chore(deps): update bump-dependencies - #75
Merged
Merged
Conversation
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.1.278→2.1.2832.1.285(+1)0.86.0→0.87.10.99.1(+1)0.156.1→0.157.10.159.2(+3)2.3.5-1~debian.13~trixie→2.3.6-1~debian.13~trixieWarning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
anthropics/claude-code (@anthropic-ai/claude-code)
v2.1.283Compare Source
x-claude-code-prompt-idto the gateway hint headers so LLM gateways can group the requests that serve one user prompt; opt in withCLAUDE_CODE_GATEWAY_HINT_HEADERS=1availableModelsMatchmanaged setting: with"exact", anavailableModelsentry allows only the model version it names, so new releases stay blocked until listeddeniedModelsmanaged setting to block specific models, even whenavailableModelsallows themtool.outputOpenTelemetry span event whenOTEL_LOG_TOOL_CONTENT=1/doctor prompt-audit(also/checkup prompt-audit) to audit your CLAUDE.md files, skills, agents and commands for prompting patterns written for older modelspathto--plugin-dirload-failure entries in the stream-jsonsystem/initplugin_errors, naming the directory that did not loadload_test_modeblock to the Claude apps gateway config: requests are built and signed but not sent upstream, and clients get a canned reply, so a deployment can be load testedmantleupstream provider to the Claude apps gateway for Amazon Bedrock's Mantle endpointresult.usage/mcpno longer offers Authenticate for such servers/usageand the VS Code usage meters when telemetry is disabled/modelaccepting Sonnet 4.6 or Sonnet 5 with[1m]when the id carried a date or-v1:0suffix, in the cases where the plain id was refused/modelpicker showing a hardcoded Haiku version and price whenANTHROPIC_DEFAULT_HAIKU_MODELpins a different modelDISABLE_PROMPT_CACHING_HAIKUhaving no effect when Haiku is the session's main modelclaude plugin validatesaying Claude Code accepts a plugin or marketplace name it cannot install; such names inmarketplace.jsonnow fail validationclaude plugin validatepassing plugins whoseoutputStyles,themes,monitors, orlspServerspaths are missing or point outside the plugin directoryclaude plugin detailsshowing 0 MCP servers for plugins that declare their servers inplugin.jsonclaude plugin marketplace removenot saying which installed plugins it uninstalled with the marketplace; it now lists themclaude plugin uninstallremoving the other of two installed plugins whose ids differ only in case, with its options and secrets, when the one named had noenabledPluginsentry at that scopeinstalled_plugins.jsonshowing no plugins when it holds a record under an invalid plugin id; such a file loads againinstalled_plugins.jsonbeing rewritten, losing records, when it holds a record this version cannot read;claude plugincommands now name the record and say how to recover/contextnot counting MCP server instructions: they now appear as their own row and count toward the totalclaude mcp add,add-json, andremovereporting success when the user or local config file could not be written, for example inside a sandboxcmdan alias ofmeta, which could producecmd+shortcuts most terminals never sendkeybindings.jsonsilently accepting a misspelled modifier such asctl+k; it now warns in the debug log and suggests the fixfooter:openSelectedwas rebound or unbound inkeybindings.jsonGIT_CONFIG_COUNTenvironment pairsgitasking credential helpers to store the sandbox proxy's login, which printed "failed to store"sandboxsettings being ignored entirely when one nested value was invalid; the invalid value now fails closed and the rest of the block still appliesDISABLE_TELEMETRYorDO_NOT_TRACK/remote-controlmenu cutting its QR-code hint mid-word in narrow terminals.dropping a Shift+Enter newline, leaving the cursor inside an accented letter, and repeating an older change after3Jor Visual-modeJon the last lineVthenpnow lands on the first non-blankJjoining lines with different spacing than Vim (such as a space before)or after a tab), and3Jor Visual-modeJon the last line not moving the cursor as Vim doescmd /c rd,rmdir,delorerasedelete drive roots, the home folder and other folders thatRemove-Itemrefuses/mcptool list: it shows more tools at once, scrolls with the page keys and mouse, and marks tools your organization blocked with a warning icon/tasks: rows show a status icon, the name and whole facts, the title and key hints stay on screen with many tasks, and the list gains paging keys, the mouse wheel and clicks/help,/hooks,/copy,/chrome,/memory,/ide,/release-notes,/rewind,/diff,/remote-env,/pluginand other pickers with page keys, mouse wheel and clicks/skillsand/artifacts, to draw their pointer dim while the search box has the keys, so only one pointer is highlightedprompt-auditon Claude Code configuration: stale paths, stale commands and contradicting instruction files now lead the report, and thinking keywords that Claude Code documents are keptinstalled_plugins.jsonthat cannot be read at all: its contents are kept in a file beside it before it is rebuilt, andclaude plugin listnames that fileclaude -pand Claude Code Remote no longer load the interactive UI, and the auto-mode classifier's rules and the Artifact tool load on first use instead of at launchpermissions.defaultModestill overrides it/ultrareviewlaunch dialog to say that reviewing a local branch may upload uncommitted changes to tracked files/modelpicker's Opus row and the Default model's name to drop "(1M context)" where Opus already has a 1M context window; the window is unchanged--system-promptand--append-system-promptto accept their text and-fileforms together; the file's text comes firstSkill(anthropic-skills:<name>)deny rules to also block that skill when Claude Desktop delivers it as a plugin, andSkill(skill:<name>)denies to match the skill's alias and display name/rewindand/difflists to move on the same keybinding actions as every other list (select:*);messageSelector:*/diff:*rebinds still work/workflowsrun list to size itself like other lists: half the terminal inline, and it keeps its title on screen when the prompt shows belowclaude plugin evalto require git 2.31 or later when git is installed; a run on an older git is refused with a message naming the versionpre-pushhook, ignore a writable systemcore.hooksPath, and not sign commits without--configure-gitGIT_SSL_CAINFOandGIT_SSL_NO_VERIFYunder Anthropic-managed git: the runner's own git always verifies Anthropic's git route, and warning lines say what applies whereclaude-ainame: skills, commands, workflows and MCP servers' skills and prompts so named load again, andSkill(claude-ai:*)rules are ordinary prefix rulesv2.1.282Compare Source
maxProseWidthsetting that caps the width of Claude's prose in wide terminals while tables and code blocks keep the full width/statusandclaude doctorentries, listing telemetry variables in a project's settings files that were ignored or that turned telemetry offallowClaudeInChromeWithManagedMcpmanaged setting to letclaude --chromerun alongside an exclusivemanaged-mcp.json; the error shown when Chrome is blocked now names itstore.readiness_grace_secondsto the Claude apps gateway so/readyzcan stay ready through a short Postgres outage such as a database failover/feedbackdrafts list in fullscreen mode; it appears while the mouse is over the list--continue,--resume) re-sending earlier messages in a changed form, which could make the API drop Claude's earlier reasoning/model,/rename,/artifactsor another immediate slash command was used while Claude was working--toolslist that leaves out a built-in tool offered earlier in the conversationdatainredacted_thinkingblock" API error; Claude Code now drops the conversation's thinking blocks and retries once/modelwith a full Fable model id stopping at an API error instead of opening the usage-credits prompt when the plan needs usage credits that aren't turned on yet/Networkvia..or a/.vol-style kernel path, or a rules link to macOS's/homebeing listed:*being skipped in settings files while--allowedToolshonored them; they now work from every source, with a startup warning on how they matchdisableClaudeAiConnectorsorallowManagedPermissionRulesOnly; the lock now applies and startup names the keypermissions,autoMode,worktreeandattributionsettings being ignored entirely when one nested value was invalid; the rest of the block now still applies--add-dirskills, commands and skills-directory plugin manifests pre-approving their own tools viaallowed-toolsunder managedallowManagedPermissionRulesOnlySessionStarthookclaude remote-control --debugfailing with "Unknown argument: --debug", although Remote Control's own eligibility error says to run with--debug/install-github-appsaying "cancelled" and then still pushing the branch and saving the API key secret; leaving now stops the remaining steps and reports what was already done/in/skillsmoving the skill list instead of reaching the search box/skillssearch box to the skill list while typing, which could hide the caret and put IME input in the wrong place/skillsand/mcp, being two columns narrower outside fullscreen mode, where the scrollbar can never appear·separator in the/tasksdialog footer when the stop-all-agents shortcut is unbound inkeybindings.json>>indenting empty lines,rwith a count longer than the line changing text,2Jjoining one line too many, and a count on the last line (2dd,2>>) shifting or deleting itdd,dj,dGor a whole-linep/Pit lands on the first non-blank,yyno longer moves it, and Esc after an emoji no longer leaves it inside the emoji.when repeatingx,s,p,dorc, and whole-linep/P,o,O,J,>>and<<acting on the wrong line when a line above wrapsxdid nothing/artifacts: titles line up in one column, details are dropped whole instead of cut mid-word, and the list supports PgUp/PgDn, Home/End, the mouse wheel and clicksclaude-apiskill: pre-output refusal billing now links to the How refusals are billed docs, mid-stream refusals bill at normal rates, and pre-output refusals count against rate limitsclaude-apiskill to recommendant applyfor keeping Managed Agents resources as version-controlled filesCLAUDE_CODE_AUTO_MODE_SERVER=0opts out)sandbox.excludedCommandsto ignore project and local settings entries when managed settings or--settingssetallowUnsandboxedCommands: false, or managedallowManagedDomainsOnly: trueCLAUDE_CODE_ENABLE_TELEMETRYandOTEL_LOG_*managed-settings.json) keeps user-writable HKCU and WSL/etc/claude-codefrom applyingSkill(anthropic-skills:*)andSkill(claude-ai:*)allow rules to cover only skills synced from claude.ai, not plugins or other skills that merely use such a nameanthropic-skillsorclaude-ainamespace to no longer load; a plugin so named still loads but yields name ties to synced skillsanthropic-skillsorclaude-aito list no skills or prompts (their tools still work); rename the server in your MCP configuration to list them againultracodevisuals in/effortand the prompt input to plain styling (no ripple, border flourish or keyword glimmer) and removed the dynamic-workflows spinner tipv2.1.281Compare Source
desktoppolicy blocks, includingblockReadsOutsideWorkingDirectoriesanddisableBypassPermissionsModeassume_roleon Claude apps gateway Bedrock upstreams: the gateway calls Bedrock as an IAM role it assumes through STS, in another AWS account if needed, optionally one session per developerguardrail: {id, version}on Claude apps gateway Bedrock upstreams to apply an Amazon Bedrock guardrail to every request sent through them (set it on all Bedrock upstreams or none)telemetry.resource_attributesto the Claude apps gateway config, to put fixed labels on the telemetry of Claude Desktop and/loginsessions"attribution": falseinsettings.jsonto hide all commit and PR attribution; older CLI versions skip a settings file that holds it, so keep the object form in files shared across versionsclaude plugin validate: it reports.mcp.jsonentries that would be silently dropped at load, undeclared${user_config.*}references, and insecure URLs/insightsthat estimates how many permission prompts auto mode could have handled in your recent sessions/skills,/mcpand/pluginInstalled lists in fullscreen mode, like the one/workflowsnow has: it appears while the mouse is over the list and can be clicked or dragged--max-turns, when the model alternated unparseable tool calls and output-limit truncationCLAUDE_CODE_RETRY_WATCHDOGsessions failing on the first 5xx or dropped connection after a run of 429/529 waits, and sleeping uncapped and silently on a longRetry-Afterfrom a 5xxRetry-After: 0--input-format stream-jsonsessions (Agent SDK, VS Code extension) and scheduled cloud sessions failing every turn with an error when an earlier assistant message had plain-string content-p, Agent SDK) failing on the next turn after the directory they were started in was deleted mid-session/.vol,/.nofollowor/.resolve(which can reach a network mount) before approvalrmwhose target is only command-substitution output, such asrm -rf "$(pwd)", running unprompted in auto and--dangerously-skip-permissionsmode; it now asks even with a Bash allow rule, unless run withCLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT=1excludedCommandsentries not matchinggit rev-parse --git-dir, programs named like shell builtins, and commit messages containing[WIP]or#lines$TMPDIRwhenCLAUDE_CODE_TMPDIRis setclaude --bgstarting a background session, and running its project hooks, in a directory that had not passed the workspace trust prompt; it now asks for trust first, or exits when not run interactively--setting-sources(and SDKsettingSources) not being forwarded to spawned sessions: teammates,/bg,claude agentssessions and--worktree --tmuxnow start with the parent's restriction--add-dirdirectory inside the working directory being sent to the model twice in headless and SDK sessions/loopwakeups being fired again every second when their delivery failed, which could make Claude Code exit at the end of a turnclaude remote-controlstarts for you to open from Claude Desktop, claude.ai or the mobile appgcpAuthRefresh/awsAuthRefreshlogin processes being left running (and holding their localhost callback port on Windows) when Claude Code exits or the refresh times outmcp_toolhooks on blocking events (PreToolUse and similar) being skipped while their MCP server was still connecting; they now wait for it, up to the MCP connect timeoutMCP_CONNECTION_NONBLOCKING=0giving up on claude.ai connectors after 1s instead of honoringMCP_CONNECT_TIMEOUT_MS--channelsplugin entries being checked against the installed plugin's marketplace alone; the installed plugin's name must now match the entry as well--plugin-diron a folder of plugins that also has a.claude-plugin/marketplace.jsonloading one empty plugin instead of the plugins in itclaude plugin uninstallrefusing to remove a project-scope plugin that isn't enabled, saying it is "enabled at project scope" whileclaude plugin disablesays it is already disabledclaude plugin updatefailing for project-scoped plugins when--scopeis omitted — it now resolves the scope the plugin is installed at instead of assuming userclaude plugin validatereportingprivacyPolicyUrl,supportUrland other listing metadata keys in plugin.json as unknown fieldsknown_marketplaces.jsonrecording a marketplace as refreshed when its remote could not be reached andCLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILUREkept the existing clone/pluginErrors tab showing no confirmation after its last error is resolved/pluginstarting a second uninstall or update of the same plugin when Enter was pressed again while the first was still runningyheld while/pluginchecks a marketplace source adding the marketplace the instant the "Add marketplace?" question appears, before it can be read1answering Yes in/permissions' delete and remove-directory confirms while the pointer is on No, which let a held1remove one workspace directory after another/configoffering to turn thinking off on models that can't; thinking now stays on there, with a one-line reason in place of the switch/contexttotal leaving out messages added since the last response; it now matches its categories and can read higher than the status line/modelshowing the raw API error JSON and request ID when the API refuses the picked model; it now shows the server's message and says the model was not changed/ideshowing "No available IDEs detected" while also listing a running IDE/setup-bedrockor/setup-vertexrestarts Claude Code to apply new settings/configexiting whenrespectGitignoreorcopyFullResponsein~/.claude.jsonholdsnull/memory,/hooks,/mcp(including a server's sign-in screen),/export,/copy,/theme, and/teleport's uncommitted-changes and login prompts (where Esc also quit)xors, acting on the previous selection: a stale effort level in/effortand the model picker, and the previously highlighted row in/skills, the background task rows under the prompt, MCP server prompts and/install-github-app/install-github-appupdating the workflow after "Skip workflow update" was chosen, running setup twice on a repeated Enter, and ↑ on the repository step blocking a typed repository name when no repository was detecteddj/dk/dG/dggand theirc/yforms acting on part of a line;1Ggoing to the last line;d0/c0/y0doing nothing; the cursor being off by one after.repeats an insert; ando/pon a!-prefixed line switching to shell modecwon a space, an empty line, a word's last letter or a one-letter word also changing the next word; word motions stopping inside words in Hindi, Bengali and other scripts; and.,porPthat inserts text starting with!switching to shell mode, losing text or editing the wrong character- 316.) showing as letters, roman numerals or the wrong numberskeybindings.json, and showing a stray·when the stop-all-agents shortcut is unbound/skills) in fullscreen mode/heapdumpsummary saying most memory is native when it is in the JS heap snapshotxstopping it, when a new run started while the list was open/config,/plugin,/permissions) showing no highlight while the tab bar has focus when color is off (NO_COLOR)/pluginInstalled list scrolling the pane behind it instead of the list/hooksand/mcpdetail views printing a long value over the row below it in narrow terminals/pluginnot being answerable by typing a number in screen-reader mode$TMPDIR/…failing with "Permission denied"claude.exebackup, which could leave noclaude.exebehindsandbox.network.allowLocalBinding--agentsto accept the path to a JSON file (with-p) as well as inline JSON, and to allow an emptyprompt/batchto run where a WorktreeCreate hook provides the agent worktrees, not only inside a git repositoryclaude plugin validatewarning when a shell-form hook leaves${CLAUDE_PLUGIN_ROOT}unquoted (it breaks on plugin paths with spaces)/menu,/skills,/contextand the/pluginInstalled list to show skills synced from claude.ai by their short name when no other command uses it, notanthropic-skills:<name>/deep-researchreliability on long research briefs by removing unused required fields from the scope step's outputenvvariables ignored because the session's launch environment already sets them/permissionsand/usage: ↑/↓ move focus between the tab row and the content, and a list responds to keys only while it has focus/helpand/sandbox: ←/→ and Tab switch tabs from inside a tab's list, and ↓ on an empty Custom commands tab in/helpno longer leaves the keys stuck until Esc/install-github-app,/desktop, the/permissionsauto mode environment prompts, and the/plugin"Add marketplace?" and "Run this command?" prompts: they now use the standard dialog frame with key hints, and Ctrl+C or Ctrl+D cancels them on the second press like other dialogs/workflowsand/mcplists: they page (PgUp/PgDn, Home/End) and take j/k and the mouse like other lists, their arrows followselect:previous/select:nextrebinds, andxin/workflowsstops the run the pointer is on/pluginplugin and marketplace details menus and the/remote-controlalready-connected menu: they now support Home/End and clicking a row/skills: each row now leads with the skill's name, with ✔ or ◯ alone showing on or off, and stays on one line in narrow terminals/skills,/workflows,/feedback): a name keeps 20 columns beside its first detail, and details are shown whole or not at all/diff: a scrollbar shows where you are in a long list of changed files, and long paths no longer wrap their rows/hooks: a hook's detail screen now says what kind of hook it is and where to change it, instead of always pointing at settings.json, and the hooks-disabled, safe mode and managed-hooks-only notices each say what is happening in one plain sentence/mcp: a disabled server is read as "off" instead of "pending"CLAUDE_CODE_AUTO_MODE_SERVERto also apply on a direct Anthropic API connection:0opts out of the server-side auto mode classifier (the local classifier then counts toward usage),1opts inrmprompt in--dangerously-skip-permissionsand auto mode to wait 2 minutes for an answer, then deny the command with a rewrite hint so unattended sessions keep going (CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT=1turns this off)managedMcpServersentry'senvHelperpath starts with\??\or/??/, a path form current Claude Desktop refuses to runcommandhook that appends--system-promptor--append-system-promptmust switch to--system-prompt-fileor--append-system-prompt-file⧉ nameor⧉ N) that opens/artifacts, which now lists this session's artifacts first/config, to tint the row instead of drawing a second ❯ pointer beside the focused row'sclaude plugin uninstall --jsonand the /plugin dialog to say a plugin's data was kept when its folder stays because another installed plugin uses it or install records cannot be read/tasks): pressingxon a running/ultrareviewnow asks for confirmation before stopping the review/agentsentry from the command menu and/help; typing/agentsstill explains where the wizard wentConfiguration
📅 Schedule: (UTC)
* * * * 3)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.