New releases publish command lets GitLab CI, Buildkite, and local docs builds push changelog updates with RELEASES_API_TOKEN, reusing the plan from the publish-changelog GitHub Action. releases json validate now accepts publish: "push" changelog locators from the current releases.json schema.
Releases CLI
npx @buildinternet/releases get releases-cliAdds --official / --no-official to releases admin oauth client create and a new releases admin oauth client update command for the official, trusted, and disabled flags, with official now shown in client list and get output. The flag controls the Verified by Releases Index badge and requires an API with buildinternet/releases#2421; older APIs ignore official on create and reject an update that sets only official.
Agent skills now live in the self-contained Claude plugin folder at plugins/claude/releases/skills/ so the plugin passes Claude plugin directory validation, with npx skills add buildinternet/releases-cli finding them at the new path and the skills update check reading it. The Claude plugin also points at the agents.releases.sh/mcp endpoint, with documentation, support and terms links added to its manifest.
releases login now persists only the read-only API key it mints, and releases keys and releases publish-token open a fresh one-time browser approval per command that is signed out when the command finishes; every subcommand accepts --no-browser to print the URL and code instead. releases auth logout revokes the stored key directly and always removes the local credential, and pre-existing credential files are upgraded in place by signing out and stripping any leftover session token.
releases login no longer leaks a new relu_ key on every run: it remembers the minted key's id and revokes the key it replaces once the new one is safely stored, and hitting the server's active-key limit now returns an error naming the commands to list and revoke keys. releases auth logout also revokes the stored key server-side, best-effort.
Added releases publish-token create/list/revoke commands to mint relk_ tokens scoped to one source, for use with the publish-changelog GitHub Action via RELEASES_API_TOKEN environment variable.
releases admin discovery onboard no longer starts a remote discovery session, as the discovery worker and POST /v1/workflows/discover were retired; the command now exits 1 with a pointer to releases admin org create, releases admin source create, and the local-ingest skill. The onboard apply subcommand and the --managed-agents and --sandbox engine flags are removed.
macOS binaries are now built on macOS and ad-hoc code-signed; v0.77.0 and v0.78.0 shipped with invalid signatures that macOS 27 rejects, which caused brew upgrade to fail while generating shell completions.
Webhook list/add/show/edit/remove/test/rotate-secret commands accept a new --workspace <id-or-slug> flag for managing a shared workspace-owned webhook instead of your own. A new releases workspace list command shows a workspace's id, slug, and your role in it.
releases webhook add and edit now accept --format discord to deliver releases as formatted Discord embeds via a Discord incoming webhook URL. Human-readable webhook output redacts the delivery URL, while --json still includes it.
New releases admin recommendations notify-added command lets operators opt in to emailing a submitter that their suggested source was added to the registry.
New releases changelog command prints recent product updates from releases.sh and links to https://releases.sh/updates. The same capability is exposed as the local MCP changelog tool.
Unified feedback, submit, and keys command network calls onto the shared apiFetch transport, adding an opt-in skipDefaultAuth flag so keys' session-token Authorization header isn't overwritten by a configured admin/API key. Error messages, idempotency, and command output are unchanged.
Effectful write requests (feedback submit, webhook create/rotate-secret/test, API-key mint) now send an Idempotency-Key header, so retries after network failures replay the original response instead of double-submitting. Reusing a key with a different payload returns a clear idempotency_conflict message instead of a raw 409.
getApiUrl() no longer memoizes the API base URL process-wide, fixing a test isolation bug that caused 22 failing tests under bun test. The releases stats command now reads the server's real values instead of returning zeroed-out fields, and source backfill --dry-run reports how much history is not yet stored.
Search results now include an AI-scored importance field (1–5) in JSON output, with the TTY table marking high-importance hits. Added a TLS certificate verification hint and custom-CA documentation for proxy environments.
Removed the deprecated get_source_changelog MCP tool, replaced by get_catalog_entry with changelog params. Search now supports --category and --collection filters, and the release importance score is surfaced in tail/latest output.
Local stdio MCP bridge's get_catalog_entry tool now accepts changelog parameters to inline a source entry's CHANGELOG in the same call, matching the hosted server. The standalone get_source_changelog tool is deprecated. Also added releases admin release refetch command and consolidated agent skills by moving operator skills to the backend monorepo.
Fixed overview stale warning to use content write time (updatedAt) instead of original generation time, so amended overviews no longer appear months-old when recently rewritten.
New releases json export <org> command generates a releases.json v2 domain manifest from a tracked org by reconstructing it from the registry via the backend GET /v1/orgs/:slug/manifest endpoint. Output prints to stdout (pipeable into releases json validate -) or writes to a file with -o/--output. Bumps @buildinternet/releases-api-types to ^0.41.0 to support product-level tags in manifests.


