902 Commits
Author SHA1 Message Date
GitHub Actions 52c76441ca chore: Update CHANGELOG.md and feed.xml 2026-10-01 18:43:08 +00:00
GitHub Actions 816ec211a6 chore: Update CHANGELOG.md and feed.xml
Fixes #70763
Fixes #97352
v2.1.287
2026-10-01 17:59:57 +00:00
Alice T'Poteat 6160717d89 diff: the dialog opens every file it lists, and says nothing when closed (#98555)
* diff: the dialog opens every file it lists, and says nothing when closed

* diff: the dialog's fetch asks its seat first, and a generated file opens too

* diff: a read started by a move of the selection never rejects unheard

* diff: a test that a moving window reads only its new rows
2026-09-30 22:23:04 -07:00
Alice T'Poteat 525d3b3531 diff: the pane notices a finished merge by itself, and stays quiet on an unusual branch name (#98357) 2026-09-30 15:36:31 -04:00
Alice T'Poteat 292c5b8971 diff: the pane reads every file's hunks with one git process, where it started one per file (#98445) 2026-09-30 15:36:22 -04:00
Alice T'Poteat 9778ad7c09 diff: the pane reads the diff again after a rebase that finished (#98374) 2026-09-30 15:35:43 -04:00
GitHub Actions f5f60250a0 chore: Update CHANGELOG.md and feed.xml v2.1.286 2026-09-30 19:09:54 +00:00
Qing Wang 732e167ee9 Merge pull request #97952 from anthropics/security-hardening-gh-actions
ci: security hardening for GitHub Actions workflows that call Claude
2026-09-29 23:30:04 -07:00
Claude 89c73ce6f6 Remove a compiled Python file committed by mistake 2026-09-30 06:20:54 +00:00
Alice T'Poteat 2282079d6a agents-md: send the AGENTS.md loaded line to the debug log (#98275) 2026-09-29 18:03:19 -07:00
Alice T'Poteat 684800b206 sec-default: the system prompt's sections continue past the user tier (#97241)
* sec-default: the system prompt's sections continue past the user tier; the declarations carry prompt.compose

* sec-default: prompt.compose has its own row, a second case where a person's plugin asks first, and the declarations as the event shipped

* sec-default: the two new cases set their several-line hooks apart
2026-09-29 19:39:25 +00:00
GitHub Actions ec44ca97dc chore: Update CHANGELOG.md and feed.xml v2.1.285 2026-09-29 19:27:09 +00:00
Alice T'Poteat 16da1ecd3f sec-default: a settings deny rule holds over an allow or ask from a plugin the person installed (#98080)
* sec-default: a settings deny rule holds over an allow or ask from a plugin the person installed

* sec-default: the tool.check test plugins carry their verdicts in their own bodies

* sec-default: a user-tier link counts as loosening only when it answers looser than it was handed

* sec-default: the README says where the line lands in a plain -p run

* sec-default: a batch listed under prepend may hold a person's plugin, and the line says lift

* sec-default: the README and one doc comment say what the batch fix changed
2026-09-29 19:07:07 +00:00
Alice T'Poteat 0d7f14dd35 sec-default: a managed option, allowManagedModsOnly, keeps the mods a person installs from loading (#98083) 2026-09-29 10:27:48 -07:00
Claude 7dbaea237f Run @claude mentions and dedupe in auto mode on a model that supports it
claude-sonnet-4-5 predates auto mode, so Claude Code fell back to its
default permission mode in the dedupe job. Move it and claude.yml to
claude-sonnet-4-6. The action sets --permission-mode acceptEdits for
@claude mentions and appends the workflow's claude_args after it, so the
--permission-mode auto in claude.yml wins. Drop claude.yml from
EXEMPT_FROM_AUTO_MODE.

The check now also fails when a step in auto mode names a model older than
claude-opus-4-6.
2026-09-29 08:21:19 +00:00
Alice T'Poteat dec92bc87a mods: revert two changes (agents-md truncated reads, diff forced colors) (#98018)
* Revert "agents-md: the truncated-read tests laid out as the formatter lays them"

* Revert "fix(agents-md): retain instructions after truncated reads"

* Revert "diff: the shared diff arguments' doc says what --no-color pins"

* Revert "fix(diff): preserve hunks when Git forces colored output"
2026-09-28 17:05:53 -07:00
Claude 574ef0b8b7 Fail the check when settings name a file outside the repository
The check can't read such a file, so it can't tell whether it sets a
permission mode.
2026-09-28 18:56:30 +00:00
Claude 55ac4d7fce Flag defaultMode anywhere in a job that calls Claude
A settings file that an earlier step writes at run time can't be read by
the step-level check, so also fail when the job's definition mentions
defaultMode at all.
2026-09-28 18:54:51 +00:00
Claude a83eb8099f Check settings files and --settings for a permission mode
The security check looked for defaultMode only in an inline 'settings'
input. Also read the file a 'settings' input or a --settings flag in
claude_args names, when it is inside the repository, and fail if it sets
a permission mode.
2026-09-28 18:53:48 +00:00
Claude b1922f294d Add the network allow list, a security check and CLAUDE.md guidance
- .github/egress-firewall.yaml: the hosts that jobs on the
  egress-firewall runner may reach, in enforce mode, each with what
  uses it.
- .github/workflows/workflow-hardening.yml and
  .github/scripts/check_workflow_hardening.py: a check that fails when a
  job that calls Claude is not on the egress-firewall runner, does not
  pass --permission-mode auto, or when the allow list is missing, empty, not in
  enforce mode or names a host with '*'.
  claude.yml is listed as exempt from the permission mode rule, with
  the reason.
- CLAUDE.md: a "Security hardening for GitHub Actions" section so that
  new and edited workflows keep these protections.
2026-09-28 18:52:06 +00:00
Claude 592d541c18 Run workflows that call Claude on the egress-firewall runner in auto permission mode
Move the three workflow jobs that sign in to the Claude API (claude.yml,
claude-issue-triage.yml, claude-dedupe-issues.yml) from ubuntu-latest to
GitHub's egress-firewall runner (ubuntu-24.04-firewall), and pass
--permission-mode auto to the Claude Code action in the triage and
dedupe steps.

In auto permission mode Claude Code reviews each tool call that needs
permission and that the command's allowed-tools list does not cover, and
runs it only if Claude Code's safety review passes it. Until now these runs, which
have nobody to ask, refused every such call. Anyone can start both jobs by opening
an issue, and the triage job also by commenting on one, so both steps
also pass a --disallowedTools list for tools they never need.

claude.yml answers @claude mentions, and for those the action sets
--permission-mode acceptEdits itself. Its permission mode is unchanged.

Allowed tools, models, triggers and permissions are unchanged. The
network allow list for the firewall follows in the next change.
2026-09-28 18:52:06 +00:00
GitHub Actions 8364969e9f chore: Update CHANGELOG.md and feed.xml v2.1.284 2026-09-28 18:01:46 +00:00
GitHub Actions 7779afb12e chore: Update CHANGELOG.md and feed.xml v2.1.283 2026-09-25 21:49:55 +00:00
Alice T'Poteat c94815511c diff: the focus hook answers to either name the engine stamps on its elements (#96953) 2026-09-25 18:42:18 +00:00
Alice T'Poteat e1bb7b065b telemetry, agents-md: the test plugins hook and call the collector stream by name, and stand in for telemetry through its events (#96930)
* telemetry: the test plugins a person installed hook and call the collector's stream by name

* agents-md: the test plugin standing in for telemetry hooks its two events, adding the noun only where the engine has none
2026-09-24 19:35:26 -07:00
GitHub Actions 163ae3a264 chore: Update CHANGELOG.md and feed.xml 2026-09-25 02:20:46 +00:00
Alice T'Poteat 6557bbe6b6 telemetry: log and mark are what the mod's hooks do, the noun added only where the engine has none (#96917)
* telemetry: log and mark are what the mod's hooks do, the noun added only where the engine has none

* telemetry: the engine.create step spreads what is beneath last, so a telemetry it already has stands
2026-09-24 18:32:25 -07:00
poteat 684ffc4da0 agents-md: the truncated-read tests laid out as the formatter lays them 2026-09-24 11:41:16 -07:00
7487 653d32fb73 fix(agents-md): retain instructions after truncated reads 2026-09-24 11:41:16 -07:00
GitHub Actions ddcb43a29b chore: Update CHANGELOG.md and feed.xml v2.1.282 2026-09-24 18:37:49 +00:00
poteat 32251d1aa7 diff: the shared diff arguments' doc says what --no-color pins 2026-09-24 11:16:25 -07:00
7487 453620980b fix(diff): preserve hunks when Git forces colored output 2026-09-24 11:16:25 -07:00
Alice T'Poteat cbab6f4598 telemetry: rows carry the engine's version, base version and build time from $.session.version() (#96487) 2026-09-24 17:49:26 +00:00
Alice T'Poteat 6c6915eb63 diff: a shell command the tool held read-only fetches nothing, as the built-in panel's touch is gated (#95423) 2026-09-24 17:22:20 +00:00
Alice T'Poteat 384e28e6c3 diff: the command.run hook names its command by the literal the engine's scan reads (#96570) 2026-09-24 10:22:12 -07:00
GitHub Actions d78be9481b chore: Update CHANGELOG.md and feed.xml v2.1.281 2026-09-23 19:18:58 +00:00
GitHub Actions 56f3653253 chore: Update CHANGELOG.md and feed.xml v2.1.280 2026-09-22 16:37:53 +00:00
timgu0 b486776a2e Merge pull request #95932 from anthropics/add-github-connection-issue-template
Add issue template for GitHub connection problems on claude.ai
2026-09-21 15:23:27 -07:00
Dickson Tsai 411c240990 Add issue template for GitHub connection problems on claude.ai 2026-09-21 15:01:17 -07:00
GitHub Actions 8187baaaaf chore: Update CHANGELOG.md and feed.xml 2026-09-21 12:12:04 +00:00
Alice T'Poteat 7974a70773 diff: a resumed session with edits opens the pane before any new edit, /clear leaves it up, and the session line follows the engine's start (#95587) 2026-09-20 01:03:16 -07:00
Alice T'Poteat 4564326dca telemetry: complete rows gathered through $, sent in batches, serving built-in plugins only (#95618) 2026-09-20 01:02:49 -07:00
GitHub Actions bf7d404e26 chore: Update CHANGELOG.md and feed.xml v2.1.278 2026-09-19 03:10:24 +00:00
Alice T'Poteat 92ec78f288 diff: a docked pane reads the repository before it opens, so it never lands on Loading diff (#95488) 2026-09-18 20:39:54 -04:00
Alice T'Poteat 2287e5d473 diff: the first edit opens the pane only from the main loop with checkpointing on, and an open the engine leaves waiting is withdrawn (#95476) 2026-09-18 16:12:15 -07:00
Alice T'Poteat 6ce37e9f46 mods/diff: type openPane's answer as unknown so a richer $.ui.open result compiles (#95198) 2026-09-18 19:28:00 +00:00
Alice T'Poteat 2fc72b2918 mods/agents-md: a Read attaches no nested AGENTS.md where the engine attaches nothing to a turn (#95417) 2026-09-18 12:27:53 -07:00
GitHub Actions f708f4f0c7 chore: Update CHANGELOG.md and feed.xml 2026-09-18 18:11:04 +00:00
GitHub Actions ca02e7deeb chore: Update CHANGELOG.md and feed.xml v2.1.277 2026-09-18 18:06:17 +00:00
Alice T'Poteat a92ea1cdb1 mods/agents-md: the AGENTS.md project-instructions mod (#95409)
* mods/types: refresh the engine typings; diff's old-files fixture names isLink

* mods/agents-md: the AGENTS.md project-instructions mod

* mods/agents-md: the instructionFiles option with its legacy key, as shipped; typings at 2.1.277
2026-09-18 17:35:47 +00:00