v0.13.3

googleworkspace/cliv0.13.3Mar 13, 2026by github-actions[bot]

AI Summary

Patch release fixing timezones, array handling, and security vulnerabilities.

Key Highlights

  • Fixed calendar agenda to use local timezone instead of UTC.
  • Fixed +append --json-values flattening multi-row arrays correctly.
  • Fixed path traversal vulnerability in chat +send command.

New Features

  • Security fix for path traversal in chat.
  • Bug fixes for calendar and chat operations.

Full Release Notes

## Release Notes

### Patch Changes

- 8ef27a2: fix(calendar): use local timezone for agenda day boundaries instead of UTC
- 4d7b420: Fix `+append --json-values` flattening multi-row arrays into a single row by preserving the `Vec<Vec<String>>` row structure through to the API request body
- bb94016: fix(security): validate space name in chat +send to prevent path traversal
- 4b827cd: chore: fix maintainer email typo in flake.nix and harden coverage.sh
- 44767ed: Map People service to `contacts` and `directory` scope prefixes so `gws auth login -s people` includes the required OAuth scopes
- 8fce003: fix(docs): correct flag names in recipes (--spreadsheet-id, --attendees, --duration)
- 21b1840: Expose `repeated: true` in `gws schema` output and expand JSON arrays into repeated query parameters for `repeated` fields
- 1346d47: Sync generated skills with latest Google Discovery API specs
- 957b999: test(gmail): add unit tests for +triage argument parsing and format selection

## Install gws 0.13.3

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-installer.ps1 | iex"
```

### Install prebuilt binaries into your npm project

```sh
npm install @googleworkspace/cli@0.13.3
```

## Download gws 0.13.3

|  File  | Platform | Checksum |
|--------|----------|----------|
| [gws-aarch64-apple-darwin.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-aarch64-apple-darwin.tar.gz.sha256) |
| [gws-x86_64-apple-darwin.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-x86_64-apple-darwin.tar.gz.sha256) |
| [gws-x86_64-pc-windows-msvc.zip](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-x86_64-pc-windows-msvc.zip.sha256) |
| [gws-aarch64-unknown-linux-gnu.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [gws-x86_64-unknown-linux-gnu.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-x86_64-unknown-linux-gnu.tar.gz) | x64 Linux | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [gws-aarch64-unknown-linux-musl.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-aarch64-unknown-linux-musl.tar.gz) | ARM64 MUSL Linux | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [gws-x86_64-unknown-linux-musl.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-x86_64-unknown-linux-musl.tar.gz) | x64 MUSL Linux | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.13.3/gws-x86_64-unknown-linux-musl.tar.gz.sha256) |

## Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the [GitHub CLI](https://cli.github.com/manual/gh_attestation_verify):
```sh
gh attestation verify <file-path of downloaded artifact> --repo googleworkspace/cli
```

You can also download the attestation from [GitHub](https://github.com/googleworkspace/cli/attestations) and verify against that directly:
```sh
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
```