Sitelet https://github.com/basecamp/basecamp-cli/releases
Skip to content

Releases: basecamp/basecamp-cli

basecamp v0.11.0

Choose a tag to compare

@github-actions github-actions released this 09 Sep 23:15
6c4f230

What's Changed

Other Changes

  • Skill: warn that stdin '-' support is v0.10.0+ by @dhh in #688
  • Import personal access tokens with auth login --with-token by @jeremy in #681
  • feat(people): add people clients add/remove/invite/enable/disable by @jeremy in #689
  • Update release metadata for v0.11.0 by @jeremy in #690

New Contributors

  • @dhh made their first contribution in #688

Full Changelog: v0.10.0...v0.11.0

basecamp v0.10.0

Choose a tag to compare

@github-actions github-actions released this 03 Sep 23:13
e4bfd01

What's Changed

⚠️ Breaking Changes

  • Stdin - support everywhere sensible; usage error for stray - elsewhere by @jeremy in #641
  • Remove timeline --watch by @jeremy in #646
  • Require --force to delete a chat line when nobody can confirm it by @jeremy in #654

Features

  • Serve Basecamp over MCP with basecamp mcp by @jeremy in #662
  • Streamline first-time setup with recommended defaults by @robzolkos in #660
  • feat(bubble-up): add bubble-up add/remove commands by @jeremy in #677
  • Add a CLI command to edit your profile (bio, title, out-of-office) by @jeremy in #679
  • Add to-do list template library commands by @robzolkos in #682

Bug Fixes

  • Reject three more doomed invocations before draining stdin by @jeremy in #645
  • Blank lines between blocks vanish when CLI-posted content is edited in Basecamp by @jorgemanrubia in #637
  • Bound stdin (and the --file twin) at 1 MiB by @jeremy in #647
  • Restore the lost blank line before Markdown tables by @jeremy in #648
  • Refuse to prompt when nothing can answer the prompt by @jeremy in #652
  • Keep rich composers rich across Reset by @jeremy in #651
  • Read tables back as Markdown instead of smearing their cells by @jeremy in #650
  • Warn about the keyring fallback on the first credential read, not only on login by @jeremy in #664
  • Emit retryable in the JSON error envelope by @jeremy in #665
  • Police OAuth egress with per-provenance address enforcement by @jeremy in #656
  • Make IsMachineOutput honor an explicit --styled/--md by @jeremy in #670
  • Resolve a bare numeric cards <id> to a clear error instead of silent exit-0 by @jeremy in #678
  • Preserve account context in template library breadcrumbs by @robzolkos in #683

Documentation

  • Fix stale comments in ensureDeleteConfirmable by @jeremy in #668

Other Changes

  • Add hey-cli Windows signing secrets to the release env manifest by @jeremy in #642
  • Pin bin/ci's tool versions in .mise.toml by @jeremy in #649
  • Delete the dead TUI, and add a check that could have seen it by @jeremy in #653
  • Bump github.com/basecamp/cli for the keyring probe race fix by @jeremy in #661
  • MCP follow-up: converge the Codex review of #662 by @jeremy in #663
  • Bump golang.org/x/crypto past CVE-2026-56854 by @jeremy in #667
  • Bump github.com/basecamp/cli for the per-probe keyring item by @jeremy in #666
  • Release hygiene: label name, canary auto-close, coverage doc, allowlist honesty by @jeremy in #671
  • deps: bump google.golang.org/grpc to v1.83.1 by @jeremy in #680
  • Update release metadata for v0.10.0 by @robzolkos in #684

Full Changelog: v0.9.1...v0.10.0

basecamp v0.9.1

Choose a tag to compare

@github-actions github-actions released this 12 Aug 05:13

What's Changed

Other Changes

  • Add basecamp files versions by @jeremy in #622
  • Add basecamp files replace: publish a new version of an uploaded file by @jeremy in #634

Full Changelog: v0.9.0...v0.9.1

basecamp v0.9.0

Choose a tag to compare

@github-actions github-actions released this 06 Aug 01:57

⚠️ Breaking: BC5 logins now request full access by default

basecamp auth login against a Basecamp-hosted OAuth server (not Launchpad) previously received a read-only token, because the server defaults an omitted scope to its least-privilege entry — so every write returned "access denied". Logins now ask for full, matching what Launchpad logins have always granted. Use basecamp auth login --scope read for a read-only token.

This changes the scope granted to new logins only; existing stored credentials are untouched and keep whatever they were granted.


What's Changed

⚠️ Breaking Changes

  • BC5 device logins request full access by default by @jeremy in #616

Other Changes

  • Ask BC3 for presence-aware card step updates by @jeremy in #608
  • Share the AUR notifier and the Nix hash classifier between their callers by @jeremy in #609
  • Adopt basecamp-sdk v0.12.0 and cover the surface it opened up by @jeremy in #611
  • Filter the account-wide task listings by assignee and due date by @jeremy in #612
  • Stop a losing rm -rf race from failing a passing test by @jeremy in #613
  • Point two comments at functions that exist by @jeremy in #614
  • Make basecamp upgrade a real upgrade: native, verified self-update by @jeremy in #615
  • Tell agents the truth about card column moves by @jeremy in #618
  • Drive the circuit breaker's clock from tests, not sleep() by @jeremy in #619
  • Stop echoing back step fields the caller never changed by @jeremy in #620
  • Correct the API coverage claim: 183/184, not 100% by @jeremy in #621
  • Take the communiques out of the source tree by @jeremy in #623
  • Install the skill where opencode actually looks by @jeremy in #624
  • Lint the release the same way we lint everything else by @jeremy in #625
  • Keep refreshing opencode's other spelling by @jeremy in #627
  • Make the lockstep check catch stale agreement and .yaml workflows by @jeremy in #628
  • Make the Codex probe's timeout actually bound doctor by @jeremy in #629

Full Changelog: v0.8.1...v0.9.0

basecamp v0.9.0-rc.2

basecamp v0.9.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 05 Aug 17:04
3d4e235

Release candidate. Stable channels — Homebrew, Scoop, AUR, the Nix flake and the Claude/Codex plugin manifests — all stay on v0.8.1. Install these assets explicitly to test.

Notes below diff against v0.8.1, not v0.9.0-rc.1. rc.1's release job never ran (it failed at the pre-release lint gate on a stale golangci-lint pin, fixed in #625), so it published nothing and there is no rc.1 build to compare against.

⚠️ BC5 logins now request full access by default

basecamp auth login against a Basecamp-hosted OAuth server (not Launchpad) previously received a read-only token, because the server defaults an omitted scope to its least-privilege entry — so every write returned "access denied". Logins now ask for full, matching what Launchpad logins have always granted. Use basecamp auth login --scope read for a read-only token.

This changes the scope granted to new logins only; existing stored credentials are untouched and keep whatever they were granted.


What's Changed

⚠️ Breaking Changes

  • BC5 device logins request full access by default by @jeremy in #616

Other Changes

  • Ask BC3 for presence-aware card step updates by @jeremy in #608
  • Share the AUR notifier and the Nix hash classifier between their callers by @jeremy in #609
  • Adopt basecamp-sdk v0.12.0 and cover the surface it opened up by @jeremy in #611
  • Filter the account-wide task listings by assignee and due date by @jeremy in #612
  • Stop a losing rm -rf race from failing a passing test by @jeremy in #613
  • Point two comments at functions that exist by @jeremy in #614
  • Make basecamp upgrade a real upgrade: native, verified self-update by @jeremy in #615
  • Tell agents the truth about card column moves by @jeremy in #618
  • Drive the circuit breaker's clock from tests, not sleep() by @jeremy in #619
  • Stop echoing back step fields the caller never changed by @jeremy in #620
  • Correct the API coverage claim: 183/184, not 100% by @jeremy in #621
  • Take the communiques out of the source tree by @jeremy in #623
  • Install the skill where opencode actually looks by @jeremy in #624
  • Lint the release the same way we lint everything else by @jeremy in #625

Full Changelog: v0.8.1...v0.9.0-rc.2

basecamp v0.8.1

Choose a tag to compare

@github-actions github-actions released this 03 Aug 22:37

What's Changed

Features

Other Changes

  • Stop an AUR outage from masking release verification by @jeremy in #600
  • Fix the deprecated app-id input, and track failed AUR recoveries by @jeremy in #601
  • Fix the Nix flake, and stop the hash check reporting false success by @jeremy in #606

Full Changelog: v0.8.0...v0.8.1

basecamp v0.8.0

Choose a tag to compare

@github-actions github-actions released this 03 Aug 09:52

What's Changed

⚠️ Breaking Changes

  • Migrate to basecamp-sdk TodoListOptions.Completed by @jeremy in #456
  • Remove shortcut commands that shadow group nouns by @robzolkos in #416
  • Scope templates --status flag to the list subcommand by @robzolkos in #518
  • Fix tools create to use the BC5 create-by-type API (#471) by @jeremy in #553
  • Project-scope messagetypes on the bucket-scoped SDK; absorb bump-range surface (Fixes #567) by @jeremy in #570
  • Bound the account-wide listings, and drop the boost aggregate by @jeremy in #590

Features

  • Show comments by default in basecamp show by @robzolkos in #389
  • Comment flags on all show commands + bug fixes by @jeremy in #394
  • Promote files, checkins, and schedule to core commands by @robzolkos in #397
  • Send combined CLI and SDK versions in API user agent by @robzolkos in #400
  • Bump Basecamp SDK to v0.7.3 by @jeremy in #401
  • Replace hand-rolled MarkdownToHTML with goldmark by @jeremy in #415
  • Improve Windows installation with native PowerShell support and tougher shell installer fallbacks by @robzolkos in #406
  • Revert macOS signing workaround now that GoReleaser ships TeamID fix by @jeremy in #460
  • Bc5 assets by @jzimdars in #488
  • Support release candidate publishing by @robzolkos in #492
  • Add stdin support for comment content by @robzolkos in #414
  • Add basecamp cards done command by @robzolkos in #442
  • Add BASECAMP_NONINTERACTIVE escape hatch for prompts by @robzolkos in #520
  • Add --by flag to filter answers by person by @robzolkos in #444
  • security: pin the gitleaks download with a SHA-256 checksum by @jeremy in #483
  • Bump SDK to d15f023f and collapse todos update onto TodosService.Edit by @jeremy in #543
  • feat(codex): ship native basecamp plugin by @yigitkonur in #534
  • Add hidden agent-hook command for shared plugin hooks by @jeremy in #549
  • Bump SDK to 81660dc1 and surface BC5 forward-compat fields by @jeremy in #552
  • feat(chat): add chat update command for editing campfire messages by @nnemirovsky in #462
  • Add table extension to mdConverter goldmark renderer by @savtrip in #498
  • Expose client visibility at create time (Fixes #457) by @jeremy in #554
  • Add todolists position to reorder to-do lists (#484) by @jeremy in #562
  • Add --visible-to-clients to docs/uploads create (Fixes #556) by @jeremy in #563
  • Cross-project card move via wormholes (#342) by @jeremy in #559
  • test(todos): guard todos show --json surfaces SDK fields (Refs #449) by @jeremy in #564
  • Deterministic, reply-ready comment context (comments thread + show) by @jeremy in #565
  • Add post-deploy installer smoke canary by @jeremy in #569
  • Sync Dependabot action pin comments via reusable workflow by @jeremy in #572
  • Rebuild comment sync as a post-merge repair caller by @jeremy in #577
  • ci: harden installer canary and add pre-merge Bash 3.2 gate by @jeremy in #575
  • Re-pin dependabot-sync past the bot-author fix by @jeremy in #580
  • Add Nix development shell by @pradhankukiran in #583
  • Bump SDK to v0.10.0 and wire its account-wide aggregates by @jeremy in #584
  • Include email addresses in people list output by @robzolkos in #588
  • BC5 OAuth: resource-first discovery, device-flow login, RFC 8707 resource echo by @jeremy in #582
  • Carry an explicit project into the bare boost list usage hint by @jeremy in #591

Bug Fixes

  • Embed TeamIdentifier in macOS CodeDirectory by @jeremy in #392
  • Handle CommonMark backslash escapes in MarkdownToHTML by @robzolkos in #402
  • Preserve untouched document fields in files update by @robzolkos in #441
  • Require Go 1.26.4 by @robzolkos in #489
  • Fix --version over-propagation in check-cli-surface.sh by @sawirricardo in #499
  • Fix todo update dropping untouched fields by @robzolkos in #413
  • Read comment content from stdin when using dash by @robzolkos in #467
  • fix(attachments): download real bytes and hint --type for bucket-scoped recordings by @nnemirovsky in #447
  • fix(cards): carry over step title when updating assignees or due date by @nnemirovsky in #496
  • Test cards update preserves HTML body by @robzolkos in #512
  • Return fresh project after update by @robzolkos in #513
  • Fix TestFormatDueDate year-boundary flake by @robzolkos in #514
  • Bump SDK to cc8e977 and thread bucket ID into card column commands by @robzolkos in #522
  • Surface failing request IDs in CLI errors by @robzolkos in #446
  • Surface Todoset-level todos in todos list by @robzolkos in #526
  • Separate contiguous paragraphs in HTML passed to the CLI by @robzolkos in #527
  • Bump Go toolchain to 1.26.5 by @robzolkos in #533
  • Convert Markdown mention links inside HTML blocks to mention chips by @robzolkos in #532
  • security: reject foreign-host URLs in api to prevent token leak by @jeremy in #478
  • security: strip ANSI/OSC escapes from API-controlled output by @jeremy in #479
  • security: harden OAuth discovery and token endpoints by @jeremy in #480
  • security: close config trust-boundary gaps and gate completion loader by @jeremy in #481
  • security: tighten config-dir perms and validate plugin scope argv by @jeremy in #482
  • Fix TestHardenConfigDir on macOS: resolve TMPDIR symlinks in test dirs by @jeremy in #536
  • Fix todos update silently clearing completion subscribers by @jeremy in #540
  • Fix agent-help hidden-flag leak; make check-surface a real drift gate by @jeremy in #542
  • Refresh Claude marketplace cache and report setup failures honestly by @jeremy in #555
  • Produce gosec SARIF via golangci-lint for suppression parity by @jeremy in #561
  • Fix #528: non-TTY installer hardcodes the Claude agent by @jeremy in #558
  • Fix search timeout, sort vocabulary, and metadata handling by @jeremy in #557
  • Fix piped installer under nounset by @pradhankukiran in #568
  • Disable keyring in installer canary by @jeremy in #571
  • Defer keyring probe to first credential use; belt the installers by @jeremy in #578
  • Bound the keyring probe on headless sessions by @jeremy in #581
  • Reference STYLE.md instead of importing it, and fix two wrong claims by @jeremy in #587

Documentation

  • Add Since column to API coverage matrix by @jeremy in #461
  • Document multiple identity profiles by @robzolkos in #486
  • skill: document project archive/unarchive via api put by @gsamat in #450
  • Document todo subtask API usa...
Read more

basecamp v0.8.0-rc.3

basecamp v0.8.0-rc.3 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 03 Aug 09:02
7aefeaf

What's Changed

Other Changes

  • Stage the PowerShell installer as ASCII+CRLF before signing it by @jeremy in #597

Full Changelog: v0.8.0-rc.2...v0.8.0-rc.3

basecamp v0.8.0-rc.2

basecamp v0.8.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 03 Aug 07:35
07b2786

What's Changed

⚠️ Breaking Changes

  • Bound the account-wide listings, and drop the boost aggregate by @jeremy in #590

Features

  • Include email addresses in people list output by @robzolkos in #588
  • BC5 OAuth: resource-first discovery, device-flow login, RFC 8707 resource echo by @jeremy in #582
  • Carry an explicit project into the bare boost list usage hint by @jeremy in #591

Bug Fixes

  • Reference STYLE.md instead of importing it, and fix two wrong claims by @jeremy in #587

Other Changes

  • Sign Windows executables and steer Smart App Control users by @jeremy in #592
  • Remove the AI labeler and dead AI changelog: GitHub Models is retired by @jeremy in #593
  • Adopt basecamp-sdk v0.11.0 by @jeremy in #594
  • Automate the headless keyring-probe composition test by @jeremy in #596

Full Changelog: v0.8.0-rc.1...v0.8.0-rc.2

basecamp v0.8.0-rc.1

basecamp v0.8.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 29 Jul 18:58
e1059fb

The biggest release yet — four months of work since v0.7.2, and the headline is that your listings are no longer stuck inside one project.

Ask across every project

Eight list commands now answer their question account-wide. No project needed, no prompt to pick one:

basecamp todos list --all-projects --overdue
basecamp cards list --all-projects --unassigned
basecamp messages list --all-projects
basecamp files list --all-projects --kind images --person me

--all-projects works on todos list, cards list, messages list, comments list, files list, forwards list, boost list, and checkins answers. It overrides a configured default project, so the same script behaves the same way on every machine.

todos list and cards list add --unassigned and --no-due-date there; cards list also takes --not-now, --overdue, and --status completed. files list gains --kind (all, images, pdfs, documents, videos) and repeatable --person. Results come back grouped by project in --json, flattened with a project column everywhere else.

Also new

  • Windows, natively. PowerShell installer support, plus a much tougher fallback path in the shell installer.
  • Headless and CI sessions just work. The keyring is no longer touched until a credential is actually needed, which removes the startup hang on SSH and headless machines. BASECAMP_NONINTERACTIVE turns off every prompt for scripts and CI.
  • New commands: basecamp cards done, basecamp chat update for editing campfire messages, basecamp todolists position for reordering lists, and basecamp comments thread for reply-ready discussion context.
  • Cross-project card moves through wormholes, and client visibility (--visible-to-clients) at create time on messages, todolists, check-ins, schedule entries, docs, and uploads.
  • Better Markdown end to end: goldmark rendering, tables, mention chips inside HTML blocks, and correct CommonMark backslash escapes.
  • Comments show by default in basecamp show, with comment flags across the show commands.
  • Clearer failures: the failing request ID is surfaced in CLI errors, so a support conversation can start from the actual request.
  • A native Codex plugin, alongside the Claude Code one.

Security hardening

OAuth discovery and token endpoints are hardened, the api command rejects foreign-host URLs so a token cannot leak to another host, API-controlled output has ANSI and OSC escapes stripped before it reaches your terminal, and the gitleaks download is pinned to a SHA-256 checksum.

Behavior changes

Read these if you script against the CLI.

  • HTTP 400 now exits 9, not 7. It maps to the validation error code rather than api_error, matching how 422 already behaved. Any script branching on exit code 7 for a bad request needs updating.
  • search machine output gained and changed keys. content and description now serialize as explicit null instead of being omitted, and plain_text_content, plain_text_description, and bubble_up_url appear when populated. Styled output is unchanged. The plain-text fields are HTML fragments despite the name — Basecamp wraps query matches in <mark> — so strip markup before displaying them.
  • The interactive project prompt no longer fires on the eight list commands above when no project is configured. They list account-wide instead.
  • todos list --overdue with no project returns results instead of erroring with a redirect. Both commands stay: reports overdue buckets by lateness, todos list --all-projects --overdue is a flat oldest-first list. --assignee still errors and still points at reports assigned.
  • comments list, boost list, and checkins answers take an optional item ID. Everything that worked before still works; omitting the ID now lists account-wide instead of erroring.
  • files list --json changes shape account-wide. The account-wide feed returns the SDK's file superset, which spells the name title, where the project-scoped path returns name.
  • vaults list / folders list refuse --all-projects. There is no account-wide folder listing, so rather than hand back a listing with no folders in it, they point at files list --all-projects. docs list / documents list pin --kind documents account-wide. Project-scoped behavior of all three is unchanged.
  • Shortcut commands that shadowed group nouns were removed — use cards create, todos complete, comments create, and the other canonical <group> <action> forms.

What's Changed

⚠️ Breaking Changes

  • Migrate to basecamp-sdk TodoListOptions.Completed by @jeremy in #456
  • Remove shortcut commands that shadow group nouns by @robzolkos in #416
  • Scope templates --status flag to the list subcommand by @robzolkos in #518
  • Fix tools create to use the BC5 create-by-type API (#471) by @jeremy in #553
  • Project-scope messagetypes on the bucket-scoped SDK; absorb bump-range surface (Fixes #567) by @jeremy in #570

Features

  • Show comments by default in basecamp show by @robzolkos in #389
  • Comment flags on all show commands + bug fixes by @jeremy in #394
  • Promote files, checkins, and schedule to core commands by @robzolkos in #397
  • Send combined CLI and SDK versions in API user agent by @robzolkos in #400
  • Bump Basecamp SDK to v0.7.3 by @jeremy in #401
  • Replace hand-rolled MarkdownToHTML with goldmark by @jeremy in #415
  • Improve Windows installation with native PowerShell support and tougher shell installer fallbacks by @robzolkos in #406
  • Revert macOS signing workaround now that GoReleaser ships TeamID fix by @jeremy in #460
  • Bc5 assets by @jzimdars in #488
  • Support release candidate publishing by @robzolkos in #492
  • Add stdin support for comment content by @robzolkos in #414
  • Add basecamp cards done command by @robzolkos in #442
  • Add BASECAMP_NONINTERACTIVE escape hatch for prompts by @robzolkos in #520
  • Add --by flag to filter answers by person by @robzolkos in #444
  • security: pin the gitleaks download with a SHA-256 checksum by @jeremy in #483
  • Bump SDK to d15f023f and collapse todos update onto TodosService.Edit by @jeremy in #543
  • feat(codex): ship native basecamp plugin by @yigitkonur in #534
  • Add hidden agent-hook command for shared plugin hooks by @jeremy in #549
  • Bump SDK to 81660dc1 and surface BC5 forward-compat fields by @jeremy in #552
  • feat(chat): add chat update command for editing campfire messages by @nnemirovsky in #462
  • Add table extension to mdConverter goldmark renderer by @savtrip in #498
  • Expose client visibility at create time (Fixes #457) by @jeremy in #554
  • Add todolists position to reorder to-do lists (#484) by @jeremy in #562
  • Add --visible-to-clients to docs/uploads create (Fixes #556) by @jeremy in #563
  • Cross-project card move via wormholes (#342) by @jeremy in #559
  • test(todos): guard todos show --json surfaces SDK fields (Refs #449) by @jeremy in #564
  • Deterministic, reply-ready comment context (comments thread + show) by @jeremy in #565
  • Add post-deploy installer smoke canary by @jeremy in #569
  • Sync Dependabot action pin comments via reusable workflow by @jeremy in #572
  • Rebuild comment sync as a post-merge repair caller by @jeremy in #577
  • ci: harden installer canary and add pre-merge Bash 3.2 gate by @jeremy in #575
  • Re-pin dependabot-sync past the bot-author fix by @jeremy in #580
  • Add Nix development shell by @pradhankukiran in #583
  • Bump SDK to v0.10.0 and wire its account-wide aggregates by @jeremy in #584

Bug Fixes

  • Embed TeamIdentifier in macOS CodeDirectory by @jeremy in #392
  • Handle CommonMark backslash escapes in MarkdownToHTML by @robzolkos in #402
  • Preserve untouched document fields in files update by @robzolkos in #441
  • Require Go 1.26.4 by @robzolkos in #489
  • Fix --version over-propagation in check-cli-surface.sh by @sawirricardo in #499
  • Fix todo update d...
Read more