* diff: the dialog opens every file it lists, and says nothing when closed
* diff: the dialog's fetch asks its seat first, and a generated file opens too
* diff: a read started by a move of the selection never rejects unheard
* diff: a test that a moving window reads only its new rows
* sec-default: the system prompt's sections continue past the user tier; the declarations carry prompt.compose
* sec-default: prompt.compose has its own row, a second case where a person's plugin asks first, and the declarations as the event shipped
* sec-default: the two new cases set their several-line hooks apart
* sec-default: a settings deny rule holds over an allow or ask from a plugin the person installed
* sec-default: the tool.check test plugins carry their verdicts in their own bodies
* sec-default: a user-tier link counts as loosening only when it answers looser than it was handed
* sec-default: the README says where the line lands in a plain -p run
* sec-default: a batch listed under prepend may hold a person's plugin, and the line says lift
* sec-default: the README and one doc comment say what the batch fix changed
claude-sonnet-4-5 predates auto mode, so Claude Code fell back to its
default permission mode in the dedupe job. Move it and claude.yml to
claude-sonnet-4-6. The action sets --permission-mode acceptEdits for
@claude mentions and appends the workflow's claude_args after it, so the
--permission-mode auto in claude.yml wins. Drop claude.yml from
EXEMPT_FROM_AUTO_MODE.
The check now also fails when a step in auto mode names a model older than
claude-opus-4-6.
* Revert "agents-md: the truncated-read tests laid out as the formatter lays them"
* Revert "fix(agents-md): retain instructions after truncated reads"
* Revert "diff: the shared diff arguments' doc says what --no-color pins"
* Revert "fix(diff): preserve hunks when Git forces colored output"
A settings file that an earlier step writes at run time can't be read by
the step-level check, so also fail when the job's definition mentions
defaultMode at all.
The security check looked for defaultMode only in an inline 'settings'
input. Also read the file a 'settings' input or a --settings flag in
claude_args names, when it is inside the repository, and fail if it sets
a permission mode.
- .github/egress-firewall.yaml: the hosts that jobs on the
egress-firewall runner may reach, in enforce mode, each with what
uses it.
- .github/workflows/workflow-hardening.yml and
.github/scripts/check_workflow_hardening.py: a check that fails when a
job that calls Claude is not on the egress-firewall runner, does not
pass --permission-mode auto, or when the allow list is missing, empty, not in
enforce mode or names a host with '*'.
claude.yml is listed as exempt from the permission mode rule, with
the reason.
- CLAUDE.md: a "Security hardening for GitHub Actions" section so that
new and edited workflows keep these protections.
Move the three workflow jobs that sign in to the Claude API (claude.yml,
claude-issue-triage.yml, claude-dedupe-issues.yml) from ubuntu-latest to
GitHub's egress-firewall runner (ubuntu-24.04-firewall), and pass
--permission-mode auto to the Claude Code action in the triage and
dedupe steps.
In auto permission mode Claude Code reviews each tool call that needs
permission and that the command's allowed-tools list does not cover, and
runs it only if Claude Code's safety review passes it. Until now these runs, which
have nobody to ask, refused every such call. Anyone can start both jobs by opening
an issue, and the triage job also by commenting on one, so both steps
also pass a --disallowedTools list for tools they never need.
claude.yml answers @claude mentions, and for those the action sets
--permission-mode acceptEdits itself. Its permission mode is unchanged.
Allowed tools, models, triggers and permissions are unchanged. The
network allow list for the firewall follows in the next change.
* telemetry: the test plugins a person installed hook and call the collector's stream by name
* agents-md: the test plugin standing in for telemetry hooks its two events, adding the noun only where the engine has none
* telemetry: log and mark are what the mod's hooks do, the noun added only where the engine has none
* telemetry: the engine.create step spreads what is beneath last, so a telemetry it already has stands
* mods/types: refresh the engine typings; diff's old-files fixture names isLink
* mods/agents-md: the AGENTS.md project-instructions mod
* mods/agents-md: the instructionFiles option with its legacy key, as shipped; typings at 2.1.277