This release keeps dependencies and maintenance posture current for teams operating this tool.
✓ No known CVEs patched in this version
ReleasePort's take
Light signalclickup-cli v0.12.1 migrates npm publishing to OIDC Trusted Publishing, a CI infrastructure change. This update does not affect end-user functionality.
Why it matters: CI infrastructure for npm publishing now uses OIDC Trusted Publishing. No action required; changes do not affect package functionality.
Summary
AI summaryMinor fixes and improvements.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Refactor | Medium |
Migrated npm publish to OIDC Trusted Publishing. Migrated npm publish to OIDC Trusted Publishing. Source: llm_adapter@2026-05-21 Confidence: low |
— |
Full changelog
What's Changed
- ci(npm): migrate npm publish to OIDC Trusted Publishing by @nicholasbester in https://github.com/nicholasbester/clickup-cli/pull/63
Full Changelog: https://github.com/nicholasbester/clickup-cli/compare/v0.12.0...v0.12.1
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About nicholasbester/clickup-cli
ClickUp API integration with 143 MCP tools covering all ~130 endpoints. Token-efficient compact responses (~98% smaller than raw JSON), flattening nested objects for minimal context usage. Also works as a standalone CLI.
Related context
Beta — feedback welcome: [email protected]