
HTTP_PROXY, HTTPS_PROXY, and NO_PROXY environment variables when loading remote source descriptions or resolving external $refs.
Proxy settings are consistently applied during reference resolution as well.Updated @redocly/openapi-core to v2.31.2.
Fixed the remove-unused-components decorator to remove unused components containing allOf keyword.
Warning: The bundler may now remove more unused components than before.
Fixed the no-unused-components rule to highlight unused schemas containing allOf keyword.
Fixed the remove-unused-components decorator to remove unused components containing allOf keyword.
Warning: The bundler may now remove more unused components than before.
Fixed the no-unused-components rule to highlight unused schemas containing allOf keyword.
Updated @redocly/openapi-core to v2.31.2.
Updated @redocly/openapi-core to v2.31.1.
Updated @redocly/openapi-core to v2.31.0.
Updated @redocly/openapi-core to v2.30.6.
Fixed an issue where query-language strings (JSONPath, XPath, SPARQL, OPA) in Respect request bodies were incorrectly treated as runtime expressions.
redocly.yaml caused a config validation error during the build.--har-output option in the respect command.Your coding agent can read these notes before it upgrades. Set up the MCP server →