DEV Community

Fenju Fu
Fenju Fu

Posted on

SkillHub v0.2.21, Run for Real: Suite Bundles, Device Flow Login and Pi

SkillHub v0.2.21 shipped on 2026-09-19. Instead of summarizing the release notes, we pulled the tag, started it locally with the official compose.release.yml, and recorded each headline update as it actually runs. Every screenshot below comes from that local run; the skills and suites are fictional sample data.

The deployment

Images skillhub-server, skillhub-web and skillhub-scanner at v0.2.21 (server image revision matches the tag). All five services — PostgreSQL, Redis, scanner, server and web — reported healthy, and Flyway migrations V54 through V65 applied automatically on first start.

Local Docker deploy of SkillHub v0.2.21: five healthy containers and Flyway V54–V65

Two flags are required for the full bundle flow: SKILLHUB_SUITE_BUNDLE_CONFIRMATION_ENABLED=true and SKILLHUB_SUITE_REVIEW_WRITES_ENABLED=true. We also kept the security scanner on — public bundle members are rejected at preview time without it.

1. Two-stage Suite Bundle publishing

A Suite Bundle is one ZIP (or folder) with a single SUITE.yaml at the root plus one directory per member skill. Uploading it produces a member change preview: target coordinate and version, each member's relationship (added, updated, unchanged, removed), and the publish action.

Member change preview for a Suite Bundle in SkillHub v0.2.21

The preview has no side effects — no Skill versions, review tasks or Suite versions are created. Only Confirm and start publishing starts work. SkillHub then creates a durable task: each member goes through the existing scan/publish/review path, and the Suite draft is created only when every member is ready. The task page can be reopened after a refresh.

Suite publishing task: changes confirmed, members published, Suite draft generated

2. CLI sign-in with OAuth Device Flow

skillhub login without a token now starts a device flow. With --no-open (useful on headless machines) it prints the verification URL and a one-time code:

CLI device code entered on the SkillHub /device page

After approval on /device, the CLI validates the token before saving it and prints Logged in … as <handle>; skillhub whoami confirms it. Output never includes the secret.

Terminal: skillhub login --no-open succeeds, whoami shows the handle

3. Pi as a first-class agent target

skillhub install <slug> --agent pi --scope project installs into .pi/skills/<slug> (user scope uses .pi/agent/skills).

skillhub install with --agent pi writes into .pi/skills

Also in this release: yank from the web

Skill owners and namespace admins can yank a published version through the Web/API lifecycle endpoints (skill:yank token scope). In our run, v1.0.1 was yanked and the current version fell back to v1.0.0. Concurrent yanks of the same version are now serialized on the same row lock.

Skill versions: v1.0.1 yanked, v1.0.0 current

Before you upgrade

  • Back up PostgreSQL — Flyway V54–V65 run automatically.
  • OAuth's default post-login fallback is now / instead of /dashboard; set an explicit return target if you depended on it.
  • The unified identity core ships in LEGACY mode by default, so existing login behavior is preserved.

Release notes: https://github.com/iflytek/skillhub/releases/tag/v0.2.21
Source: https://github.com/iflytek/skillhub

Top comments (1)