SkillHub v0.2.21 shipped on 2026-09-19. Instead of summarizing the release notes, we pulled the tag, started it locally with the official compose.release.yml, and recorded each headline update as it actually runs. Every screenshot below comes from that local run; the skills and suites are fictional sample data.
The deployment
Images skillhub-server, skillhub-web and skillhub-scanner at v0.2.21 (server image revision matches the tag). All five services — PostgreSQL, Redis, scanner, server and web — reported healthy, and Flyway migrations V54 through V65 applied automatically on first start.
Two flags are required for the full bundle flow: SKILLHUB_SUITE_BUNDLE_CONFIRMATION_ENABLED=true and SKILLHUB_SUITE_REVIEW_WRITES_ENABLED=true. We also kept the security scanner on — public bundle members are rejected at preview time without it.
1. Two-stage Suite Bundle publishing
A Suite Bundle is one ZIP (or folder) with a single SUITE.yaml at the root plus one directory per member skill. Uploading it produces a member change preview: target coordinate and version, each member's relationship (added, updated, unchanged, removed), and the publish action.
The preview has no side effects — no Skill versions, review tasks or Suite versions are created. Only Confirm and start publishing starts work. SkillHub then creates a durable task: each member goes through the existing scan/publish/review path, and the Suite draft is created only when every member is ready. The task page can be reopened after a refresh.
2. CLI sign-in with OAuth Device Flow
skillhub login without a token now starts a device flow. With --no-open (useful on headless machines) it prints the verification URL and a one-time code:
After approval on /device, the CLI validates the token before saving it and prints Logged in … as <handle>; skillhub whoami confirms it. Output never includes the secret.
3. Pi as a first-class agent target
skillhub install <slug> --agent pi --scope project installs into .pi/skills/<slug> (user scope uses .pi/agent/skills).
Also in this release: yank from the web
Skill owners and namespace admins can yank a published version through the Web/API lifecycle endpoints (skill:yank token scope). In our run, v1.0.1 was yanked and the current version fell back to v1.0.0. Concurrent yanks of the same version are now serialized on the same row lock.
Before you upgrade
- Back up PostgreSQL — Flyway V54–V65 run automatically.
- OAuth's default post-login fallback is now
/instead of/dashboard; set an explicit return target if you depended on it. - The unified identity core ships in
LEGACYmode by default, so existing login behavior is preserved.
Release notes: https://github.com/iflytek/skillhub/releases/tag/v0.2.21
Source: https://github.com/iflytek/skillhub







Top comments (1)