
Security News
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold Outreach
An AI agent is merging PRs into major OSS projects and cold-emailing maintainers to drum up more work.
@hubspot/cli
Advanced tools
A CLI for HubSpot developers to enable local development and automation. Learn more about building on HubSpot.
For more information on using these tools, see Local Development Tooling: Getting Started
npm install -g @hubspot/cli
Once the @hubspot/cli has been added to a project, a config file named hubspot.config.yml will also be needed. It is recommended that the config file is kept in your $HOME directory.
cd ~
hs init
You can set up command autocompletion by running
hs completion
and copying the output to either your .bashrc or .zshrc, and then sourcing that file source ~/.bashrc source ~/.zshrc or restarting your terminal.
A full breakdown of the commands can be found on the local development tools reference page.
Note: When @hubspot/cli is installed local to a project, the commands need to be prefixed with either yarn if using yarn or npx if using npm.
There are two ways that the tools can authenticate with HubSpot.
hs init or hs auth personalaccesskey and follow the instructionshs auth oauth2OAuth2 and follow the stepsNote: The Account ID used should be the Test Account ID (not the developer app ID). Client ID and Client Secret are from the developer app.
The CLI will exit with one of the following exit codes:
0: A successful run1: There was a config problem or an internal error2: There are warnings or validation issuesThe best way to stay up to date is to check out the Github Releases and also follow our developer changelog posts for an easier to read breakdown of major changes.
FAQs
The official CLI for developing on HubSpot
The npm package @hubspot/cli receives a total of 39,292 weekly downloads. As such, @hubspot/cli popularity was classified as popular.
We found that @hubspot/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 40 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
An AI agent is merging PRs into major OSS projects and cold-emailing maintainers to drum up more work.

Research
/Security News
Chrome extension CL Suite by @CLMasters neutralizes 2FA for Facebook and Meta Business accounts while exfiltrating Business Manager contact and analytics data.

Security News
After Matplotlib rejected an AI-written PR, the agent fired back with a blog post, igniting debate over AI contributions and maintainer burden.