chore(deps): update all dependencies - #42
Merged
Merged
Conversation
gw0-bot
force-pushed
the
renovate/all-deps
branch
from
August 25, 2026 09:48
ddd3872 to
a9ec5e6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.1.241→2.1.24515.16.0→16.0.0Release Notes
anthropics/claude-code (@anthropic-ai/claude-code)
v2.1.245Compare Source
v2.1.243/usage: per-loop run count, total tokens, tokens per run, and last run, so runaway or chatty/looptasks are easy to spotmodelPickersetting: curate the/modelpicker with an ordered, labeled list of models (any id spelling, including Vertex/Bedrock ids), appended to or replacing the built-in lineuppromptCacheTtlandsubagentPromptCacheTtlsettings so API-key and cloud-provider users can keep a 1-hour prompt cache on the main conversation while subagents stay at 5 minutesmodelPricingmanaged setting so an organization's contracted per-model rates and discount multiplier are used for/cost, the status line, and telemetry cost figures instead of list price/login→ Anthropic Console: "Sign in with your Console account" (recommended) alongside creating an API key, so organizations that don't allow API keys can sign inSkipped sourcesline to/statusthat lists managed settings sources (for examplemanaged-settings.json) present but not applied because a higher-precedence managed source is activemanagedmarker in/mcpand/pluginson claude.ai connectors whose authentication is managed by your organization/web-setup/statusline showing whether GitHub is connected for Claude Code on the web (Pro/Max), pointing to/web-setupwhen it isn't/tasksand the agent detail dialogs-p) and SDK sessions never recovering after a dropped connection; they now reconnect automatically or report as failed/modelpicker silently ignoring an Ultracode selection; picking Ultracode now applies it to the current session/resumeonly listing the 50 most recent sessions; the picker now loads more as you scroll/login) losing its leading columns when another part of the screen repaintsspellchecknot underlining a misspelled word typed directly after an emojiAPI Error: No response from APIcompanyAnnouncementsnot showing at startup in a session that began with signing in (for example the first launch after/logout)ifconditions likeBash(cat *)firing on unrelated Bash commands when the command contained$()or backtick command substitution followed by more argumentsmarketplacefield never resolving when both plugins are loaded together via--plugin-dir/reload-pluginskeeping the LSP tool after the last LSP plugin is disabled; it now also warns before an LSP plugin change that would re-read the conversation--agentssilently ignoring invalid JSON or invalid agent definitions; it now exits with a clear error, like--mcp-config/statusshowing "Found invalid entries in: ." with no filename when~/.claude.jsonhas an invalid MCP server entry/clearremoving the/renamesession name from the prompt bar even though the name was kept for the new session~/.claude/history.jsonlcontains a malformed entryHTTPS_PROXY(and sometimes failing) whenlocalhostwas listed inNO_PROXYbut not lowercaseno_proxy; both casings are now honoredcurlprinting the proxy's 403 page)rate_limitsfields and/usagestill showing a rate-limit window's pre-reset usage percentage after the window reset while the session was idleclaude --teleport <session>exiting on uncommitted changes instead of offering to stash them and continue, as the session picker already does/web-setuprepeatedly asking you to log in when an older GitHub CLI (withoutgh auth token) was already authenticatedclaudelauncherANTHROPIC_AUTH_TOKENdirectly against the Anthropic API, so its data-handling settings apply/loginover SSH: the sign-in URL appears immediately, pressingcreports how the URL was copied instead of always claiming success, and a hint explains how to select text in fullscreenxhigh/maxis used with thinking turned off: it now names the level, the setting that disabled thinking, and/effort highas the fix/loop: consecutive wake-ups where Claude has nothing to do now fold into a single line in the terminal instead of printing each one/modelpicker and the bundledclaude-apiskill to show Sonnet 5's $2/$10 per Mtok pricing as its standard list price rather than a limited-time promo/model,/fast, and/effortto also run immediately instead of queueing until the turn ends on Bedrock, Vertex, and Foundry and when telemetry is disabledclaude remote-controlexiting and stranding attached Remote Control sessions when the server drops its environment mid-session; it now recoversclaude remote-controlsometimes getting stuck after it was stopped and restarted, for Team and Enterprise members without an admin or owner rolesickn33/agentic-awesome-skills (sickn33/agentic-awesome-skills)
v16.0.0Compare Source
[16.0.0] - 2026-08-24 - "Durable Project State and Runtime Reliability"
This release helps Claude Code, Cursor, Codex CLI, Gemini CLI, Antigravity, and
related AI coding assistants preserve verified project state across sessions,
operate the Famulor platform with explicit tool and consent boundaries, and use
current Salesforce and X/Twitter integration patterns without weakening safety
or evidence requirements.
Start here:
npx agentic-awesome-skillsproject-state-governorfor reconstructing,validating, and maintaining durable project state from authoritative evidence.
famulor-skillfor selecting and operating FamulorMCP tools across assistants, calls, campaigns, automations, and related areas.
Added
project-state-governorfor durableproject-state reconstruction and maintenance with authority ordering, compact
and scaled schemas, lifecycle rules, negative evidence, and independently
verified completion transitions
(#1214).
famulor-skillwith a 282-tool snapshot,task-oriented toolset maps, assistant-design guidance, consent boundaries,
and live-schema verification requirements
(#1224).
Changed
salesforce-developmentaroundcurrent API-version configuration, External Client Apps, OAuth security,
integration patterns, deployment, and testing guidance
(#1213).
x-twitter-scraperfor its current SDKand tightened consent, credential, rate-limit, privacy, and automation
boundaries (#1220).
express-rate-limitfrom 8.6.0 to 8.6.1(#1216).
external skills CLI to skip otherwise valid skills
(#1218).
uizze-ui-researchsource listing and synchronizedits stale bundle memberships while keeping the maintained
anti-ui-slopworkflow (#1225,
#1228).
marketplaces, editorial bundles, compatibility reports, and Codex/Claude
plugin distributions for 2,026 skills.
Fixed
security module explicitly before ACL inspection and hardening
(#1221,
#1227).
invoking the npm CLI through Node instead of spawning
npm.cmddirectly(#1222,
#1227).
uizze-ui-researchbundle memberships after the retired skillwas removed from the canonical catalog.
Security
preserves the current lifecycle state, records the evidence gap separately,
and never promotes child completion to a project-level claim.
inspection for authoritative parameters, and made consequential external
actions subject to explicit user confirmation and platform permissions.
bounded by user consent, platform rules, rate limits, and privacy constraints.
PowerShell security module, and preserved immutable npm release-identity
verification under the npm 12 invocation path.
Who should care
model which survives context loss without turning unverified claims into fact.
while preserving schema, scope, consent, and side-effect boundaries.
automation, privacy, and rate-limit guidance.
Validation
checks, warning-budget enforcement, the complete repository test suite,
plugin-compatibility and editorial-bundle checks, canonical artifact preview,
and protected canonical synchronization.
safety, provenance, declared risk, limitations, consent boundaries, and exact
head evidence before protected merge.
npm-managed Windows release-identity invocation.
Limitations
does not create evidence, replace domain verification, or authorize cleanup
beyond the user's stated boundary.
server; workspace permissions, plan entitlements, and consent still govern
which operations are available.
release, so live schemas and official platform constraints remain authoritative.
they do not substitute for every possible enterprise PowerShell policy or npm
installation layout.
Credits
project-state-governorinPR #1214.
Famulor Skill source for
famulor-skillinPR #1224.
guidance update in
PR #1213.
refresh in PR #1220.
the eight frontmatter delimiters in
PR #1218.
Configuration
📅 Schedule: (in timezone UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.