808 Commits
Author SHA1 Message Date
GitHub Actions 12dd8d74c7 chore: bump Claude Code to 2.1.286 and Agent SDK to 0.3.286 v1 v1.0.238 2026-09-30 19:10:48 +00:00
Qing WangandClaude a8cb0db4d8 ci: security hardening for GitHub Actions workflows that call Claude (#1867)
* Run workflows that call Claude on the egress-firewall runner in auto permission mode

Move every workflow job that signs in to the Claude API from
ubuntu-latest to GitHub's egress-firewall runner (ubuntu-24.04-firewall),
and pass --permission-mode auto to the Claude Code action in each of
them except claude.yml.

In auto permission mode Claude Code reviews each tool call that needs
permission and that the allowed tools do not cover, and runs it only if
Claude Code's safety review passes it. Until now these runs, which have nobody to
ask, refused every such call. The issue triage step, which anyone can
start by opening an issue, also passes a --disallowedTools list for
tools it never needs.

claude.yml answers @claude mentions, and for those the action sets
--permission-mode acceptEdits itself. Its permission mode is unchanged.

Allowed tools, settings, models, triggers and permissions are unchanged.
The network allow list for the firewall follows in the next change.

* Add the network allow list, a security check and CLAUDE.md guidance

- .github/egress-firewall.yaml: the hosts that jobs on the
  egress-firewall runner may reach, in enforce mode, each with what
  uses it.
- .github/workflows/workflow-hardening.yml and
  .github/scripts/check_workflow_hardening.py: a check that fails when a
  job that calls Claude is not on the egress-firewall runner, does not
  pass --permission-mode auto, or when the allow list is missing, empty, not in
  enforce mode or names a host with '*'.
  claude.yml is listed as exempt from the permission mode rule, with
  the reason.
- CLAUDE.md: a "Security hardening for GitHub Actions" section so that
  new and edited workflows keep these protections.

* Pin the model for issue triage

The step named no model, so it ran on Claude Code's default model. That
default changed with Claude Code 2.1.280 to a model that is not available
to this CI account. Pass --model claude-opus-5, the model this repository's test-*.yml
workflows (ANTHROPIC_MODEL) and the Python SDK's example runs are
pinned to for the same reason.

This is independent of the security hardening in the two changes before
it.

* Check settings files and --settings for a permission mode

The security check looked for defaultMode only in an inline 'settings'
input. Also read the file a 'settings' input or a --settings flag in
claude_args names, when it is inside the repository, and fail if it sets
a permission mode.

* Flag defaultMode anywhere in a job that calls Claude

A settings file that an earlier step writes at run time can't be read by
the step-level check, so also fail when the job's definition mentions
defaultMode at all.

* Fail the check when settings name a file outside the repository

The check can't read such a file, so it can't tell whether it sets a
permission mode.

* Run @claude mentions in auto permission mode

The action sets --permission-mode acceptEdits for @claude mentions and
appends the workflow's claude_args after it, so the --permission-mode auto
in claude.yml wins. Drop claude.yml from EXEMPT_FROM_AUTO_MODE.

The check now also fails when a step in auto mode names a model older than
claude-opus-4-6: Claude Code does not run auto mode on those and falls back
to its default permission mode.

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-30 06:33:49 +00:00
GitHub Actions fd1c128679 chore: bump Claude Code to 2.1.285 and Agent SDK to 0.3.285 v1.0.237 2026-09-29 19:29:07 +00:00
GitHub Actions 8ce9314fa9 chore: bump Claude Code to 2.1.284 and Agent SDK to 0.3.284 v1.0.236 2026-09-28 18:04:13 +00:00
GitHub Actions 756cc22e19 chore: bump Claude Code to 2.1.283 and Agent SDK to 0.3.283 v1.0.235 2026-09-25 21:50:53 +00:00
GitHub Actions 9171db3e57 chore: bump Claude Code to 2.1.282 and Agent SDK to 0.3.282 v1.0.234 2026-09-24 20:26:46 +00:00
GitHub Actions 8cf3482550 chore: bump Claude Code to 2.1.281 and Agent SDK to 0.3.281 v1.0.233 2026-09-23 19:39:47 +00:00
Mohamed HegazyandClaude Code 46a42b4323 ci: pin the integration tests to claude-opus-5 (#1853)
The test workflows name no model, so they run on the Claude Code CLI's
default model. Since the bump to Claude Code 2.1.280 that default is Opus 5.5,
which the CI account's API access refuses, so the tests fail and the release
job never runs. Setting ANTHROPIC_MODEL at the workflow level keeps the tests
independent of the CLI's default model, the same fix the Agent SDK for Python
used.

Co-authored-by: Claude Code <noreply@anthropic.com>
v1.0.232
2026-09-23 09:39:39 -07:00
GitHub Actions 9ca9355b36 chore: bump Claude Code to 2.1.280 and Agent SDK to 0.3.280 2026-09-22 16:39:34 +00:00
GitHub Actions cfc3eb22bf chore: bump Claude Code to 2.1.278 and Agent SDK to 0.3.278 v1.0.231 2026-09-19 03:11:10 +00:00
GitHub Actions 4036a180cf chore: bump Claude Code to 2.1.277 and Agent SDK to 0.3.277 v1.0.230 2026-09-18 18:07:24 +00:00
GitHub Actions a4f54ef2c5 chore: bump Claude Code to 2.1.276 and Agent SDK to 0.3.276 v1.0.229 2026-09-18 02:13:13 +00:00
GitHub Actions 2261fcfc88 chore: bump Claude Code to 2.1.275 and Agent SDK to 0.3.275 v1.0.228 2026-09-17 22:33:23 +00:00
GitHub Actions 3b8197d3d4 chore: bump Claude Code to 2.1.274 and Agent SDK to 0.3.274 v1.0.227 2026-09-17 00:12:40 +00:00
GitHub Actions 7b0b255830 chore: bump Claude Code to 2.1.273 and Agent SDK to 0.3.273 v1.0.226 2026-09-15 20:23:44 +00:00
GitHub Actions bf38e86e58 chore: bump Claude Code to 2.1.272 and Agent SDK to 0.3.272 v1.0.225 2026-09-15 00:43:27 +00:00
GitHub Actions 51db78a4b8 chore: bump Claude Code to 2.1.271 and Agent SDK to 0.3.271 v1.0.224 2026-09-14 22:13:27 +00:00
GitHub Actions 9cdae7f0d9 chore: bump Claude Code to 2.1.270 and Agent SDK to 0.3.270 v1.0.223 2026-09-12 19:46:49 +00:00
GitHub Actions 56cf60fde4 chore: bump Claude Code to 2.1.269 and Agent SDK to 0.3.269 v1.0.222 2026-09-11 19:18:51 +00:00
GitHub Actions 0a8d3c9443 chore: bump Claude Code to 2.1.268 and Agent SDK to 0.3.268 v1.0.221 2026-09-10 20:39:16 +00:00
GitHub Actions 19dda84776 chore: bump Claude Code to 2.1.267 and Agent SDK to 0.3.267 v1.0.220 2026-09-09 20:11:01 +00:00
GitHub Actions 5ccc3a35a6 chore: bump Claude Code to 2.1.266 and Agent SDK to 0.3.266 v1.0.219 2026-09-08 23:56:12 +00:00
GitHub Actions 0d0e0876d3 chore: bump Claude Code to 2.1.265 and Agent SDK to 0.3.265 v1.0.218 2026-09-08 20:38:21 +00:00
GitHub Actions 9c5ddab2e6 chore: bump Claude Code to 2.1.263 and Agent SDK to 0.3.263 v1.0.217 2026-09-06 02:55:18 +00:00
GitHub Actions d75b94d5ad chore: bump Claude Code to 2.1.261 and Agent SDK to 0.3.261 v1.0.216 2026-09-04 19:58:53 +00:00
GitHub Actions ef8bb1e43b chore: bump Claude Code to 2.1.260 and Agent SDK to 0.3.260 v1.0.215 2026-09-03 23:48:49 +00:00
GitHub Actions fa2b2666b7 chore: bump Claude Code to 2.1.259 and Agent SDK to 0.3.259 v1.0.214 2026-09-02 22:34:41 +00:00
GitHub Actions 8251c103ac chore: bump Claude Code to 2.1.258 and Agent SDK to 0.3.258 v1.0.213 2026-09-01 22:33:40 +00:00
GitHub Actions 781d62e9d5 chore: bump Claude Code to 2.1.257 and Agent SDK to 0.3.257 v1.0.212 2026-09-01 17:54:28 +00:00
GitHub Actions 833fb0f8c9 chore: bump Claude Code to 2.1.252 and Agent SDK to 0.3.252 v1.0.211 2026-08-31 19:47:59 +00:00
GitHub Actions a874e9ecd7 chore: bump Claude Code to 2.1.251 and Agent SDK to 0.3.251 v1.0.210 2026-08-28 18:20:42 +00:00
GitHub Actions a60f3e1db3 chore: bump Claude Code to 2.1.250 and Agent SDK to 0.3.250 v1.0.209 2026-08-28 00:50:11 +00:00
GitHub Actions e8c2d7c16c chore: bump Claude Code to 2.1.248 and Agent SDK to 0.3.248 v1.0.208 2026-08-27 22:12:44 +00:00
GitHub Actions 70fec18385 chore: bump Claude Code to 2.1.247 and Agent SDK to 0.3.247 v1.0.207 2026-08-27 00:09:24 +00:00
GitHub Actions 1f291e1cfe chore: bump Claude Code to 2.1.246 and Agent SDK to 0.3.246 v1.0.206 2026-08-25 22:32:51 +00:00
Muhammad Abdullah khan 76ac41a83e fix: encode branch names in GitHub links (#1713)
* fix: encode branch names in GitHub links

* style: format branch URL helper
2026-08-25 11:02:49 -07:00
Jeremy Schoemaker 8ef9699156 fix: bound download_job_log against a stalled log fetch (#1719)
The download_job_log MCP tool called
client.actions.downloadJobLogsForWorkflowRun() with no timeout and no
AbortController. @octokit/rest@21 runs on Node's native fetch, which has
no default timeout, and Octokit only cancels a request when the caller
passes request.signal. If the log blob fetch stalls, that await never
resolves and never rejects.

This tool is always enabled in tag mode (src/modes/tag/index.ts), so a
"fix the failing CI" run that calls get_ci_status -> get_workflow_run_details
-> download_job_log can hang on this one await with nothing to recover it.
It's headless, so the run only ends when the Actions job-level
timeout-minutes kills it, burning the whole job budget with the tracking
comment stuck at "Claude Code is working...".

Sibling fetch in src/github/utils/image-downloader.ts (fetchImage) already
got this treatment in #1625 via a timeout-driven AbortController. Same
shape of call: fetch a GitHub-hosted resource by ID from untrusted PR/CI
content. This mirrors that fix for github-actions-server.ts.

Extracted the download+write logic into an exported downloadJobLog()
function (with an injectable timeoutMs) so the timeout path is directly
testable, and guarded the module's entrypoint side effects with
import.meta.main, matching the pattern already used by the other
entrypoints in src/entrypoints/.
2026-08-25 08:46:02 -07:00
Yauheni Papovich 791545dab1 fix: allow parentheses in valid branch names (#1710)
Accept parentheses while preserving existing branch-name security checks.

Add regression coverage for scoped branch names.

Refs anthropics/claude-code-action#1709
2026-08-25 08:45:50 -07:00
2d7a787fbd fix: use paths in delete_files prompt example (#1702)
* fix: use paths param in delete_files prompt example

The tag-mode prompt told the model to call delete_files with
"files", but the MCP tool schema and handler expect "paths".

Co-authored-by: Cursor <cursoragent@cursor.com>

* test: prove delete_files prompt against the live MCP schema

The old {files} payload is rejected by the same Zod shape the
tool registers; the generated prompt example now parses cleanly.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test: cover delete_files schema edges and the sibling commit_files tool

Confirm the old files-only payload still fails, types and required
fields are enforced, and commit_files was not inverted by the fix.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: RESILIENCE Agentic Solutions <286555414+WeAreResilience@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-25 08:45:33 -07:00
Mohammed Alkindi b58c16b325 chore: add .gitattributes to normalize line endings (#1708)
On Windows, git's default core.autocrlf=true checks out CRLF, and the contributor commands in CONTRIBUTING.md then fail: bun run format:check reports 191 files because Prettier defaults to endOfLine "lf", and three tests that match LF-terminated content fail.

All tracked blobs are already LF, so this changes checkout behavior only and produces no renormalization diff. Every CI job runs on ubuntu-latest, where it is a no-op.
2026-08-25 08:45:13 -07:00
GitHub Actions 16b3b310c3 chore: bump Claude Code to 2.1.245 and Agent SDK to 0.3.245 v1.0.205 2026-08-25 05:14:05 +00:00
GitHub Actions 6bcfb8263a chore: bump Claude Code to 2.1.241 and Agent SDK to 0.3.241 v1.0.204 v1.0.203 2026-08-25 03:43:35 +00:00
GitHub Actions b62c7454dc chore: bump Claude Code to 2.1.241 and Agent SDK to 0.3.243 2026-08-25 03:38:24 +00:00
GitHub Actions e5ad3c7725 chore: bump Claude Code to 2.1.243 and Agent SDK to 0.3.243 v1.0.202 2026-08-24 23:41:35 +00:00
GitHub Actions c81e3bc69d chore: bump Claude Code to 2.1.241 and Agent SDK to 0.3.241 v1.0.201 2026-08-23 00:53:06 +00:00
GitHub Actions 24dcd50c05 chore: bump Claude Code to 2.1.240 and Agent SDK to 0.3.240 v1.0.200 2026-08-22 14:45:56 +00:00
GitHub Actions dcb57747bf chore: bump Claude Code to 2.1.239 and Agent SDK to 0.3.239 v1.0.199 2026-08-21 19:55:45 +00:00
492d2d78ee fix: teach claude_args --allowedTools in the signed prompt (#1704)
allowed_tools was removed in v1.0. The tag-mode prompt still named it
as the way to enable Bash under commit signing.

Co-authored-by: RESILIENCE Agentic Solutions <286555414+WeAreResilience@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-20 16:17:53 -07:00
ulofiaiandulofiai 2ca5fb4027 fix: surface resolved model limits (#1608)
Signed-off-by: ulofiai <monsterking@tutamail.com>
Co-authored-by: ulofiai <monsterking@tutamail.com>
2026-08-20 16:17:36 -07:00
anishandanish f3f2789f0a fix(mcp): recognize mcp__github aggregate selector for GitHub MCP server initialization (#1657)
* fix(mcp): accept shorthand selectors for GitHub MCP server initialization

## Problem

Signed-off-by: anish <anishesg@users.noreply.github.com>

* address review feedback: fix prettier formatting

Signed-off-by: anish <anishesg@users.noreply.github.com>

---------

Signed-off-by: anish <anishesg@users.noreply.github.com>
Co-authored-by: anish <anishesg@users.noreply.github.com>
2026-08-20 16:17:25 -07:00