chore(deps): update all dependencies - #44
Open
gw0-bot wants to merge 1 commit into
Open
Conversation
gw0-bot
force-pushed
the
renovate/all-deps
branch
2 times, most recently
from
August 31, 2026 10:22
be17a71 to
2aa811c
Compare
gw0-bot
force-pushed
the
renovate/all-deps
branch
from
September 1, 2026 09:05
2aa811c to
01411bf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.1.247→2.1.2523.13.1→3.14.0v46.2.4→v46.2.516.2.0→16.5.0Release Notes
anthropics/claude-code (@anthropic-ai/claude-code)
v2.1.252Compare Source
v2.1.251Compare Source
PreModelSwitchandPostModelSwitchhook events (block, confirm, or annotate a model switch);SessionStartresume hooks now receive session staleness and the estimated re-cache cost/usageand arate_limits.spend_limitstatus line field for developers behind a Claude apps gateway with spend limits/cost(hit ratio, misses, tokens re-cached, warm/cold) and a matchingprompt_cacheobject for status line scriptsattach,logs,stop,respawn, andrmtoclaude --help; the--resumemessage for a running background session now names the exactclaude attach <id>commandscriptPathoutside what the session may read before the permission check ranRead(...)deny rules to files reached through a symlinked search pathhighin that caseSendMessageto that session id now delivers through Claude Desktop instead of failing with "not reachable"fromwas the agent type, which is not an address)disableAutoModearriving mid-session not moving an already-running auto-mode session back to default mode/statusand retrying gateway 401s with it, though requests never use it/mcp reconnecton Remote Control showing a generic withheld-detail error instead of the real remedy when a server was disabled in another session--input-format stream-json: client-injected assistant tool calls sent without a message id were merged into the first one and their results lost, including when resuming older sessionsgit worktree add/usage-creditsfor Team and Enterprise members whose admin set the org's usage-credit limit to $0: it now offers to ask the admin instead of saying a cap was reached--worktree --tmuxwith a merge-request number on a gitlab.com origin trying a doomed GitHub-style fetch first instead of fetching the GitLab ref directly/dev/tty, such asemacs -nwandmicroadditionalDirectoriesentry containing a null byte crashing startup, or breaking/add-dirand later settings updates when it came from an SDK host, IDE, or hook; it is now skippedscreenterminal typeclaude mcp add --headerandclaude mcp add-jsonhelp text naming the wrong transportsclaude ultrareviewand/ultrareviewwaiting the full 30 minutes when the cloud session fails to start; they now stop early and report the reasonOPTIND=1/0,RANDOM=2+2); these now prompt for approval←,/background,--bg) losing a Vertex/Bedrock gateway (ANTHROPIC_*_BASE_URL+CLAUDE_CODE_SKIP_*_AUTH) exported in the shell, so every request failedclaude --bg --model fableon Max plans stopping to ask for usage credits while the interactive session on the same account still had Fable allowance/bugand/sharereporting that/feedbackwas disabled; tips,/help, and refusal messages no longer suggest/feedbackwhen an org policy or env var turns it off/scheduleto explain that MCP servers configured in Claude Code can't be attached to cloud routines, instead of a bare "No MCP connectors" message/tasksCLAUDE_CODE_PROVIDER_MANAGED_BY_HOST(e.g. Claude Desktop): a session given a Bedrock model ID or ARN no longer waits for inference-profile discovery/radioto be available on Bedrock, Vertex AI, Foundry, and Claude Platform on AWS, and when telemetry is disabledCLAUDE_CODE_SUBAGENT_MODELto set the default subagent model rather than override everything: an agent definition'smodel:and an explicit per-spawn model now take precedence over itCo-Authored-By: Claude Codewhen the active model isn't a recognized Claude model (e.g. third-party models behind a customANTHROPIC_BASE_URL)/effortto save your default effort level per model, so each model keeps its own setting when you switchDISABLE_TELEMETRYgh auth token,GH_TOKEN, orGITHUB_TOKEN) instead ofgh pr viewANTHROPIC_CUSTOM_HEADERSfrom managed or project settings to require approval when it sets a credential, org/tenant, routing, or API-behavior header (e.g.Authorization,Host).claude/settings.jsonenvto no longer setCLAUDE_CONFIG_DIR,CLAUDE_CODE_TMPDIR, orTMPDIR/TMP/TEMP; set them in your shell, user, or managed settings instead/remote-controlv2.1.250Compare Source
v2.1.248Compare Source
--restricted(orCLAUDE_CODE_RESTRICTED=1): removes the built-in tools that run commands or code andWebFetch(unless named in--tools), keeps file tools inside the working directory, refusesbypassPermissions, and ignores user, project and local settings filesexperimental.cacheTtl("5m"or"1h") to agent frontmatter: a per-agent prompt cache TTL used when no subagent TTL setting is configuredclaude self-hosted-runner --client-label <label>(orSELF_HOSTED_RUNNER_CLIENT_LABEL) to override the label the runner registers with (default: hostname)/doctorand/statusline explaining a load failure or why they weren't fetched (Bedrock/Vertex/third-party provider, customANTHROPIC_BASE_URL)/web-setupwhen the GitHub CLI token lacks theworkflowscope, since pushes to very large repositories can be rejected without it/usage-creditsfor Enterprise organizations billed through AWS Marketplace, self-serve Enterprise, and Enterprise trials, so members can request a higher usage limit from their adminSendMessage/ListAgents) between sessions on the same machine on Bedrock, Vertex, and Foundry, and when telemetry is disabledScheduleWakeuptool definition changing between a session and its--resumewhen the account had entered usage overage, causing a full prompt-cache miss on the resumed session's first turndesktopSessionCleanupPeriodDayssetting caps the exemptionclaude agentslist not responding to the keyboard after detaching from a session, or when launched in a terminal tab left in win32-input-mode/loginfailing with an OAuth error before showing a sign-in URL on machines where it can't be used (for example whenANTHROPIC_API_KEYor an API key helper is set); it now falls back to the API-key sign-in/modeland fast-mode switch notices to render as code, so suffixes like[1m]display literally instead of as a linkclaude agentsskipping the workspace trust prompt when theCIenvironment variable is setclaude agentscrashing on launch when the PR-status cache held a malformed entryclaude agents: opening a stopped session that you already resumed in another terminal no longer starts a second process on that conversation; the row now says it is open in a terminalclaude agentsandclaude rmrefusing to delete a session ("has commits that are not pushed anywhere") when its worktree branch was already merged into your checked-out default branch (e.g. localmain) but not yet pushedPermissionRequestorPreToolUsehook prints an invalid answer: theclaude agentsrow now names the hook and the schema error{…}object that isn't valid JSON as plain text; it's now reported as a hook error with the parse message/mcplisting a project.mcp.jsonentry that declares the claude.ai connector type under the trusted "claude.ai" heading; it now appears under its real scopeheadersHelpersupplies theAuthorizationheader falling into OAuth discovery on a 401 instead of re-running the helper and retrying the call as documented/loginto a Claude apps gateway hanging when the managed-settings security approval dialog was requiredCLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY) never running whenapiKeyHelperis the only credentialclaude logsleaving mouse tracking, bracketed paste and the alternate screen switched on in the terminal it was run from/ultrareviewand locally seeded cloud sessions uploading uncommitted edits toprod.env-style and*.tfvarsfiles, or to editor swap, temp, and backup copies of credential files (e.g.key.pem.tmp,id_rsa.swo); they now stay on your machineclaude remote-controlrejecting its own flags (e.g.--spawn,--name) when a global flag or a wrapper-injected option precedes the subcommandgit worktree removeleave it alonecrossSessionInboundvalue being silently ignored: it now warns and holds cross-session messages (user settings) or refuses them (managed settings) until fixed/usage-creditswhen that command isn't available for your organization (e.g. hidden withDISABLE_EXTRA_USAGE_COMMAND)workflow-authoringskillgh prcommand still refreshes it right away/ultrareview <PR#>to check before launch that the GitHub account connected to your Claude account can access the repository, and to explain how to fix it, instead of failing after the cloud session starts/tmpdirectory when the default one can't be used, and the notice and/statusname the directory to fix/loop: self-paced dynamic mode and the no-prompt autonomous default are now always available, including on Bedrock/Vertex/Foundry[Anthropic telemetry]instead of[3P telemetry] OTEL diag error, so they are not mistaken for your OTel collector failingSendMessagefrom a subagent to another session: the result now notes that any reply is delivered to the parent session's conversation, not to the subagentmvdan/sh (mvdan/sh)
v3.14.0Compare Source
This release drops support for Go 1.25 and includes many enhancements, particularly in the interpreter, which implements more shell features and fixes many divergences from Bash.
--detectto find shell files by executable bit or shebang - #944Preorder, an iterator over all nodes, complementingWalkencoding.TextUnmarshalerimplementations for each operator type${ foo;}and${|foo;}inside double quotes - #1368{varname}redirects, likeexec {fds[3]}>&-- #719${args[cmd,#]}- #1285#as the start of a comment inside[[ ]]tests - #1326thenordowith a semicolon when heredocs are pending - #1047!in arithmetic expressions, avoiding history expansion - #987SplitBracesreject malformed sequences and skip backslash escapes - #1330${=name},${~name}, and${^name}prefixes - #1238;|case terminator and leading parentheses for globs - #1293, #1279[globs in arrays - #1278, #1322">>", rather than integers - #1321BashOptsto set Bash options likeshopt- #962AccessHandlerto control file access checks, used by-randcd- #1318HandlerContext.LastExitStatus, and provide aHandlerContextto stat handlershelpandtimesbuiltins, as well as$-- #1398;∧;&case terminators - #1391-Ntest operator, and make-ntand-otfollow POSIX - #1340a=([5]=x)- #1373execfails withENOEXEC- #1065js/wasm, where subprocesses and pipes are unavailableexecwith no argumentsRunBracesSeqwith a config and error reporting, deprecatingBracesVariable.Indexesto describe sparse indexed arrays&&and||operators - #1371"${a[@]%o}"- #1081${!arr[@]}consistent with the quoted form - #672[as a literal character, like Bash - #1372[![:space:]]dashshebangs as POSIX shell for-ln=auto- #1307Consider becoming a sponsor if you benefit from the work that went into this release!
Binaries built on
go version go1.27.0 linux/amd64with:renovatebot/github-action (renovatebot/github-action)
v46.2.5Compare Source
Documentation
Miscellaneous Chores
Build System
Continuous Integration
sickn33/agentic-awesome-skills (sickn33/agentic-awesome-skills)
v16.5.0: "Document Trust and Safer Automation"Compare Source
[16.5.0] - 2026-08-31 - "Document Trust and Safer Automation"
This release helps Claude Code, Cursor, Codex CLI, Gemini CLI, Antigravity, and
related AI coding assistants inspect documents with explicit human-review
boundaries, keep code-derived presentations tied to their source, and use
Upstash Redis and rate limiting without hiding production mutation or
fail-open behavior.
Start here:
npx agentic-awesome-skillsverify-documentandverify-citationsfor evidence-labeled documentand source checks.
slideopsfor cited HTML decks with later driftdetection.
upstash-redisandupstash-ratelimitfor serverless data andtraffic controls.
Added
citation verification, grounded extraction, Australian identity-pack gap
checks, adverse-media review, AU/NZ tender matching, and AI-text triage. Each
declares hosted-data transmission, consequential-decision, false-positive,
and qualified-human-review boundaries
(#1305).
slideopsfor repository-derived HTML decks whosecode excerpts carry file, line, hash, and build-commit citations. The
catalog copy pins upstream v1.0.0 and requires approval before installation,
home-directory symlinks, optional downloads, or deck writes
(#1306).
upstash-redisandupstash-ratelimitwith explicit transaction,latency, algorithm, timeout, and edge-runtime limits; connected five
existing queue, workflow, caching, and retry skills to the new routes
(#1307).
a bounded sustainability plan, and a documented public/private boundary;
then aligned its description with the live directory validator's
500-character constraint
(#1299,
#1301).
Changed
lovable-cleanupwith Vercel favicon andCDN-cache recovery: overwrite-in-place semantics, complete icon linkage,
cache-header guidance, and post-deployment verification
(#1296).
marketplaces, editorial bundles, compatibility reports, and Codex/Claude
plugin distributions for 2,107 skills.
Fixed
with a strict size-bounded parser, removed a mutable Agent QA
npxfallback,and corrected mutation-risk metadata across Atlas, babysitting, and delegation
skills
(#1303).
made Atlas temporary and final output handling symlink- and overwrite-aware;
added a symlink-safe favicon writer; enforced Boost.Asio frame caps before
allocation; rejected raw control characters before URL parsing; and pinned
Unsloth model and dataset revisions with approval and provenance gates
(#1303).
Lua scripting without presenting a dynamic evaluation call
(#1307).
Security and Reliability
and installer-backed workflows as critical where they transmit sensitive
data, mutate remote state, deny traffic, install links, or write output.
uploads, and kept authenticity, misconduct, sanctions, tender, identity, and
citation results as bounded review signals rather than final verdicts.
generated catalogs and mirrors in the protected canonical-sync lane.
Who should care
document triage without turning probabilistic API output into an automatic
consequential decision.
caching, or edge runtimes that need honest fail-open and mutation semantics.
snippets move or change.
propagated through protected canonical mirrors.
Validation
warning-budget enforcement, focused security regressions, the complete
repository test suite, web-app coverage, npm audits, and protected canonical
synchronization for the accepted source batch.
canonical skill, with the redundant
ai-code-reviewerproposal closed ratherthan adding a third overlapping AI-code audit workflow.
main, version and tagparity, npm metadata, CI, CodeQL, release-only Pages, live catalog and legacy
bridge surfaces, and every already-configured local AAS MCP host.
Limitations
current retention, residency, deletion, legal, and organizational requirements
before transmitting sensitive documents or personal data.
examples do not replace production load, timeout, consistency, or failure-mode
testing.
uncited prose is correct or that a deck remains appropriate for its audience.
every bundled skill or upstream service.
Credits
skills in
#1305.
slideopsin#1306.
limiting skills and routing updates in
#1307.
Vercel favicon-cache recovery guidance in
#1296.
v16.4.0: "Sharper Reasoning and Safer Service Draining"Compare Source
[16.4.0] - 2026-08-30 - "Sharper Reasoning and Safer Service Draining"
This release helps Claude Code, Cursor, Codex CLI, Gemini CLI, Antigravity, and
related AI coding assistants choose the right reasoning depth, drain production
services without fighting their process manager, and avoid stale catalog
references after a canonical skill is removed.
Start here:
npx agentic-awesome-skillsfalsifyfor explicit mode selection, calibratedfalsification, and lightweight estimate routing.
graceful-shutdownfor bounded draining,readiness transitions, and shutdown deadlines.
Changed
falsifywith a mandatory mode-selection gate soincidents, simple requests, rough estimates, questions, and deep analysis do
not all enter the same heavyweight reasoning protocol
(#1287).
graceful-shutdownso liveness probesremain available during draining, aborted HTTP requests release their active
counters, and FastAPI shutdown guidance preserves Uvicorn's signal ownership
(#1289).
Removed
ui-slop-scoreskill after the canonical UIZZE projectstopped publishing it; the maintained
anti-ui-slop,ui-design, andui-radarskills remain available(#1288).
Fixed
regenerated before cross-reference validation. Source-only skill deletions
can now remove stale bundle and web references before the reference gate runs
(#1291).
marketplaces, editorial bundles, compatibility reports, and Codex/Claude
plugin distributions for 2,097 skills
(#1292).
Security and Reliability
server runtime, install dependencies, or take ownership of production
signals.
cannot wait forever, while keeping readiness and liveness semantics separate.
locked the workflow ordering with regression tests.
Who should care
direct, useful rough estimates without unnecessary ceremony.
connections that need predictable termination behavior.
leaving stale generated references behind.
Validation
warning-budget enforcement, the complete 113-group repository test suite,
176 web-app tests, the production web build, npm audits, plugin compatibility,
bundle and marketplace checks, and protected canonical synchronization.
maincommit, with zero open pull requests, issues, security alerts, orgenerated-state drift before release preparation.
Limitations
falsifystructures routing and evidence checks but cannot guarantee truth orreplace domain expertise and higher-quality evidence.
load-balancer, process-manager, and orchestrator deadlines in the deployed
environment.
ui-slop-scoredoes not remove the maintained UIZZE design-analysisskills or affect projects that independently pinned the retired upstream
package.
Credits
falsifyrouting update in
#1287.
graceful-shutdownguidance in#1289.
retired UIZZE skill in
#1288.
v16.3.0: "Delegation Workflows and Reliable Operations"Compare Source
[16.3.0] - 2026-08-28 - "Delegation Workflows and Reliable Operations"
This release helps Claude Code, Cursor, Codex CLI, Gemini CLI, Antigravity, and
related AI coding assistants delegate bounded implementation work, review and
monitor pull requests, challenge scientific claims, fine-tune models on limited
hardware, operate SandBase safely, and shut down production services without
dropping in-flight work.
Start here:
npx agentic-awesome-skillsdelegate-setupfor configuring the externaldelegation runtime before selecting an implementer relay.
babysit-pranddebate-reviewfor iterative review andtwo-perspective code-review workflows.
graceful-shutdownfor bounded draining,readiness transitions, and shutdown deadlines.
Added
delegate-setupand 17 docs-only implementerrelays for Agy, Aider, Claude, Cline, Codex, CommandCode, Copilot, Cursor,
Grok, Kimi, OMP, OpenCode, Pi, Qoder, Vibe, Warp, and ZCode. Each relay ships
its complete dispatch, queue, review, and brief-writing references while
keeping review and landing with the orchestrator
(#1283).
babysit-prfor bounded review-round monitoringand
debate-reviewfor structured two-model review,including their prompt, schema, and comment-format assets
(#1282).
falsifyfor explicit hypotheses, adversarialchecks, evidence grading, calibrated conclusions, and a durable thinking
ledger (#1281).
sandbase-mcpwith immutable release pinning,checksum and archive verification, and explicit credential, privacy, cost,
and mutation approval gates
(#1279).
unsloth-finetuningfor single-GPU VRAMplanning, LoRA and QLoRA, GRPO and DPO, template and loss-mask correctness,
and GGUF or merged-model export
(#1278).
graceful-shutdownfor SIGTERM and SIGINThandling, connection draining, probe transitions, shutdown deadlines, and
Kubernetes-aware Node.js, Python, and worker patterns
(#1276).
Changed
@supabase/supabase-js2.112.0 to 2.112.2,including fixes for duplicate Realtime bindings, stale sign-out payloads,
preserved authentication 5xx messages, and token refresh behavior
(#1273).
marketplaces, editorial bundles, compatibility reports, and Codex/Claude
plugin distributions for 2,098 skills.
Fixed
source-only scoring workflow intact
(#1274).
the imported review, delegation, and scientific-reasoning skills instead of
publishing incomplete entrypoints.
operating-boundary summaries.
Security
runtimes are not bundled, relays never land changes, and unsandboxed,
all-tools, or
danger-full-accessexecution requires separate humanauthorization.
v0.1.17release and SHA-2561ad535b2899ca460b57b3c268aef278fee28fd28e649a89b92951514fd71fffa,with archive inspection before installation and two approval boundaries
before credentialed or mutating work.
explicit dataset and template validation, checkpointing, and output review.
draining cannot hang a deployment indefinitely.
Who should care
bounded permissions, polling, independent review, and controlled landing.
an external runtime with bundled repository functionality.
practical single-GPU fine-tuning guidance.
and long-lived production connections.
Validation
warning-budget enforcement, the complete 113-group repository test suite,
176 web-app tests, the production web build, npm audits, plugin compatibility,
bundle and marketplace checks, and protected canonical synchronization.
semantics, safety, provenance, declared risk, limitations, permission
escalation, and review or landing boundaries before protected merge.
maincommit with no open pull requests, issues, or generated-state drift.Limitations
alone does not install or authenticate those tools.
orchestrator review, test evidence, repository policy, or human approval for
elevated execution.
replace domain expertise, replication, or higher-quality evidence.
and version-dependent; validate against the current upstream project.
data to its service; review current upstream terms and privacy behavior.
Credits
amElnagdy/delegate-skills
and amElnagdy/review-skills
sources for the delegation and review collections proposed in
#1265 and
#1264.
falsify, proposedin #1266.
unsloth-finetuning, proposed in#1267.
sandbase-mcp,proposed in #1269.
graceful-shutdown, proposed in#1272.
correction proposed in
#1271.
#1273.
Configuration
📅 Schedule: (in timezone UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.