chore(deps): update all dependencies - #39
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.1.233→2.1.2381.3.14-slim→1.4.0-slimbb05f3f→37fe63115.14.0→15.16.0Release Notes
anthropics/claude-code (@anthropic-ai/claude-code)
v2.1.238Compare Source
keybindingFlavorsetting: set it to"readline"to make Ctrl+W in the prompt delete back to the previous whitespace, as in Bash; the default ("classic") is unchangedheadersHelperon a url marketplace or a catalog entry runs a command that mints HTTP headers (e.g. a short-lived token) for catalog and same-origin archive fetchesheadersHelperruns only when you install or update that plugin, after its command is shown;claude plugin install/updateask[y/N](or pass-y)claude self-hosted-runner --defer-shutdown-max-min <minutes>: on SIGTERM, keep serving attached sessions, park what is left after that many minutes, then exitclaude self-hosted-runner --proxy-authorization-command/--proxy-authorization-filefor egress proxies that require a freshly issuedProxy-Authorizationheader on every connectionCLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=truenot keeping prompt suggestions on when your account is near, but not over, its usage limit/tmp/claude-*-cwdfiles when a Bash command is killed, times out, or is interruptedserver/discoverrequest beforeinitialize, forcing lazy servers to start their backend on every session open/modeland/effortcache-miss warning appearing when the prompt cache had already expiredclaude remote-controlinheriting session-scoped environment variables from the launching shellclaude remote-controlwas restarted; it can now be reused when you next message itListAgents/SendMessagereporting "Remote Control is not connected" in sessions run byclaude remote-control(server mode) or Desktop/IDE hosts; they now list and reach Remote Control peersListAgentsandSendMessageexposing the idle worker that the agent view pre-warms for your next background session; it now appears only once a task claims itcrossSessionInbound: "refuse") now reports "refused" to the sender instead of a silent successclaudestarts sooner on macOSclaude-apiskill for the Managed Agents Aug 19 release: web search/fetch domain settings and memory stores on self-hosted sandboxes/clearshortcut was removed, and 1-row nvim terminals no longer trigger automatic/clearloopsclaude mcp listandclaude mcp getto show disabled servers as⊘ Disabledinstead of connecting to them for a health checkheadersHelperin a project.mcp.json, and inline MCP servers in project or--add-diragent files, now require that folder's trust dialog to have been accepted (also underclaude -p)headersHelperfrom a project.mcp.json, plugin, or agent file runs without inherited credential env vars; user, managed and claude.ai-scope helpers now run from the Claude config dirv2.1.237Compare Source
v2.1.236Compare Source
ANTHROPIC_DEFAULT_MODELenvironment variable: sets the model new sessions start on, while a/modelpick still overrides it and persists across restarts (unlikeANTHROPIC_MODEL)notify_when_idleto cross-sessionSendMessage: ask another Claude Code session on this machine to send one notice when it next goes idle — opt-in, one-shot, no polling (macOS and Linux)**/.env) now take precedence inside allowed read regions, cover matched directories' contents, and can't be bypassed by renaming the denied file/modelpicker rendering taller than the terminal: it now shows only as many models as fit the window, with the rest reachable by scrollingSendMessagecalls being rejected when a malformed closing tag left the message text inside the summary fieldpowershell.exeon WSL with Windows interop disabled (regression in 2.1.234)~/.claude.jsonwas malformed/recap) is now capped at 400 characters, cut at a word boundaryMonitorallow rules are now set aside while auto mode is active, so Monitor commands are reviewed the same way Bash commands arestatus.showUntrackedFiles=nosetting into reporting a clean tree/modelpicker to highlight only the newest model's name, so the highlight marks the new release rather than an arbitrary subset of the list/goal: an idle session whose goal is parked behind long-running background work now checks in automatically after 30 minutes (then 1h, 2h) instead of waiting for you to return/usagenow shows the usage-credits spend row for Team and Enterprise members, and shows a capped row at 0% before anything is spentSendMessagenow refuses further messages to a session up front once a rapid burst would exceed what that session's inbox accepts, instead of reporting them sent while they were droppedv2.1.235Compare Source
spellchecksetting that underlines misspelled words in the prompt input as you type, using your installedaspell,hunspell, orispellsubagent_typethere now gets a clear error listing the available agentsctrl+t) always starting collapsed when resuming or relaunching into a session that still has open tasks/ultrareviewor/autofix-prrun in the background — their event streams are no longer re-scanned and re-rendered on every updategrepin native macOS/Linux builds: pathological patterns now fail fast instead of exhausting memory, and-m Nwith-A/-Cprints correct context/configto re-enable itSendMessagenow refuses messages too large for cross-session delivery up front instead of silently dropping themclaude rcnow applies the same enterprise-gateway availability check as interactive startupv2.1.234Compare Source
CLAUDE_CODE_PROJECT_DIR_NAMEenvironment variable: hosts that give each session its own config directory can choose a short name for the per-project transcript directoryselection:clearkeybinding action, so a key can be bound to clear an in-app text selection; also works in the agents view/config("Continue automatically at usage limit")\??\) paths, hardening the remaining pre-approval file accesses against the NTLM credential-leak vectorSendMessagerejecting a recipient copied fromListAgentswhen the session name is at the 200-character cap or emoji-heavy${VAR}form, and connection-failure details show only the server originstrictKnownMarketplacesallowlists accepting SCP-style git marketplace sources whose host differs from the one git would actually connect to/loginOAuth URL losing characters when copied in fullscreen---horizontal rule in rendered markdown running into the line after it/permissionsopened while a!shell command was running being dismissed when the command finished!shell command being sent to the model as plain text after pressing up-arrow to edit the queued input!mode no longer sticks after a mid-turn submit--dangerously-skip-permissions), tool allow/deny rules, model or effort flags/tuidropping launch--allowed-tools/--disallowed-toolsrules when it restarts; it now declines to switch, with the reason, when the session has restrictions a restart can't carry over/loginwhileCLAUDE_CODE_OAUTH_TOKENis set, the stale-token reminder no longer leaks into Claude's automatically resumed turn — it now appears only to youSendMessageandListAgentsnow say when your account's session list was too long to check completely, instead of treating unseen sessions as absent/loginwhen a claude.ai login would take precedenceclaude-apiskill from ~200k+ tokens to ~25k by loading reference docs on demand/permissionscan now be opened while Claude is working — rule changes apply to the rest of the current turn/add-dir <path>can now be used while Claude is working;/add-dir,/autocompact,/theme,/help,/configand/advisordialogs open mid-turn in the fullscreen TUI/goalnow clears itself with a notice when a turn dies on an unrecoverable error (e.g. revoked auth, an exhausted credit balance, or a context overflow) instead of staying armed/goal: when background tasks keep a goal waiting for 30+ minutes, Claude now checks in on them instead of waiting indefinitely (setCLAUDE_CODE_GOAL_CHECKIN_MINUTES=0to opt out)claude setup-tokennow rejects unexpected extra arguments instead of silently ignoring them/config; agent-team teammates now use the leader's model unless the spawn names one<system-reminder>tags, matching mid-turn delivery~/.claude.jsonis read-onlysickn33/agentic-awesome-skills (sickn33/agentic-awesome-skills)
v15.16.0Compare Source
[15.16.0] - 2026-08-20 - "Agent Reliability, Evidence Integrity, and Stack Audits"
This release helps Claude Code, Cursor, Codex CLI, Gemini CLI, Antigravity, and
related AI coding assistants test agent harnesses safely, distinguish run claims
from inspectable evidence, review multi-agent control flow, score recurring UI
failure modes, and keep research conclusions honest when sources disagree.
Start here:
npx agentic-awesome-skillsagent-harness-fault-injectionforbounded resilience testing with explicit cleanup and recovery gates.
audit-agent-run-evidencefor tracingagent-run claims back to logs, traces, artifacts, and reproducible checks.
multi-source-searchfor provider-optionalresearch backed by an offline, schema-validated evidence ledger.
Added
boost-asio-profor production-orientedasynchronous C++ networking with Boost.Asio, including composed operations,
cancellation, coroutine lifetimes, strands, backpressure, and testable error
paths (#1186).
agent-harness-fault-injectionforcontrolled timeouts, malformed outputs, partial failures, and recovery checks
with explicit blast-radius, consent, rollback, and evidence requirements
(#1189).
audit-agent-run-evidenceforread-only auditing of agent-run claims against recorded events, artifacts,
timestamps, identifiers, and reproducible verification steps
(#1192).
review-multi-agent-orchestrationfor reviewing delegation boundaries, shared-state hazards, handoff contracts,
retry behavior, convergence, and evidence quality in multi-agent systems
(#1193).
ui-slop-scorefor scoring recurring genericinterface patterns against a concrete product brief, reference evidence,
accessibility constraints, and a transparent weighted rubric
(#1196).
multi-source-searchfor bounded researchacross optional providers with claim-level citations, source polarity,
conflict tracking, URL canonicalization, and an offline validation script
(#1202,
#1205).
Changed
aas stack auditflow and paired browser-local Workbenchcomparison for detecting digest, catalog, target, and exact skill-set drift
between stack artifacts without applying either stack
(#1199).
youtube-transcript-apiinterfaces, common YouTube URL forms, and UTF-8 outputon legacy Windows consoles, with isolated network-free regression tests
(#1198).
supporting or contradicting, conflicts agree with that classification, and
superficial URL variants cannot inflate source diversity
(#1205).
marketplaces, editorial bundles, compatibility reports, and Codex/Claude
plugin distributions for 2,025 skills.
Security
explicit preconditions, abort thresholds, rollback, recovery verification,
and evidence capture before any resilience claim is accepted.
treats missing telemetry as success or authorizes repairs, retries, or
production actions without a separate user-approved step.
of report artifacts and an offline validator that fails closed on missing
evidence, inconsistent conflict state, or duplicate canonical sources.
before any installation or workspace mutation can be considered.
Who should care
cancellation, serialization, backpressure, and shutdown contracts.
outcomes are actually supported by durable evidence.
convergence risks before expanding autonomy.
a real brief rather than subjective aesthetic claims.
exact stack-artifact drift detection.
Validation
checks, warning-budget enforcement, the complete repository test suite,
plugin-compatibility and bundle checks, web-app install/build/prerender, and
the npm package dry run on the protected release base.
provenance, declared risk, limitations, consent boundaries, and relevant
regression coverage; also reviewed the YouTube compatibility and stack-audit
changes against their isolated tests.
Limitations
scenario; it does not prove resilience to untested failures or authorize
experiments against production systems.
control-flow risks but do not reconstruct missing telemetry or implement the
fixes they recommend.
ui-slop-scoreis a transparent heuristic tied to supplied references andconstraints, not an objective guarantee of visual quality or user success.
access; source count cannot replace source quality, and unresolved conflicts
remain unresolved in the final report.
or mutate an installation.
Credits
boost-asio-proinPR #1186.
agent-harness-fault-injection,audit-agent-run-evidence,review-multi-agent-orchestration,and the paired stack-audit source contributions in
PRs #1189, #1192, #1193, and #1199.
uizze/uizze source for
ui-slop-scoreinPR #1196.
transcript API compatibility repair ported in
PR #1198.
@denial123789 for
multi-source-searchand its evidence-integrityfollow-up in PR #1202
and PR #1205.
v15.15.0Compare Source
[15.15.0] - 2026-08-18 - "Evidence, Durable Context, and UI Contracts"
This release helps Claude Code, Cursor, Codex CLI, Gemini CLI, Antigravity, and
related AI coding assistants keep claims attached to evidence, preserve verified
project knowledge across sessions, evaluate agent outcomes without denominator
drift, and carry product contracts consistently from storage to clients.
Start here:
npx agentic-awesome-skillsdsh-deepreadfor evidence-first document analysis.using-lwcfor durable, source-grounded project memory.anti-ui-slopfor product-specific UI contracts and ahard finish gate.
Added
anti-ui-slopfor grounding web and iOS work inreal interface references, explicit product contracts, required interaction
states, and a finish gate that rejects generic coding-agent defaults
(#1166).
liuguang-banlan-uifor two parameterizediridescent UI modes with OKLCH authoring, deterministic WebGL and CSS fallback,
reduced-motion handling, screenshot QA, and measurable color reports
(#1154).
using-lwcfor durable, source-grounded agent memoryacross Wiki document and CodeGraph planes, with explicit scope, installation,
initialization, and write-consent boundaries
(#1152).
dsh-deepreadfor evidence-first reading ofarticles, books, PDFs, web pages, and document sets through claim ledgers,
argument analysis, knowledge maps, and Feynman checks
(#1174).
agent-evaluation-reportingforkeeping autonomous, assisted, failed, timed-out, and invalid evaluation
outcomes distinct, with explicit denominators, uncertainty, and readiness
gates (#1177).
cross-platform-contract-propagation-auditfor read-only tracing of fields, enums, flags, and API contracts across
storage, services, clients, analytics, rollout controls, and tests
(#1178).
Changed
JSON-array response for
npm view --json, while rejecting empty or ambiguousmulti-item results and preserving fail-closed
gitHeadverification(#1167).
diff can proceed without weakening the rejection of missing or non-empty
evidence
(#1171,
#1172,
#1173).
marketplaces, editorial bundles, compatibility reports, and Codex/Claude
plugin distributions for 2,019 skills.
Security
changes; missing, empty, changed, or ambiguous registry identity remains a
hard installer failure.
liuguang-banlan-uiandusing-lwcwith explicit provenance, risk labels, consent gates, pinned LWCbootstrap identities, reduced-motion behavior, renderer fallback, and
regression coverage
(#1169).
explicit network approval, and kept LWC installation, global initialization,
and durable writes behind current user authorization.
Who should care
claims remain linked to inspectable source evidence.
survive across agent sessions without silently widening workspace authority.
accessible iridescent rendering workbench.
denominators, explicit readiness gates, and evidence for every contract edge.
contributor-credit workflows that fail closed on ambiguous evidence.
Validation
checks, warning-budget enforcement, the complete 111-group repository test
suite, plugin-compatibility and bundle checks, web-app install/build/prerender,
and the npm package dry run on the protected release base.
provenance, declared risk, limitations, consent boundaries, and relevant
regression coverage.
Limitations
dsh-deepreadrequires readable source material and cannot recover or inventcontent that the host agent could not retrieve.
using-lwcdocuments LWC workflows but does not bundle an initialized Wiki,trusted project scope, or permission to install software or write memory.
use needs approval, screenshot claims need actual image inspection, and WebGL
environments still require the documented fallback and accessibility checks.
missing data comparable or implement the repairs they identify.
Credits
uizze/uizze source for
anti-ui-slopinPR #1166.
liuguang-banlan-uiinPR #1154.
JanYork/using-lwc for
using-lwcinPR #1152.
xiehuan123/dsh-deepread for
dsh-deepreadinPR #1174.
agent-evaluation-reportingandcross-platform-contract-propagation-auditin PR #1177
and PR #1178.
in PR #1167.
Configuration
📅 Schedule: (in timezone UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.