GitHub CLI 2.62.0
Full Changelog: https://github.com/cli/cli/compare/v2.61.0...v2.62.0
A security vulnerability has been identified in GitHub CLI that could allow remote code execution (RCE) when users connect to a malicious Codespace SSH server and use the gh codespace ssh or gh codespace logs commands.
For more information, see https://github.com/cli/cli/security/advisories/GHSA-p2h2-3vg9-4p87
Similar to the notification of latest gh releases, the v2.62.0 version of GitHub CLI will notify users about latest extension upgrades when the extension is used:
$ gh ado2gh
...
A new release of ado2gh is available: 1.7.0 → 1.8.0
To upgrade, run: gh extension upgrade ado2gh --force
https://github.com/github/gh-ado2gh
This removes a common pain point of extension authors as they have had to reverse engineer and implement a similar mechanism within their extensions directly.
With this quality of life improvement, there are 2 big benefits:
Extension authors should review their extensions and consider removing any custom logic previously implemented to notify users of new releases.
Fetched April 8, 2026