# GitHub CLI 2.24.0

DevFeed: [GitHub CLI 2.24.0](<https://devfeed.tech/articles/github-cli-2-24-0-75253.md>)

Original publisher: [Read original article](<https://github.com/cli/cli/releases/tag/v2.24.0>)

Published: 2023-03-08T16:55:35Z

Content type: release

Language: en

Sources: [GitHub CLI](<https://devfeed.tech/sources/github-cli.md>)

Topics: [GitHub CLI extension](<https://devfeed.tech/topics/gh-extension.md>), [Secure token management](<https://devfeed.tech/topics/secure-token-management.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [2](<https://devfeed.tech/tags/2.md>), [api](<https://devfeed.tech/tags/api.md>), [arm64](<https://devfeed.tech/tags/arm64.md>), [auth](<https://devfeed.tech/tags/auth.md>), [github](<https://devfeed.tech/tags/github.md>), [github-cli](<https://devfeed.tech/tags/github-cli.md>), [keychain](<https://devfeed.tech/tags/keychain.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [secret](<https://devfeed.tech/tags/secret.md>)

## AI overview

GitHub CLI 2.24.0 adds an opt-in `--secure-storage` flag to `gh auth login` and `gh auth refresh`, storing access tokens in the system keyring instead of the plain text configuration file. It also adds several commands and options, updates behavior across repository, codespace, and pull request commands, and provides macOS arm64 prebuilt binaries.

## Source excerpt

## What's New ### Option to store gh access token in system encrypted storage The `gh auth login` and `gh auth refresh` commands gained the new `--secure-storage` flag. In this mode, the access token that GitHub CLI uses for GitHub API requests will now be stored in the system keyring instead of in the plain text config file. To migrate as an existing GitHub CLI user, re-authenticate like so: ``` gh auth refresh --secure-storage -h github.com ``` Depending on your system, you could get an interactive prompt to allow the CLI tool to access the system keyring. The systems that are supported are: - Keychain on macOS - GNOME Keyring on Linux (Secret Service dbus interface) - Wincred on Windows Please note: * This feature is currently opt-in, but will become the default in the near future. * If none of the system storage providers are found, or the store operation fails, the token will be written to the config file as before. * Using this feature could result in Go extensions breaking if they were not updated to the latest [go-gh] version. If extensions you are using no longer work after migrating your token to secure token storage, please report the issue to that extension's repository. * Storing tokens in system keyring most likely won't work in "headless" environments. ### Other additions * Add option to store credentials in OS keyring by @samcoe @mislav in https://github.com/cli/cli/pull/7033 https://github.com/cli/cli/pull/7043 https://github.com/cli/cli/pull/7098 * `browse`: add `--releases` option by @owenvoke in https://github.com/cli/cli/pull/6996 * Add `gpg-key add --title` to name GPG keys by @rpadaki in https://github.com/cli/cli/pull/6993 * Add command `gh repo unarchive` by @Ruminateer in https://github.com/cli/cli/pull/7003 * Add macOS `arm64` prebuilt binaries by @beret in https://github.com/cli/cli/pull/4435 * Introduce GH_PATH environment variable by @samcoe in https://github.com/cli/cli/pull/7025 ## What's Changed * `repo fork`: retry `git clone` on gi