Skip to content

v2.0.0

Choose a tag to compare

@github-actions github-actions released this 27 May 01:48
· 147 commits to main since this release
v2.0.0
4ce47a9

Restish v2.0.0 is a major redesign of the REST-ish HTTP CLI, with a new Go codebase, stronger OpenAPI command generation, typed JSONC config, safer auth/config handling, improved output/filtering/pagination behavior, and first-party plugin support.

Highlights:

  • New v2 module path: github.com/rest-sh/restish/v2
  • Improved generic HTTP and generated OpenAPI workflows
  • Automatic v1 config migration for standard config locations
  • New out-of-process plugin system, including CSV, MCP, bulk, and PKCS#11 plugins
  • Refreshed docs, install guide, v1 upgrade guide, and interactive tour

This is a breaking major release. Users upgrading from v1 should read the upgrade guide before switching production workflows.

See more at https://rest.sh/docs/getting-started/tour/

Changelog

  • 2d92b74 Merge pull request #331 from rest-sh/v2
  • 3b30aba build(output): add OCI image packaging
  • 1ce964a build: bump shorthand/v2 to 2.3.0
  • 3cea485 build: move module path to github.com/rest-sh/restish/v2
  • 5cd809e build: preserve v1 release archive names
  • 0af3be4 build: update docker ignore patterns
  • bfd79df chore(auth): cache OAuth tokens in memory
  • 5b3e77a chore(auth): design OpenAPI credential auth model
  • 3fb6f63 chore(auth): enforce profile selection and auth hooks
  • a94b74e chore(auth): list supported auth types in errors
  • f1ad6c4 chore(auth): rename generated auth override flag
  • 63a483b chore(auth): strip query credentials on cross-host follows
  • 525a074 chore(auth): update credential storage hardening and permission warnings
  • 9024a75 chore(cache): encode response cache path components
  • b0babbb chore(cli): quiet non-request command help
  • 3d7a9c9 chore(cli): reframe v2 command surface decision
  • 6827a96 chore(cli): startup fast-path skips flags and recognizes built-in verbs
  • 8f3bf76 chore(cli): update aPI-name vs built-in command collision guard
  • 2a92bdc chore(cli): update centralized global-flag parsing
  • c225f5b chore(cli): update flag-completion registrations
  • c51692b chore(cli): update setup command correctness and UX improvements
  • 8d4e762 chore(config): lock config patch writes
  • 0cb641a chore(config): update config write safety and error quality
  • 8a59f6f chore(config): update unified directory and path helpers with XDG + Windows support
  • d8ae425 chore(config): use XDG-style config defaults on Unix
  • 58fe081 chore(config): write config files atomically
  • d8ef1c4 chore(deps): update shorthand to v2.4.0
  • 89ef7c4 chore(openapi): let spec loaders persist transformed ContentType and Raw
  • f590e28 chore(openapi): refresh cached specs when sources change
  • e5e527a chore(openapi): resolve refs before merging spec files
  • 26c3f47 chore(openapi): respect GLAMOUR_STYLE for Markdown rendering
  • 4f15624 chore(openapi): skip generated API loading for built-ins
  • e4ddf99 chore(openapi): spec-discovery error aggregation and deterministic reporting
  • e039605 chore(openapi): tidy generated command help-all output
  • 09a6377 chore(openapi): warn on broken generated specs and extra args
  • e19a317 chore(output): clarify raw and line output semantics
  • cff14fc chore(output): group help output for commands and global flags
  • 7ccab1f chore(output): highlight HTTP dates and paginated framed output
  • 774bd95 chore(output): stabilize verbose header output
  • 246518b chore(output): update phase 10 filter/content/output polish
  • 861f088 chore(output): update setupMarkdownHelp race safety
  • 12b3c18 chore(output): use readable formatting for streamed JSON output
  • bd59c60 chore(plugin): cache generated operations and parallelize bulk
  • 7145337 chore(plugin): cache plugin manifests between runs
  • 7fa4f14 chore(plugin): clarify safe plugin decoder usage
  • 619621d chore(plugin): close command plugin pipes on start failure
  • da0eb2e chore(plugin): require declared plugin hooks for extensions
  • 29c0f5f chore(plugin): unify formatter plugin streaming output
  • fba0d26 chore(plugin): update install and plugin paths to rest-sh module
  • 3ff1c55 chore(plugin): update phase 9 plugin subsystem cleanup
  • a7d7997 chore(retry): clarify retry help default
  • 739005f chore(stream): return status errors from links command
  • dd92a85 chore: Replace interface{} with any
  • 7871e5c chore: add basic AGENTS.md
  • 8e1e1f9 chore: address restish v2 review findings
  • 2953850 chore: clone only paginated wrapper paths
  • a7a5921 chore: colorize diagnostic labels
  • 13bc26a chore: ignore local test notes
  • e904fcf chore: log every verbose request through the shared transport
  • 9c8e352 chore: manage TLS signer subprocess lifecycle
  • b710873 chore: parse hints and multi-expression shorthand
  • 192bd26 chore: refine rsh-review skill
  • ccaa463 chore: remove unused link dependency
  • 7b4438e chore: remove v1 implementation for v2 import
  • a57c9a7 chore: reuse shared editor lookup for api edit
  • 788c7bd chore: scope OIDC endpoints to issuer path
  • 3a91cc6 chore: update confirmEdit safe-on-EOF; Enter-as-yes only on TTY
  • 06d764c chore: update examples using live endpoints
  • 3792251 chore: update runAPIEdit wires editor subprocess to c.Stdin/Stdout/Stderr
  • 2ccde52 chore: update shorthand.md full-depth rewrite
  • 7c95d1a chore: update signal handling, root context, ExitCodeError cause
  • f8e1481 chore: update unified Prompter interface
  • 5708a87 chore: update verbose -vv TLS details
  • db1ffe6 chore: use equal jitter for retries
  • 001f984 chore: use errors.Is for EOF checks
  • 865070a chore: use errors.Is for missing-file checks
  • 291ab6f ci: add dormant docs site deploy workflow
  • 6a9850a ci: add v2 validation workflow
  • 4ce47a9 ci: keep release workspace clean
  • 42b8ada ci: use releaser app for v2 publishing
  • e17ef31 docs(embed): document cache namespace safety
  • 3530554 docs(guide): add mise alternative method installation
  • 23fb21a docs(site): improve Restish command highlighting
  • 98828e6 feat(auth): add API key auth handler
  • 0254975 feat(auth): add api auth commands
  • a4ea588 feat(auth): add credential bindings to config
  • fa3d6c2 feat(auth): add curl-friendly auth get command
  • 760bb4d feat(auth): add operation credential metadata
  • 71cc480 feat(auth): add shared auth profiles and token helpers
  • 66a2a2d feat(auth): configure fallback operation credentials
  • fcb8723 feat(auth): create token cache temp files securely
  • 2e96184 feat(auth): extend x-cli-config credentials
  • 9262bc5 feat(auth): overhaul oauth flows and handler context
  • 7265523 feat(auth): select operation credentials for generated requests
  • 30d0185 feat(auth): show values in auth inspect
  • 944b695 feat(auth): support credentials in auth inspect
  • e0a0e7d feat(cli): add cert command and TLS options
  • f685809 feat(cli): add edit command
  • a7984a6 feat(cli): add shell completion and setup command
  • eb1efb2 feat(cli): add shell completion installers
  • 358dd88 feat(cli): expose help-all in focused help
  • a569e2f feat(cli): finish phase 4 command polish
  • 01650b5 feat(cli): finish phase 6 polish
  • 41ab96f feat(cli): improve v1 migration ergonomics
  • c0f977e feat(cli): infer POST for bare URL bodies
  • 0e1bdee feat(cli): let embedders disable signal handling
  • 3b3075f feat(cli): overhaul response output
  • 64ac36c feat(cli): polish v2 command diagnostics
  • 83a3234 feat(config): add API management subcommands (configure/show/edit/set/sync/content-types)
  • 7575295 feat(config): add auto-pagination with streaming, collect mode, and per-API config
  • 1de9d1e feat(config): add configurable output themes and GitHub shorthand names
  • 72e847d feat(config): add explicit config file selection
  • a92ab4a feat(config): expand config show summary
  • 5b2fbcc feat(config): make retry wait caps configurable
  • aedc3cd feat(config): migrate v1 config on first v2 load
  • b3eb1d3 feat(config): support shorthand config patches
  • ce63a41 feat(config): wire CacheConfig.MaxSize into HTTP cache budget
  • 5ae21f4 feat(docs): generate reference drift checks
  • 4e1f2cd feat(doctor): expand support bundle output
  • 4329a16 feat(openapi): add generated security override
  • d525858 feat(openapi): implement focused generated help and tag layout
  • 95d1037 feat(openapi): load generated commands for targeted API only
  • 3a1e545 feat(openapi): render schemas in generated command help
  • e38c6da feat(openapi): support OpenAPI multipart encodings
  • e86cbb5 feat(openapi): support OpenAPI parameter serialization
  • 2f31273 feat(openapi): support external OpenAPI refs and server escapes
  • eda9e1f feat(output): add table, gron, cbor formatters; --rsh-silent; AddFormatter on CLI
  • bdbed89 feat(output): render markdown responses with Glamour
  • 256903f feat(plugin): add CBOR wire format and plugin helpers
  • 9b27296 feat(plugin): add CSV formatter plugin example
  • 64659f8 feat(plugin): add CommandClient for command plugin authors (P14)
  • a13cb49 feat(plugin): add HandleStartupFlags and Run entry-point helpers (P16)
  • 6aa6f8d feat(plugin): add MCP call timeout diagnostics
  • 0fe3387 feat(plugin): add MCP command plugin
  • da00eee feat(plugin): add PKCS#11 TLS signer plugin
  • 5f9f324 feat(plugin): add TLS signer plugin params
  • 4edb1c4 feat(plugin): add TLS signer plugin support
  • f0e27fc feat(plugin): add TerminalContext helper (P15)
  • 3b1568a feat(plugin): add WriteManifest and WriteCommands helpers (P13)
  • cf7b305 feat(plugin): add command plugin client helpers
  • f4a4843 feat(plugin): add command plugin stdio passthrough
  • 10af33a feat(plugin): add command plugin support
  • 5527ba4 feat(plugin): add config-read message type (P5)
  • 12f280e feat(plugin): add debug hint to plugin load warnings
  • 717e441 feat(plugin): add filter field to http-request message (P7)
  • edd9f1c feat(plugin): add hook plugins for auth, request-middleware, response-middleware
  • 9e2878b feat(plugin): add hook plugins for loader and formatter
  • eca3e66 feat(plugin): add list-apis and list-profiles message types (P4)
  • 284fb31 feat(plugin): add no_cache and cache_ttl to http-request message (P1)
  • 9d9ffde feat(plugin): add no_paginate field to http-request message (P3)
  • fd360a7 feat(plugin): add plugin discovery and manifest loading (plugin list/install/remove)
  • 375c456 feat(plugin): add plugins config namespace in restish.json (P21)
  • 3362475 feat(plugin): add prompt and confirm message types (P6)
  • 029bd75 feat(plugin): add restish-bulk command plugin
  • 1f69d9f feat(plugin): add timeout to http-request message (P2)
  • bcb6f27 feat(plugin): export typed message structs and type constants (P12)
  • 7dd5df2 feat(plugin): index plugins by hook
  • 4c64bf9 feat(plugin): introduce Decoder for safe sequential stream reads
  • ff5d9e2 feat(plugin): load plugins only from config plugin dir
  • 832c17d feat(plugin): scope auth hooks to specific APIs via auth_api_names (P9)
  • 4750b82 feat(plugin): serve resolved operations to MCP plugin
  • dad6be4 feat(stream): add SSE and NDJSON streaming support
  • 3fe69bc feat(theme): add bundled themes and local installs
  • 0ad7413 feat(theme): add reset and refresh docs palette
  • e7a2757 feat: API registration in config with profile support
  • 8c17f38 feat: HTTP Basic auth with password prompting (Step 9)
  • a1d607c feat: JSONC config system with RSH_CONFIG_DIR support
  • 3f55f3a feat: OAuth2 client credentials and authorization code flows (Step 10)
  • d86232a feat: add 'api list' and 'api delete' commands (DX-3, DX-5)
  • 3797759 feat: add -v logs request/response headers to stderr
  • e43c37a feat: add Amazon Ion content type support
  • f87008f feat: add CLI.Config() accessor for embedders (DX-19)
  • 7a6fd6a feat: add CLI.FetchResponse for programmatic single HTTP requests (DX-18)
  • 5fb6dd1 feat: add Restish product skill
  • fcc0dff feat: add YAML output formatter and dynamic format name lists
  • 20920ad feat: add bootstrap-safe diagnostics
  • eecc21f feat: add bundled output themes
  • 89e0115 feat: add doctor JSON diagnostics
  • 044cf6a feat: add external-tool auth handler
  • 933c8f9 feat: add form and multipart request body support
  • a060526 feat: add hypermedia link parsing (Link header, HAL, TSJ, JSON:API, Siren)
  • ea5d7d3 feat: add more bundled themes
  • 7647c1c feat: add pagination.items_path and pagination.next_path to 'api set' (DX-12)
  • 715ae6f feat: add public embeddable API
  • 5f41349 feat: add retry with exponential backoff and RSH_TIMEOUT env var (step 12)
  • fe0dbe0 feat: add shorthand input support for api add and set
  • f1bd3e4 feat: add simplify skill
  • 27e94e6 feat: add spec_files, local spec loading, and operation_base
  • 0f24a4b feat: add terminal image rendering for image/* responses
  • 7ce9c56 feat: addAuthHandler lets embedders register custom auth schemes (DX-16)
  • d11afee feat: apply v2 design decisions
  • f0586f8 feat: complete generated operation URLs
  • 0c163ee feat: content type registry, encodings, and raw pass-through output
  • 18d40e9 feat: enhance x-cli-config with security scheme resolution and template expansion
  • 082680a feat: extend 'api set' with auth and tls_signer fields (DX-4)
  • 981c46c feat: finalize v2 theme and content aliases
  • 7675490 feat: gate cross-origin operation servers
  • 16c31ad feat: generate Cobra commands from OpenAPI operations (step 14)
  • 692f45c feat: generate deep object query child flags
  • ea327e5 feat: generic HTTP verb commands with URL normalization and global flags
  • 6a3136a feat: hint about body. prefix when -f filter returns no results (DX-9)
  • c5ac788 feat: hint shell setup on first run to prevent noglob foot-gun (DX-10)
  • 3b92962 feat: implement API spec discovery and caching (step 13)
  • 89a21f7 feat: implement RFC 7234 HTTP response cache (step 11)
  • 6790228 feat: implement final pre-release decisions
  • d098a34 feat: implement x-cli-* OpenAPI extensions (step 15)
  • 4318cc8 feat: link --rsh-columns and --rsh-sort-by from output-format help (DX-6)
  • 66f72e4 feat: module setup and CLI struct skeleton
  • 238efd1 feat: preview bundled themes
  • 16520da feat: rename --tls-min-version to --rsh-tls-min-version (DX-2)
  • 21aaeaf feat: render command Long descriptions as Markdown in TTY help output
  • 9fceb49 feat: report spec discovery result after api configure (DX-1)
  • b90bb39 feat: response filtering with shorthand and jq, --rsh-raw output
  • 83af830 feat: response formatting with chroma syntax highlighting
  • 7f74b5a feat: shorthand request body input and -c content-type flag
  • 36e3c34 feat: suggest 'api edit' when JSONC comment preservation note is shown (DX-8)
  • 09871ae feat: update AGENTS and add some skills
  • 3c702bf feat: warn about broken plugins at startup (DX-11)
  • 07a9976 feat: warn on unhandled plugin message type (P22)
  • 27e1779 feat: warn when response-middleware follow.body/headers/query is ignored (P8)
  • 4584259 fix(api): preserve embedder defaults during connect
  • 0e5d330 fix(auth): clarify inspection guidance
  • d6a5e78 fix(auth): serialize OAuth token refreshes
  • df403e7 fix(auth): use portable shell execution and tighten oauth validation
  • 87c6d15 fix(bulk): harden url handling and atomic metadata writes
  • 8da5be5 fix(bulk): preserve hidden checkout resources
  • 0136293 fix(bulk): restore themed v1 bulk output
  • 6633ace fix(cache): fix API cache clearing and retry delay compatibility
  • 73a9d71 fix(cache): fix HTTP cache size accounting
  • 348e1de fix(cache): make writes safer and retry semantics explicit
  • be1f563 fix(cli): fail on invalid pagination paths
  • 20ac1ea fix(cli): finalize v2 command surface
  • 94ac30f fix(cli): fix reviewed CLI edge cases
  • 68de0f1 fix(cli): honor help-all without side effects
  • 154492a fix(cli): improve generated API help
  • 69fdde4 fix(cli): polish help and usage errors
  • 12e9200 fix(cli): propagate command context through CLI requests
  • f550a9c fix(cli): restore edit interactive flag
  • a945615 fix(cli): standardize local command polish
  • 1365e06 fix(cli): tighten config and diagnostics handling
  • 50481b4 fix(cli): unify streaming item limits
  • cca12eb fix(config): fix api configure invalid config handling
  • ec989e3 fix(config): guard invalid JSONC inline-object bounds
  • 1cfb9c0 fix(config): honor XDG path overrides in config paths
  • 51de9e8 fix(config): preserve JSONC comments in config edits
  • 6d4974a fix(config): preserve JSONC edit directory modes
  • 1c1b068 fix(config): preserve config dirs and clarify migration recovery
  • a4dcffe fix(config): preserve profiles during API configure
  • b563799 fix(config): protect credential diagnostics
  • 49a55d9 fix(csv): handle row schema drift in streaming output
  • c459ee0 fix(docs): restore preview command selection
  • 2cfd3a4 fix(filter): improve jq fallback errors and cache eviction
  • 984ceeb fix(filter): prefer jq for leading dot fields
  • 2626c91 fix(mcp): validate json-rpc frames and encode array parameters
  • f65302a fix(openapi): bound OpenAPI server variable resolution
  • 48ebc8b fix(openapi): correct operation_base path semantics
  • 5b6aafc fix(openapi): fix generated command regression handling
  • d609770 fix(openapi): honor OpenAPI server base paths and scopes
  • 5c40f2b fix(openapi): invalidate spec cache after config changes
  • 6d9ceec fix(openapi): preserve generated array defaults
  • 5371efc fix(openapi): preserve generated schema string body fields
  • fa5dc24 fix(openapi): preserve reserved query bytes and same-origin checks
  • 4218ab1 fix(openapi): restore generated API help descriptions
  • 7f89876 fix(openapi): restore generated OpenAPI command semantics
  • 8d3191c fix(output): always close formatter plugin streams
  • e27ac57 fix(output): fix filter hint for top-level roots
  • 4aa28e2 fix(output): fix output formatter regressions
  • f9280a0 fix(output): fix v1 request and output regressions
  • d299a55 fix(output): honor pagination cancellation during output
  • fcf455f fix(output): redact sensitive response headers
  • a003c65 fix(output): restore headers for TTY image output
  • 77286d4 fix(output): tighten output filter default behavior
  • 82f86aa fix(plugin): fail stream errors early and time out MCP calls
  • 361a82d fix(plugin): fix auth and plugin hardening issues
  • bf5a421 fix(plugin): fix bulk plugin race-test fixture
  • 9218d6a fix(plugin): fix bulk pull local version tracking
  • 806c6bb fix(plugin): fix command plugin and MCP shutdown handling
  • 9070a1b fix(plugin): fix command plugin stdio integration fixture
  • 54d6642 fix(plugin): fix plugin quickstart CBOR terminology
  • 976713c fix(plugin): fix reviewed plugin and retry edge cases
  • c7d32e5 fix(plugin): fix reviewed plugin, config, and shell issues
  • f38ef1d fix(plugin): honor spec file freshness for command plugins
  • 5133a7f fix(plugin): polish bundled command help
  • 6a2cced fix(plugin): reject bulk push on version conflicts
  • 904d620 fix(plugin): reject malformed command plugin messages
  • 63b7b03 fix(plugin): surface debug decode errors and make discovery cache robust
  • e843ad4 fix(plugin): treat host plugin flags as an internal prefix
  • f414ae3 fix(plugin): validate installed plugin binaries
  • c40f057 fix(plugin): validate plugin capabilities
  • 6ed82e2 fix(plugin): validate plugin remove names
  • 04f6506 fix(plugins): preserve MCP stdin ordering
  • 9c7a8f3 fix(retry): fix header timeouts and retry handling
  • e54dc04 fix(site): align preview command baseline
  • 9696039 fix(stream): bound sse memory and clarify event parsing
  • 0a5a009 fix(stream): fix edit, pagination, cert, and prompt edge cases
  • ae774d2 fix(stream): honor status codes for streaming and pagination
  • 1e50413 fix(stream): polish streaming and pagination behavior
  • 0b4e75a fix: a couple of examples in docs
  • 9681d87 fix: add wildcard accept fallback
  • 71b73a3 fix: address code review issues across plugin, config, and CLI layers
  • fafbd08 fix: address phase 1 correctness issues
  • 7b94f8d fix: address phase 2 and 3 correctness issues
  • 9fec8eb fix: advertise all supported operation response types
  • fec5228 fix: align enum fallback schema help
  • 152523a fix: align pagination streaming and filter metadata
  • f4f1055 fix: align plugin install GitHub shorthand
  • 891ef37 fix: allow anonymous optional auth fallback
  • ababaa1 fix: allow null body pagination next links
  • f7e1ed1 fix: apply OpenAPI route auth to generic URLs
  • 09995ea fix: apply header and cookie parameters in generated API commands
  • 9c7abba fix: apply operation auth to allowed cross-origin servers
  • 818362f fix: avoid URL completion placeholders
  • d503bb7 fix: avoid caching stale or varying responses
  • 696eae7 fix: avoid oauth scope prompts in noninteractive setup
  • 8ef7052 fix: bound generated api root help descriptions
  • 9e2e2fc fix: clarify per-record filters and silent requests
  • f029944 fix: close pipes on error in startTLSSigner, fix retry bugs, fix formatters map race
  • 9169a8e fix: color ndjson output in terminals
  • 26bf83d fix: colorize generated API help groups
  • d664749 fix: correct ExternalTool auth bugs and browser/editor process handling
  • 9915cd1 fix: correct commonPrefix trailing slash and hoist regex (B11, SI-17)
  • aba7f94 fix: decode all CBOR messages in plugin debug, not just first (P23/DX-14)
  • 44b19d4 fix: disambiguate auto filter detection
  • f3c4d25 fix: embed official themes
  • 1136a4f fix: encode json-content query child flags as parent value
  • d6d6675 fix: expose headers to shorthand projections
  • 5af52f6 fix: fix URL-aware API profile matching
  • cab4b03 fix: fix regressions from hardening pass
  • 1ec3adb fix: fix remaining correctness edge cases
  • fc835bb fix: fix review cleanup items
  • e1e9e27 fix: fix review findings before restish v2 release
  • b76ea7d fix: fix review remediation items
  • eb99156 fix: flush streaming output and verbose requests
  • 6069f3c fix: guide v1 api configure users to v2
  • a5be648 fix: handle JSON sequence ndjson output
  • 3e2b2e0 fix: handle runtime edge cases and diagnostics
  • 761fd92 fix: handle structured suffix content types
  • b9d9ff8 fix: harden plugin and mcp generated operations
  • ce9c10d fix: harden plugin archive extraction
  • bd292c5 fix: highlight JSON command output on TTY
  • 95c5786 fix: honor anonymous-only operation security
  • ee3fbd2 fix: honor content type for generated body examples
  • 95b0cfd fix: honor explicit Host headers
  • 40b007b fix: ignore conflicting generated examples
  • 0e6f142 fix: ignore edit formatting-only changes
  • aba9004 fix: ignore unrelated server variables for operation servers
  • 5cbe295 fix: improve CLI error recovery diagnostics
  • 773b076 fix: improve CLI onboarding feedback
  • 7b2f9d6 fix: improve generated API spec discovery
  • fde6da8 fix: improve generated auth precedence and fallback
  • c910a6e fix: inspect all configured auth credentials
  • dcee338 fix: keep YAML formatter body-only
  • b0c3d43 fix: keep docs navbar section links active
  • 9a436b3 fix: keep generated body shorthand schema-agnostic
  • 2d0041c fix: keep header values plain in HTTP highlighting
  • 672fc45 fix: keep paginated filters item-scoped across outputs
  • 78babcd fix: keep stale generated API commands available
  • b083cd8 fix: let auth set user-agent credentials
  • 9b6863c fix: let docs code blocks use full width
  • b71ea57 fix: make cancellation interrupt auth and plugin waits
  • 56e56ab fix: make sure Accept header has text/event-stream
  • ad09a16 fix: mark review fixes complete
  • b7e2ea0 fix: merge duplicate header parameters
  • 1a8f13d fix: merge explicit headers with defaults
  • 3ee5e74 fix: normalize explicit config cache identity
  • 6956b6f fix: normalize filtered headers and protect cache
  • 8e594fa fix: normalize generated scalar examples
  • 9162633 fix: normalize headers_all for shorthand filters
  • 6b3b72c fix: parallelize OpenAPI external ref loading
  • 07fcda7 fix: polish built-in output and redirects
  • 8642e26 fix: prefer JSON in default Accept negotiation
  • f1e81f9 fix: prefer anonymous over profile auth for optional operations
  • 4cdb6a9 fix: preserve MCP parameter content schemas
  • be111da fix: preserve concurrent connect caches
  • ab642b5 fix: preserve generated command cache on clear
  • 3658bb5 fix: preserve generated commands with operator flags
  • ec7ffe5 fix: preserve generated optional defaults as documentation
  • 4ec6c14 fix: preserve nullable generated body nulls
  • 26d82c5 fix: preserve plugin short flags
  • cdd2115 fix: preserve raw XML and NDJSON bodies
  • 2c23f30 fix: preserve redirected response body bytes
  • c89c4a9 fix: preserve scalar type for const variants
  • fe05eb6 fix: preserve spec cache for operation metadata changes
  • 2461b91 fix: redact credentials in network errors
  • 347588a fix: redact suffixed password fields
  • e13672a fix: redact token-like verbose credentials
  • 09a4ec2 fix: reduce generated startup noise and cold-cache surprises
  • 750647d fix: refine reviewer skill guidance
  • 5128f7e fix: reject config path output transforms
  • 11040b2 fix: reject invalid explicit specs
  • 6f7678b fix: reject missing multipart file references
  • 11b8d41 fix: reject negative numeric global flags
  • 0e9c2fa fix: reject negative request timeouts
  • 78a6d4e fix: reject non-HTTP server overrides
  • 9aec84b fix: reject root-relative URLs without context
  • 4c0ae9e fix: reject unknown command help typos
  • 51e71fa fix: reject unsupported built-in output flags
  • 0aa3494 fix: reject unsupported structured output formats
  • 44d53ba fix: reject unused auth setup answers
  • f2e116b fix: render conditional schema help
  • a1db5c8 fix: render large text responses as text
  • ed76d70 fix: report auth readiness consistently
  • 6685e54 fix: report invalid bulk list JSON path
  • 0d1c0c4 fix: report local spec doctor operations
  • f9d16c3 fix: report noninteractive auth setup requirements
  • d7ffdfe fix: require usable auth-code oauth before requests
  • 302977a fix: reserve generated flag names
  • ee69bef fix: resolve follow-up CLI findings
  • e0cf392 fix: resolve real-world test findings
  • 91da42e fix: restore HTTP status family exit codes
  • 008bbc6 fix: satisfy duplicated query api keys from auth
  • 656b4fd fix: satisfy mutual TLS with transport config
  • 7c1eb59 fix: send raw binary generated bodies
  • de411a4 fix: serialize buffered stdout writes
  • e63b9f7 fix: serialize json content array flags as arrays
  • 530c6da fix: serialize non-exploded label params with commas
  • 5e7f088 fix: show resolved filter language in verbose output
  • 312a113 fix: skip unsupported fallback auth schemes
  • 7cf3a03 fix: sort numeric table columns numerically
  • b1f9994 fix: suggest rsh-prefixed flags
  • 136d187 fix: suggest valid array body filters
  • 0e40a15 fix: support escaped commas in env request options
  • 832c7ae fix: surface undeclared operation security schemes
  • c721fa2 fix: terminal window colorful gradient tweaks
  • 0fad4eb fix: tighten generated command request construction
  • 89b4d5a fix: tolerate mismatched enum parameter types
  • 99446b7 fix: trace request pipeline in verbose output
  • d222bc5 fix: type-check bulk matches against files
  • cd21e97 fix: use auth readiness for connect coverage
  • b1606e9 fix: use maintained HTTP cache transport
  • bcb2925 fix: validate explicit filter language
  • f4898e7 fix: validate output flags before requests
  • fef4e1f fix: validate persistent request options
  • 9421383 fix: warn on server variable enum mismatch
  • d0fe154 perf(cache): cache computed Accept headers
  • 8e6f953 perf(config): avoid double-build of V3 model in FallbackXCLIConfig
  • 3c360c3 perf(config): optimize JSONC path patch parsing
  • 66e6c8d perf(openapi): benchmark large OpenAPI startup paths
  • 12eebcc perf(output): cache compiled jq filters
  • 34588f9 perf(output): preallocate jq filter result slices
  • 97d2f44 perf(output): reduce formatter allocation churn
  • 7f46033 perf(output): reduce gron path allocations
  • 7b4e018 perf(stream): avoid SSE event join allocations
  • 5970a30 perf(stream): preallocate collected pagination buffers
  • 9ea2e41 perf: avoid rune-slice allocation in toKebabCase (PERF-8)
  • ccb977f perf: memoize BuildV3Model() result on APISpec (PERF-4)
  • 2b4d0fe perf: reuse HTTP transport across paginated requests (B10, PERF-6)
  • 6a60164 perf: run LRU cache eviction asynchronously (PERF-5)
  • abae410 perf: skip PATH scan when allowed_plugins is set (PERF-9)
  • a31e1df perf: skip yaml re-marshal for single-file specs (PERF-7)
  • 39af614 refactor(auth): centralize credential detection
  • aec9b6e refactor(auth): complete API auth management TODOs
  • a48630a refactor(auth): improve API auth configuration UX
  • d79fd43 refactor(auth): simplify auth and config helpers
  • b051a02 refactor(auth): tighten OAuth token compatibility
  • e57ce3c refactor(cli): consolidate small helper files
  • 1522da2 refactor(cli): delete unused compatibility helpers
  • 5880a08 refactor(cli): improve CLI body and edit ergonomics
  • 9c46c7d refactor(cli): improve schema help highlighting
  • 76f7401 refactor(cli): polish command surface compatibility
  • 5cebe4a refactor(cli): refactor shared CLI request execution
  • fecd647 refactor(cli): refine v2 command surface
  • 33d3394 refactor(cli): replace API setup with connect command
  • dd27fb6 refactor(cli): simplify shared API and helper logic
  • 1a9b020 refactor(cli): trim minor helper duplication
  • e6901cd refactor(config): improve API configure setup flow
  • f6be7fa refactor(config): replace JSONC patcher with CST-preserving parser (hujson)
  • 685cdb8 refactor(config): simplify JSONC patch benchmarks
  • f33a81d refactor(openapi): decouple command generation from libopenapi
  • 5cb0af3 refactor(openapi): improve generated command body ergonomics
  • b8abba0 refactor(openapi): improve spec discovery fidelity
  • 7f590b9 refactor(openapi): tighten OpenAPI discovery trust boundaries
  • bf59a74 refactor(openapi): tighten spec discovery and configure errors
  • 250e233 refactor(output): improve output and parsing hot paths
  • 8e461a8 refactor(output): polish links and verbose output
  • e4bc2a3 refactor(output): refactor CLI output formatting pipeline
  • 38e2938 refactor(output): refine pagination and streaming output semantics
  • fe79ec2 refactor(output): remove raw output format
  • 978cede refactor(output): share CLI filter and raw output logic
  • 3401e04 refactor(output): trim gron formatter path allocations
  • 27a78f7 refactor(plugin): finish plugin protocol hardening TODOs
  • d826b9c refactor(plugin): improve public plugin and auth APIs
  • 9506f5c refactor(plugin): remove misleading plugin verbose hint
  • 0a189e5 refactor(plugin): replace stringly-typed plugin protocol with typed message structs
  • 11156a9 refactor(plugin): use cbor.Decoder for stream reading
  • 92ef222 refactor: centralize config mutations
  • 69937de refactor: collapse body parsing entrypoint
  • 8119aaa refactor: complete v2 TODO follow-ups
  • b913fef refactor: consolidate atomic file writes
  • 1cf8770 refactor: consolidate startup arg scanning
  • cb53750 refactor: eliminate readableIndentDepth global using LexerState.MutatorContext (SI-26)
  • 7986bf4 refactor: eliminate redundant bodyReader variable in runHTTPInternal (SI-14)
  • 0cd89b5 refactor: export plugin.DecMode to deduplicate cbor.DecMode definition (SI-7)
  • 7d47c21 refactor: extract buildQualityHeader helper in content/registry.go (SI-10)
  • 30f9139 refactor: extract callHookRaw to deduplicate subprocess launch in hook.go (SI-11)
  • 74021dd refactor: extract configDir() helper to deduplicate env lookup (SI-25)
  • 8a5adba refactor: extract effectiveTransport helper in discover.go (SI-12)
  • 638d5c2 refactor: extract mergeTLSSignerParams to deduplicate merge logic (SI-2)
  • 3d8ded1 refactor: extract plugin helper functions to public plugin package (P10/P11/SI-4/SI-5/SI-6)
  • 9c912b3 refactor: extract profileFromCmd() to deduplicate profile resolution (SI-1)
  • 53f057c refactor: extract writeRaw helper to deduplicate raw output logic (SI-9)
  • b54809f refactor: finish remaining Phase 7 items
  • 6dffe63 refactor: inline verbose response transport hook
  • 3730644 refactor: isolate plugin install pipeline
  • 4083c8f refactor: make spec loaders options-aware
  • d30c043 refactor: merge prompt helpers
  • 7680ae5 refactor: promote OpExtBool/OpExtString/PathItemMethods to internal/spec (SI-3, SI-8)
  • 4da5ccf refactor: remove archived v1 and wasm prototype
  • 7c90b9f refactor: remove dead lowercase-key lookup in supportsMergePatch (SI-16)
  • b2714d4 refactor: remove duplicate DiscoverOIDC call in resolveTokenURL (SI-21)
  • c3dfe04 refactor: remove local notes and committed binary
  • 6116408 refactor: remove unexported wrapper functions in oauth_authcode (SI-20)
  • 85cef44 refactor: rename done channel to stopCh to avoid shadowing (SI-22)
  • 913bfce refactor: rename ttyErr to stderrIsTTY in pagination (B13/SI-23)
  • 28f8147 refactor: replace custom unifiedDiff with gotextdiff/myers in edit.go (SI-18)
  • 633fcce refactor: replace fmt.Sscanf with strconv.Atoi in cacheTTL (SI-24)
  • 74b4f12 refactor: share Link header parsing and clean stale comments
  • 892d6cf refactor: share OpenAPI parameter serialization
  • 24ebe90 refactor: share secret prompt handling
  • bb22662 refactor: simplify internal API surfaces
  • a845877 refactor: simplify request transport cleanup
  • 850c7a5 refactor: split bulk command and file helpers
  • ac62810 refactor: split command plugin runtime and handlers
  • 4334517 refactor: split mcp server responsibilities
  • b58154e refactor: tighten HTTP pipeline handling
  • 7d824ae refactor: trim request closers after each request
  • 5457980 refactor: unify CLI prompt handling
  • ba9fb55 refactor: use configFilePath() in CLI.Run instead of inline logic (SI-13)
  • 11b0ef3 security(auth): harden OAuth and external auth handling
  • 451cae2 security(auth): harden OAuth browser and device flows
  • 325f1be security(auth): harden OAuth callback handling
  • 803a1b6 security(auth): harden OAuth token cache writes
  • 2ea1d83 security(auth): harden direct OAuth endpoints
  • d973376 security(auth): harden redirects and authenticated caching
  • 24220b0 security(auth): secure OAuth token storage and external tools
  • 01a83df security(cli): harden shell setup file permissions
  • 68aa3aa security(config): harden config editing and migration
  • 6481caf security(config): restrict config directory permissions
  • b016dff security(openapi): fail closed on spec discovery DNS checks
  • ac229b9 security(openapi): harden spec cache names and OIDC host checks
  • eb23173 security(openapi): harden spec discovery against SSRF
  • 29166e7 security(plugin): bound plugin protocol inputs
  • 50cd9e6 security(plugin): cap plugin debug capture memory
  • 0af9ef5 security(plugin): cap plugin install downloads and extraction
  • 01c2e51 security(plugin): gate MCP write tools behind flag
  • 05d4e31 security(plugin): harden bulk push preconditions
  • bfb790e security(plugin): harden command plugin process handling
  • a9cfed4 security(plugin): harden plugin manifest compatibility
  • 25189cf security(plugin): reject bulk paths outside checkout base
  • b323aa5 security(plugin): require explicit plugin install trust
  • 50f585e security(stream): block HTTPS to HTTP scheme downgrade on next links
  • 80c40ea security(tls): default to TLS 1.2 minimum
  • ba556f8 security: add allowed_plugins allowlist for plugin auto-discovery (S-H2)
  • 45e40b5 security: cap response body and spec fetch at 100/50 MiB (S-M3)
  • e196b3c security: disallow external-tool auth in x-cli-config (S-H3)
  • 75e08fc security: fix Windows 'cmd /c start ' special char handling (S-L4)
  • 799e72b security: percent-encode cookie parameter values to prevent header injection (S-L5)
  • 300acc3 security: redact URL userinfo in diagnostics
  • 3f13140 security: redact auth headers in verbose mode, add insecure-TLS warning, cap MCP payload, fix SSE buffer, fix UTF-8 truncation
  • 73a001a security: redact generated api-key auth targets
  • d4aadfc security: redact secret auth params from plugin dispatch (S-L7)
  • bada961 security: redact secret auth params in 'api show' output (S-L2)
  • 17d282e security: redact secret headers in hook payloads
  • 6cbb42c security: restrict config and cache file permissions to owner-only (0600/0700)
  • 7320034 security: strip credentials on cross-host response-middleware follows (S-M6)
  • 53f8035 security: validate OIDC endpoint URLs against issuer hostname (S-M2)
  • 9a11b85 style(theme): refresh default CLI palette
  • d312c43 style: tune bundled theme palettes
  • aa524f7 test(auth): convert auth and pagination tests to injected transports
  • 15bd8a7 test(cli): close v2 release guardrails
  • c490822 test(cli): consolidate CLI test helpers
  • e569457 test(cli): convert CLI tests to injected transports
  • ab2a1da test(cli): cover edit warning without validators
  • 9060ece test(cli): fix CLI test hangs with TTY
  • cc147ae test(cli): gate slow CLI tests behind integration tag
  • a41fe7a test(cli): guard non-tty color behavior
  • 7094b12 test(cli): mark CLI override fields as test-only
  • 0bb054e test(config): cover API-rooted shorthand swaps
  • 8aa6d28 test(openapi): add OpenAPI robustness regression coverage
  • b72702e test(openapi): add public OpenAPI shape regression tests
  • 79bf23d test(openapi): expand OpenAPI edge case coverage
  • b9a3cbe test(openapi): expand spec-loading and command-generation test coverage
  • 249a944 test(openapi): harden OpenAPI generated command coverage
  • 4d1f68f test(openapi): test OpenAPI server and required parameter behavior
  • e57087f test(output): highlight paginated readable output and add regression tests
  • 468dfce test(plugin): add pluginFormatter.FormatValue round-trip test
  • 9ae818c test(plugin): cover MCP resolved server variables
  • 0f3eb31 test(plugin): fix data race in PluginSigner and pass go test -race ./...
  • feeaa50 test(plugin): speed up CLI plugin test helper builds
  • 3153c2f test(stream): add NDJSON streaming support and regression tests