chore(deps): update all dependencies - #43
Merged
Merged
Conversation
gw0-bot
force-pushed
the
renovate/all-deps
branch
from
August 27, 2026 14:55
09b62d5 to
91a0816
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.1.245→2.1.247db488dd→cdf488f0.45.0→0.46.016.0.0→16.2.0Release Notes
anthropics/claude-code (@anthropic-ai/claude-code)
v2.1.247Compare Source
SendFeedbacktool: when something goes wrong in a session, Claude can draft a feedback report for you to review and send from/feedback(turn off with thefeedbackDraftssetting){id, text, cooldownSessions, priority}entries,tipsFile, andlabeltospinnerTipsOverride, so organizations can rotate their own tips alongside the built-in ones/claude-api cost-optimizeto profile an existing project's Claude API spend and work through cost levers (caching, token hygiene, batch, effort, model choice) one measured change at a time/claude-apiskill with Admin API coverage (organization members, invites, workspaces, API keys, rate limit reports, workload identity federation, CMEK)/config,/mcp,/skills, background tasks, and/model<35;150;7Mbeing inserted into the prompt when a mouse report arrived split across reads right after the escape prefix~/.claude/settings.jsonsymlink (nix/home-manager, stow) when it is repointed outside the sandbox's writable area/terminal-setupoverwriting your entire Zedkeymap.jsoninstead of merging in its keybinding/renamesilently confirming when the session registry could not be updated; it now says other sessions may still show the old name/compactand "Summarize from here" in sessions started with--agentsummarizing under the default system prompt instead of the conversation's ownclaude agentsafter its terminal host process died; the row now fails within seconds with the reason, and Enter restarts it/install-github-appover SSH: the copy shortcut now says how the sign-in URL was copied instead of always claiming success, and the URL appears immediately when no browser can open[exited with code -1]line when they finish in background sessions/remote-controlnot reporting the working-tree diff to connected clientsrunningbefore Claude Code had started, which could trigger a premature "Claude is waiting for your input" notification from the Claude desktop app/pluginandclaude pluginoutput is escape-safeMessage from @<sender>: <first line>preview; Ctrl+O expands the full bodysurface=claude_codedevice-authorization parameter and aclaude-code/<version>User-Agent)v2.1.246Compare Source
Bash(git * main)), since they also match options inserted before the subcommand/permissionsfor viewing and editing auto mode classifier rules✻ Sautéed for 23s · done 6:05 PM+/N)lists and setext headings{}), instead of their real type/backgroundduring a dynamic workflow restarting its finished subagents; it now asks first and says how many subagents would restartclaude agentswhile its worker was still booting (common on Windows) stopping it with "was stopped while the respawn was in flight"claude agentslisting a backgrounded named session twice; backgrounding the same conversation again now numbers the new row (e.g.my-session (2)).claude/worktrees/that you created yourself when an old background-session record pointed at themnamealready includes the<plugin>:prefix showing it doubled in the slash menu (e.g./plugin:plugin:skill)claude plugin updatefailing for an installed plugin given its bare name (only the fully-qualified name worked)plugin.jsonwas saved with a UTF-8 byte-order mark (BOM)/reload-pluginsreporting 0 skills for plugins that define skills underskills/*/SKILL.md${CLAUDE_PLUGIN_ROOT}instead of the resolved plugin path/renamereplacing the theme's prompt border color (including a custom theme'spromptBorder) with the default cyan; the border now keeps your theme's color unless you pick one with/colordiffAdded/diffRemovedand their dimmed variants) being ignored in diffs and the/themepreviewkeybindings.jsonbinding with an unknown action name silently deadening that key; it is now skipped so the default binding keeps working, and a warning is logged under--debug/statsactivity heatmap showing each day's activity one cell off (Sunday's count under Monday) in timezones east of UTC/forkfrom an already-forked or backgrounded session starting the new session with an empty conversation/--(e.g. Lean doc comments) being rejected as an unknown slash command instead of being sent to Claude@file picker staying open after the typed text stopped matching a real path~/.claude/sessionsleft by sessions that exited uncleanlyANTHROPIC_BASE_URL) streams atool_useblock without anidclaude plugin install <name>exiting silently (or hanging in a terminal) instead of reporting an error when~/.claude/plugins/known_marketplaces.jsonis empty or corruptedcurl -fsSL https://claude.ai/install.sh | bashfailing with "Raw mode is not supported" for some Team/Enterprise users with server-managed settingsclaude -p --continue/--resumewith a permission prompt tool, when no permission mode was setNotificationhook not firing while the sandbox "Network request outside of sandbox" permission prompt is waiting&&or||operator--strict-mcp-configsessions prompting to approve.mcp.jsonservers they would never load, which left background sessions waiting at startupANTHROPIC_BASE_URL); a credential is now only sent to its own hostapiKeyHelperreturns short-lived JWTs: an expired cached token is now refreshed before sending, and 401/403 auth errors retry quietly/ultrareviewruns and cloud sessions launched at the same time from one repository (e.g. from several worktrees) sometimes starting with another launch's uncommitted changes3/5) shown for background cloud sessions such as/autofix-proccasionally missing a taskrequiresUserInteractionstill offering "Yes, and don't ask again" in their permission prompt; the option wrote an allow rule the tool then ignored/cd: the new directory's project settings, hooks,.mcp.jsonservers (behind the usual approval prompt), skills, and agents now take effect right after the move instead of on--resumemaxTurnslimit now returns its output marked as partial, with a hint to continue it viaSendMessage, instead of appearing finished-p, SDK, cloud sessions) to automatically continue a response cut off mid-stream by a server error, connection loss, or stall instead of ending with an errorapiKeyHelperruns at startup, and after a login token expired while idle/code-reviewso Claude can also start it on its own on Bedrock, Vertex AI, and Foundry, through the Claude apps gateway, and when telemetry or non-essential traffic is disabled/goal: Changed idle sessions to start at most three check-ins on long-running background work per goal; your next message allows three moreclaude installandclaude updateto defer a pending managed-settings consent prompt to the next interactive session instead of prompting mid-commandplugin_id_hashnow reflects the plugin's real marketplace, andenabled_viaisadmin-installfor admin-installed plugins--setting-sourcesrtk-ai/rtk (rtk-ai/rtk)
v0.46.0Compare Source
Features
Bug Fixes
Other
sickn33/agentic-awesome-skills (sickn33/agentic-awesome-skills)
v16.2.0Compare Source
[16.2.0] - 2026-08-26 - "Security Operations Expansion and Safer Integrations"
This release expands defensive security, authorized assessment, reverse
engineering, incident-response, and threat-intelligence coverage while keeping
high-impact operations behind explicit scope, authorization, evidence, and
environment-safety gates.
Added
zhaoxuya520/reverse-skillcollection, spanning reverse engineering, malware analysis, forensics,
threat hunting, API and identity security, firmware, wireless, cloud,
supply-chain, and authorized assessment workflows
(#1247).
instructreefor generating and validatingscoped repository instruction trees without walking outside the selected
project root
(#1251).
muapi-mediafor authenticated MuAPI image,video, and music generation with explicit cost, credential, and output
handling
(#1257).
api-rate-limit-handlerforretry-aware API clients with bounded backoff, jitter, idempotency guidance,
and billable-request safeguards
(#1258).
Changed
express-rate-limitfrom 8.6.1 to 8.6.2 in the generated Loki Modeexample dependency set
(#1256).
marketplaces, editorial bundles, compatibility reports, and Codex/Claude
plugin distributions for 2,074 skills.
Fixed
tree-ring-memoryinstallationguidance to target the reviewed
v0.15.0release and aligned its declaredrisk with its install and update mutations
(#1253).
the complete canonical skill subtrees remain text-safe and reviewable.
multiplying non-idempotent or billable operations.
Security
imported security collection; only reviewed Markdown skill content and
references are distributed.
stop-condition gates across offensive and dual-use security workflows.
guidance as critical risk, with secrets supplied through environment or
secure input rather than command-line arguments.
v16.1.0Compare Source
[16.1.0] - 2026-08-25 - "Specification-First Delivery and Mistake-Proofing"
This release helps Claude Code, Cursor, Codex CLI, Gemini CLI, Antigravity, and
related AI coding assistants freeze requirements before implementation, design
controls that prevent predictable mistakes, preserve consistent project-state
transitions, and query durable repository knowledge without weakening approval,
provenance, or path-safety boundaries.
Start here:
npx agentic-awesome-skillsspec-driven-loopfor a specification-firstworkflow with frozen artifacts, non-overlapping agent ownership, and an
independent delivery judgment.
poka-yokefor replacing reminders with controls,warnings, and bounded detection that make software mistakes impossible or
immediately visible.
Added
spec-driven-loopwith PRD, technicaldesign, acceptance-criteria, ownership, and completion artifacts; explicit
approval before implementation; bounded rework; and independent lead-agent
judgment backed by diffs, tests, and evidence
(#1242).
poka-yokefor identifying software error trapsand selecting the strongest practical device on a control, warning,
detection, or instruction ladder
(#1240).
Changed
project-state-governorworkstream completion with
COMPLETEDand retainedCANCELLEDin thecanonical milestone lifecycle vocabulary
(#1241).
loreto its reviewed upstream layout, movedworkflow guidance into the supported reference tree, refreshed its scripts
and compatibility documentation, and preserved the repository's stricter
mirror-target containment rules
(#1244).
@supabase/supabase-js2.111.0 to 2.112.0,including upstream authentication, PostgREST, storage, retry, and opt-in
tracing fixes (#1244).
timeouts to the truthful
manual-review-requiredpath instead of allowing anindefinitely running review job
(#1244).
marketplaces, editorial bundles, compatibility reports, and Codex/Claude
plugin distributions for 2,028 skills.
Fixed
sincevalue no longerinjects Git's epoch cutoff and silently omits existing commits.
path and time boundary while retaining fail-closed path validation.
Security
spec-driven-loopimplementation behind explicit specificationapproval, separated agent ownership, and evidence-based completion instead
of treating generated artifacts or self-reported status as proof.
poka-yokeread-only and analysis-first: consequential code or processchanges still require proposal, authorization, and validation, and detection
is not presented as equivalent to a preventive control.
targets, and pinned license provenance to the reviewed upstream commit.
head maintainer-review requirement; it is never reported as an automated
semantic pass.
Who should care
ownership, acceptance evidence, and final judgment to stay independently
inspectable.
concrete preventive or self-announcing controls.
repositories, mirrors, and successor entries.
PostgREST, retry, and tracing behavior.
Validation
warning-budget enforcement, the complete 113-group repository test suite,
web-app tests and production build, npm package dry-run, plugin compatibility,
bundle checks, and protected canonical synchronization.
refresh for semantics, safety, provenance, declared risk, limitations,
references, scripts, and exact-head evidence before protected merge.
upstream Lore test coverage for history, containment, and mirror behavior.
Limitations
spec-driven-loopstructures planning and evidence; it does not prove domaincorrectness, replace stakeholder approval, or authorize implementation
outside the approved scope.
poka-yokehelps select stronger controls, but compatibility and systemconstraints may leave only warning or detection fallbacks; those weaker
rungs must remain explicit.
it cannot reconstruct missing commits or validate external systems by itself.
documentation and service behavior remain authoritative.
Credits
spec-driven-loop source for
spec-driven-loopinPR #1242.
poka-yokeinPR #1240.
lifecycle correction in
PR #1241.
synchronization proposed in
PR #1237 and
integrated through
PR #1244.
PR #1239 and
integrated through
PR #1244.
Configuration
📅 Schedule: (in timezone UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.