chore(deps): update dependency @anthropic-ai/claude-code to v2.1.258 - #6898
chore(deps): update dependency @anthropic-ai/claude-code to v2.1.258#6898renovate-fullsend[bot] wants to merge 1 commit into
Conversation
|
🤖 Finished Review · ✅ Success · Started 3:30 AM UTC · Completed 3:39 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.40 |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
Risk Assessment: moderate (2/5) DetailsSmall dependency version bump (1 file, 2 lines) by bot author with one protected path (images/), but high recent churn and multi-author contention in the Containerfile offset by minimal change surface area. |
ReviewFindingsHigh
Next steps:
|
| # To update: bump CLAUDE_CODE_VERSION; renovate tracks this ARG via | ||
| # a customManagers regex entry in renovate.json. | ||
| ARG CLAUDE_CODE_VERSION=2.1.252 | ||
| ARG CLAUDE_CODE_VERSION=2.1.258 |
There was a problem hiding this comment.
[high] protected-path
This PR modifies images/sandbox/Containerfile, which is under the protected paths images/ and Containerfile. The PR has no linked issue providing authorization for changes to governance/infrastructure files. Human approval is required for all protected-path changes.
This PR contains the following updates:
2.1.252→2.1.258Release Notes
anthropics/claude-code (@anthropic-ai/claude-code)
v2.1.258Compare Source
v2.1.257Compare Source
claude-fable-5-1), now the default Fable model — 1M context, $10/$50 per Mtok with $0.25/Mtok cache readstimeFormat) andtimeZonesettings: 12-hour, 24-hour, 24-hour UTC, or a strftime pattern for the turn-end clock and transcript-view timestampsCLAUDE_CODE_SUBAGENT_MODEL_FORCEto applyCLAUDE_CODE_SUBAGENT_MODEL(or the main model) to every subagent, ignoring per-spawn and agent-definition model overridessin/effortto change effort for the current session only, matching/model/doctorwarning for stale sandbox mask files left by a killed sessionpermissions.blockReadsOutsideWorkingDirectories)descriptionon discovered/modelpicker entries (CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY); entries without one still read "From gateway".claude/folder created after startup not being picked up until restart←always starting in the original session's permission mode, overriding the target directory'sdefaultModeand the agent'spermissionModekeybindings.jsonrebinds of Ctrl+G being ignored inclaude agents; its Ctrl+S / Ctrl+T are now rebindable via the newAgentscontextstate.jsondetailrepeating its own dispatch prompt after a scheduled wake-upclaude agentskeeping a background session you re-prompted buried in Completed after it finished again; Completed now orders by the latest finishclaude --bgfrom a directory that was just deleted reporting "backgrounded" and leaving a crashed session row; it now prints the reason and exits 1Authorizationheader overriding the configured credential on Bedrock, Mantle, Vertex, and WIF, and the Vertex setup wizard picking up a leftover Anthropic profile from~/.config/anthropicAuthorizationor profile headers to Foundry, Vertex, and Bedrock, and Foundry Entra ID upstreams not starting whenANTHROPIC_FOUNDRY_API_KEYis set/scheduleroutines whose prompt was saved without a message role and then ran with nothing to doclaude agentsnot saying that a background session is waiting for you to approve a message from another session, or who sent itpolicyHelpertimeoutMsandrefreshIntervalMsvalues above the timer maximum (2147483) causing failures or re-runs every millisecond; they are now clampedexample.com.): adeniedDomainsentry didn't block the host inside the sandbox, and "don't ask again" for such a host kept promptingnatclaude remote-control) counting as consent, so the next request connected without asking/mcpreconnect and enable still connecting a settings-file MCP server that a managed MCP allow/deny list orstrictPluginOnlyCustomizationloaded after startup should blockclaude mcp removeleaving a remote server's stored OAuth credentials behind whenstrictPluginOnlyCustomizationlocks MCP to plugin-only serversclaude remote-control) sessions started from the Claude app ignoring the selected model and running on the machine's default instead--disallowedToolsand session deny rules being dropped after the first settings reload whenallowManagedPermissionRulesOnlyis enabled--resumelisting a backgrounded conversation twice and--continuereopening its stalled pre-background copy;--continuenow also opens finished background sessions!shell command output to expand itclaude agents --jsonbriefly switching the terminal to raw mode and undoing another program's terminal settings on exit←doing nothing in the/btwpanel inside aclaude agentssession: it now returns to the agents list (even mid-answer), and the panel comes back when you reopen the session/recap, prompt suggestions) and re-sending the full conversation uncached each timeclaude -pexiting about 5 seconds after its final result while a Monitor the model armed was still running; it now waits for the watch to fire or time outpermissions.askrule being skipped in auto mode when the matching command ran inside a compound command or subshell, letting it run without the confirmation prompt/add-dirrejecting a directory inside the current working directory; it now loads that directory's skills, commands, and agents like--add-dirdoes at startup/feedbackclaude mcp add/removehanging or exhausting memory when the project's.mcp.jsonis a FIFO or a device-file symlink; it now fails fast with an actionable messageclaude -p --input-format stream-json; it now fails fast with a clear error←or Ctrl+B) while a subagent or other tool was running occasionally making the background session treat that tool as rejected instead of re-running itRead()/Edit()deny rules not applying to< fileredirects and reader commands liketacandegrep; a deny rule on any argument or redirect target now refuses the command$VARreads,"$(…)"and heredocs that never touch git as "too complex to verify that it stays inside the worktree"/modeland/effortshowing a prompt-cache warning after rewinding a conversation back to emptytimeoutorsetsid) surviving a task stop or Claude Code exit.gitdirectory aftercdinto a subdirectory/logininstead of reporting a network errorcc-daemon-*folders in the system temp directory after an interrupted background daemon start; thecleanupPeriodDaysretention sweep now removes them[[ ]]conditionals that zsh parses differently from bash; these commands now prompt for approval/statusnot showing the Organization for that sign-in/status, declining the managed-settings dialog prints why Claude Code exited, and helper timeouts are reported as timeouts/code-review --commentto post findings on GitLab merge requests viaglab mr noteinstead of reporting the target as unsupportedclaude self-hosted-runner --configure-gitto also enable git push negotiation, so the first push of a new branch from a stale clone uploads only the new commits instead of the whole treeCLAUDE_STREAM_IDLE_TIMEOUT_MSare not mistaken for a hung session/forkto keep the original conversation's prompt cache in the new background session: its worktree briefing now arrives as a message instead of a system-prompt change:satisfied:,:telephone:,:collision:, …)--effortto lift a new model's default-effort hold for that session only rather than permanently; an effort picked on claude.ai for a Remote Control session now applies during the holdpolicyHelperin MDM ormanaged-settings.jsonshadowed at launch by cached server-managed settings to run (or exit) as soon as the fetch reports them removed, not at the next launchmanagedSourcesBehavior: "merge"to takesandbox.credentials.awsPairsandsandbox.ripgrepwhole from the highest managed source that sets them instead of combining the sources' valuesCLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY=1) to run even whenCLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFICis set, since it only queries your gatewayclaude --resume <session-id> --bgto continue that session under its own ID when nothing is running it, instead of silently starting a copy; a copy is now announced/btwhistory browsing from←/→toShift+←/Shift+→(or[/]), stepping through your recent side questions and back to the live answerdefaultMode: "bypassPermissions"in.claude/settings.jsonor.claude/settings.local.jsonto be ignored, like"auto"; set it in user or managed settings, or pass--permission-modefableandbestin Claude apps gateway sessions to keep resolving to Fable 5 for now, since gateways not yet configured for Fable 5.1 reject it; pick Fable 5.1 in/modelto use it--add-dir,/add-dir, andadditionalDirectoriesto refuse network paths (UNC shares,/net/<host>automounts) with a message before touching them; on Windows use a mapped drive letterConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.