v0.17.0
googleworkspace/cliv0.17.0Mar 17, 2026by github-actions[bot]
AI Summary
Minor release focusing on security hardening and output hygiene improvements.
Key Highlights
- Fixed critical TOCTOU/Symlink race vulnerability in atomic file writes.
- Sanitized dangerous Unicode characters (zero-width chars, bidi overrides).
- Auth errors now propagate correctly instead of being silently ignored.
New Features
- Security fixes for file operations.
- Improved error handling and output sanitization.
Full Release Notes
## Release Notes ### Minor Changes - 1b0a21f: feat: support google meet video conferencing in calendar +insert ### Patch Changes - 811fe7b: Fix critical security vulnerability (TOCTOU/Symlink race) in atomic file writes. The atomic_write and atomic_write_async utilities now use: - Randomized temporary filenames to prevent predictability. - O_EXCL creation flags to prevent following pre-existing symlinks. - Strict 0600 permissions from the moment of file creation on Unix systems. - Redundant post-write permission calls have been removed to close race windows. - b241a5b: fix(security): cap Retry-After sleep, sanitize upload mimeType, and validate --upload/--output paths - 6f92e5b: Stderr/output hygiene rollup: route diagnostics to stderr, add colored error labels, propagate auth errors. - **triage.rs**: "No messages found" sent to stderr so stdout stays valid JSON for pipes - **modelarmor.rs**: response body printed only on success; error message now includes body for diagnostics - **error.rs**: colored `error[variant]:` labels on stderr (respects `NO_COLOR` env var), `hint:` prefix for accessNotConfigured guidance - **calendar, chat, docs, drive, script, sheets**: auth failures now propagate as `GwsError::Auth` instead of silently proceeding unauthenticated (dry-run still works without auth) - 398e80c: Sync generated skills with latest Google Discovery API specs - 8458104: Extend input validation to reject dangerous Unicode characters (zero-width chars, bidi overrides, Unicode line/paragraph separators) that were not caught by the previous ASCII-range check ## Install gws 0.17.0 ### Install prebuilt binaries via shell script ```sh curl --proto '=https' --tlsv1.2 -LsSf https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-installer.sh | sh ``` ### Install prebuilt binaries via powershell script ```sh powershell -ExecutionPolicy Bypass -c "irm https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-installer.ps1 | iex" ``` ### Install prebuilt binaries into your npm project ```sh npm install @googleworkspace/cli@0.17.0 ``` ## Download gws 0.17.0 | File | Platform | Checksum | |--------|----------|----------| | [gws-aarch64-apple-darwin.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-aarch64-apple-darwin.tar.gz.sha256) | | [gws-x86_64-apple-darwin.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-x86_64-apple-darwin.tar.gz.sha256) | | [gws-x86_64-pc-windows-msvc.zip](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-x86_64-pc-windows-msvc.zip.sha256) | | [gws-aarch64-unknown-linux-gnu.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-aarch64-unknown-linux-gnu.tar.gz.sha256) | | [gws-x86_64-unknown-linux-gnu.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-x86_64-unknown-linux-gnu.tar.gz) | x64 Linux | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-x86_64-unknown-linux-gnu.tar.gz.sha256) | | [gws-aarch64-unknown-linux-musl.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-aarch64-unknown-linux-musl.tar.gz) | ARM64 MUSL Linux | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-aarch64-unknown-linux-musl.tar.gz.sha256) | | [gws-x86_64-unknown-linux-musl.tar.gz](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-x86_64-unknown-linux-musl.tar.gz) | x64 MUSL Linux | [checksum](https://github.com/googleworkspace/cli/releases/download/v0.17.0/gws-x86_64-unknown-linux-musl.tar.gz.sha256) | ## Verifying GitHub Artifact Attestations The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the [GitHub CLI](https://cli.github.com/manual/gh_attestation_verify): ```sh gh attestation verify <file-path of downloaded artifact> --repo googleworkspace/cli ``` You can also download the attestation from [GitHub](https://github.com/googleworkspace/cli/attestations) and verify against that directly: ```sh gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> ```