Skip to content

chore(deps): update ⬆️ mise-packages - #1065

Merged
renovate[bot] merged 2 commits into
mainfrom
renovate/mise-packages
Sep 16, 2026
Merged

renovate[bot] merged 2 commits into
mainfrom
renovate/mise-packages

Conversation

@renovate

@renovate renovate Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending Age Adoption Passing Confidence
aqua:astral-sh/ruff tools patch 0.16.60.16.7 0.16.8 age adoption passing confidence
aqua:astral-sh/uv tools patch 0.12.110.12.13 0.12.15 (+1) age adoption passing confidence
aqua:atuinsh/atuin tools minor 18.21.018.22.0 age adoption passing confidence
aqua:charmbracelet/gum tools patch 2.0.02.0.1 age adoption passing confidence
aqua:helm/helm tools minor 4.2.44.3.0 age adoption passing confidence
aqua:junegunn/fzf tools patch 0.74.30.74.4 age adoption passing confidence
aqua:openai/codex tools minor rust-v0.153.4rust-v0.154.0 age adoption passing confidence
aqua:snyk/cli tools patch 1.1307.11.1307.2 age adoption passing confidence
droid (source) minor 0.216.00.218.1 0.220.0 (+2) age adoption passing confidence
github:anthropics/claude-code tools patch v2.1.266v2.1.270 v2.1.273 (+2) age adoption passing confidence
github:backnotprop/plannotator tools patch v0.27.12v0.27.14 v0.27.15 age adoption passing confidence
github:janosmiko/lfk tools patch v0.18.9v0.18.12 v0.18.14 (+1) age adoption passing confidence
github:modem-dev/hunk tools minor v0.21.1v0.22.0 age adoption passing confidence
github:nolabs-ai/nono tools minor v0.76.0v0.77.0 v0.78.0 age adoption passing confidence
npm:cspell (source) tools patch 10.3.010.3.1 10.3.3 (+1) age adoption passing confidence
npm:socket tools patch 1.1.1701.1.171 1.1.173 (+1) age adoption passing confidence
pipx:semgrep (changelog) tools minor 1.176.11.177.0 age adoption passing confidence
usage tools minor 6.8.06.9.0 6.9.1 age adoption passing confidence

Release notes are maintained in a PR comment by the renovate-release-notes-comment workflow.


Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • Between 03:00 AM and 05:59 AM (* 3-5 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from scottames as a code owner September 16, 2026 10:42
@renovate
renovate Bot enabled auto-merge (squash) September 16, 2026 10:42
@scottames-github-bot

Copy link
Copy Markdown
Contributor

Renovate Release Notes

Generated from Renovate's update table by the renovate-release-notes-comment workflow.

Packages that cannot be summarized from GitHub releases are listed explicitly below.

astral-sh/ruff (aqua:astral-sh/ruff)

0.16.7: 0.16.7

Compare Source

Release Notes

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)
  • [ruff] Recognize re.prefixmatch (RUF039, RUF055) (#28311)

Bug fixes

  • Alternate nested quotes inside format spec interpolations (#28259)
  • [flake8-implicit-str-concat] Mark fix unsafe when it creates a docstring (ISC003) (#27981)
  • [flake8-tidy-imports] Skip fixes for multi-member imports (TID254) (#26584)
  • [pylint] Gate ImportCycleError on Python 3.15 (PLW0133) (#28310)

Rule changes

  • Correct D211 and D203 rule conflict diagnostic (#28444)
  • Recognize slice and frozendict generics (#28477)
  • Stop defining __cached__ for Python 3.15 (#28476)
  • [pyupgrade] Stop recommending removed typing.no_type_check_decorator (UP035) (#28475)

Performance

  • Reuse parser name lookups when interning (#28399)
  • Speed up inherited configuration resolution (#28299)

Documentation

  • Fix line-length path in --config example (#28392)
  • Remove the "Who’s Using Ruff?" list (#28455)

Other changes

  • Embed archive checksums in the shell installer (#28281)

Contributors

Install ruff 0.16.7

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.7/ruff-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.7/ruff-installer.ps1 | iex"

Download ruff 0.16.7

File Platform Checksum
ruff-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
ruff-x86_64-apple-darwin.tar.gz Intel macOS checksum
ruff-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
ruff-i686-pc-windows-msvc.zip x86 Windows checksum
ruff-x86_64-pc-windows-msvc.zip x64 Windows checksum
ruff-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
ruff-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
ruff-powerpc64-unknown-linux-gnu.tar.gz PPC64 Linux checksum
ruff-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
ruff-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
ruff-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
ruff-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum
ruff-armv7-unknown-linux-gnueabihf.tar.gz ARMv7 Linux checksum
ruff-aarch64-unknown-linux-musl.tar.gz ARM64 MUSL Linux checksum
ruff-i686-unknown-linux-musl.tar.gz x86 MUSL Linux checksum
ruff-x86_64-unknown-linux-musl.tar.gz x64 MUSL Linux checksum
ruff-arm-unknown-linux-musleabihf.tar.gz ARMv6 MUSL Linux (Hardfloat) checksum
ruff-armv7-unknown-linux-musleabihf.tar.gz ARMv7 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo astral-sh/ruff

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
astral-sh/uv (aqua:astral-sh/uv)

0.12.13: 0.12.13

Compare Source

Release Notes

Released on 2026-09-10.

Python

Enhancements

  • Verify hashes when downloading PEP 658 metadata sidecars (#21563)

Preview features

  • Respect ty exclusions when uv check automatically selects members of a virtual workspace (#21555)

Performance

  • Avoid full wheel downloads during resolution by reusing supported hashes from direct URL fragments when metadata is available separately (#21279)

Bug fixes

  • Edit Windows entry-point launcher resources in memory to support Nano Server and reduce antivirus contention (#18713)
  • Prefer core-metadata over legacy aliases in JSON index responses (#21563)

Install uv 0.12.13

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.ps1 | iex"

Download uv 0.12.13

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
uv-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
uv-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
uv-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum
uv-armv7-unknown-linux-gnueabihf.tar.gz ARMv7 Linux checksum
uv-aarch64-unknown-linux-musl.tar.gz ARM64 MUSL Linux checksum
uv-i686-unknown-linux-musl.tar.gz x86 MUSL Linux checksum
uv-riscv64gc-unknown-linux-musl.tar.gz RISCV MUSL Linux checksum
uv-x86_64-unknown-linux-musl.tar.gz x64 MUSL Linux checksum
uv-arm-unknown-linux-musleabihf.tar.gz ARMv6 MUSL Linux (Hardfloat) checksum
uv-armv7-unknown-linux-musleabihf.tar.gz ARMv7 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

0.12.12: 0.12.12

Compare Source

Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and uv and uv_build wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

Bug fixes

  • Exclude distributions uploaded after the exclude-newer cutoff from lockfiles and generated requirement hashes (#21539)

Install uv 0.12.12

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"

Download uv 0.12.12

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
uv-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
uv-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
uv-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum
uv-armv7-unknown-linux-gnueabihf.tar.gz ARMv7 Linux checksum
uv-aarch64-unknown-linux-musl.tar.gz ARM64 MUSL Linux checksum
uv-i686-unknown-linux-musl.tar.gz x86 MUSL Linux checksum
uv-riscv64gc-unknown-linux-musl.tar.gz RISCV MUSL Linux checksum
uv-x86_64-unknown-linux-musl.tar.gz x64 MUSL Linux checksum
uv-arm-unknown-linux-musleabihf.tar.gz ARMv6 MUSL Linux (Hardfloat) checksum
uv-armv7-unknown-linux-musleabihf.tar.gz ARMv7 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
atuinsh/atuin (aqua:atuinsh/atuin)

v18.22.0: 18.22.0

Compare Source

Release Notes

Bug Fixes

  • (daemon) Periodically flush captured command output to disk (#4070)
  • (daemon) Stream large DeleteHistory requests (#4076)
  • (daemon) Delete captured output when history entries are deleted (#4074)
  • (nix) Export OpenSSL lib for LD_LIBRARY_PATH in nix devshell (#4018)
  • (pty-proxy) Make PTY proxy aware of other PTYs (#4079)
  • (server) Wrap multi-write DB operations in transactions (#4088)
  • (server) Emit HTTP access logs at INFO and compile in debug tracing (#4087)
  • (sync) Expand a packfile whose range is a hole below the store head (#4085)
  • Normalize output of atuin --version (#4038)
  • Make atuin ai init a no-op instead of erroring (#4040)
  • Do not try to decrypt plaintext records (#4057)
  • Behavior of PTY proxy on terminal resizes (#4061)
  • Build error (#4094)

Features

  • (daemon) Daemon owns History Deletion (#4045)
  • (mcp) Make agents actually use the atuin MCP server (#4050)
  • (pty-proxy) Keep the start and end of command captures that exceed the max size (#4092)
  • (pty-proxy) Mirror the CWD of the PTY proxy child (#4091)
  • Implement command capture and remove semantic.rs (#4048)
  • Simplify semantic captures (#4065)
  • Store terminal size in command captures (#4072)
  • Version Stored Output Capture and Avoid PB on disk (#4068)
  • Redact secrets from captured command output (#4071)
  • Rework inspector and add output view (#4090)
  • Add [output_capture] settings (#4069)

Miscellaneous Tasks

  • (ci) Limit concurrency of workflows on same branch (#4073)
  • Lift dependencies into top-level Cargo.toml (#4042)
  • Sort dependencies in Cargo.tomls (#4046)
  • Enable Clippy cast warnings (#4049)
  • Temporary workaround for flaky test (#4083)
  • Emit proptest regression artifacts so CI failures are reproducible (#4084)
  • Lockfile bumps (#4089)
  • Don't fail if we can't capture output (#4086)
  • Link to upstream rustix issue in atuin-pty-proxy (#4093)

Refactor

  • (daemon) Manage sync inside of the daemon (#4055)
  • (daemon) Split output capture into fjall and nop backends (#4082)
  • (deps) Bump mkdocs-material from 9.7.0 to 9.7.7 in /docs in the uv group across 1 directory (#4059)
  • (deps) Bump vale-cli/vale-action from 2.1.2 to 3.0.0 (#3887)
  • (deps) Bump rpassword from 7.4.0 to 7.5.0 in the cargo group across 1 directory (#3877)
  • (history) Make HistoryId a Copy Uuid (#4013)
  • Clean up the history service and fix minor bugs

Testing

  • (daemon) Adversarial test suites with new daemon (#4058)
  • E2e pty test harness (#4075)
  • Filtered commands leave no captured output (#4081)

atuin-server 18.22.0

Install atuin-server 18.22.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/atuinsh/atuin/releases/download/v18.22.0/atuin-server-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/atuinsh/atuin/releases/download/v18.22.0/atuin-server-installer.ps1 | iex"

Download atuin-server 18.22.0

File Platform Checksum
atuin-server-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
atuin-server-x86_64-apple-darwin.tar.gz Intel macOS checksum
atuin-server-x86_64-pc-windows-msvc.zip x64 Windows checksum
atuin-server-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
atuin-server-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum
atuin-server-aarch64-unknown-linux-musl.tar.gz ARM64 MUSL Linux checksum
atuin-server-x86_64-unknown-linux-musl.tar.gz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo atuinsh/atuin

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

atuin 18.22.0

Install atuin 18.22.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/atuinsh/atuin/releases/download/v18.22.0/atuin-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/atuinsh/atuin/releases/download/v18.22.0/atuin-installer.ps1 | iex"

Download atuin 18.22.0

File Platform Checksum
atuin-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
atuin-x86_64-apple-darwin.tar.gz Intel macOS checksum
atuin-x86_64-pc-windows-msvc.zip x64 Windows checksum
atuin-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
atuin-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum
atuin-aarch64-unknown-linux-musl.tar.gz ARM64 MUSL Linux checksum
atuin-x86_64-unknown-linux-musl.tar.gz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo atuinsh/atuin

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
charmbracelet/gum (aqua:charmbracelet/gum)

v2.0.1: v2.0.1

Compare Source

No more gibberish

Screenshot 2026-09-11 at 09 34 44

This is a small Friday fix bumping Bubble Tea to fix these symbols leaking from keyboard protocol

Happy Friday and weekend,

Charm ☀️

Changelog

Other stuff

  • 7179388031ae67d7f538d001be87d931f1cf5e28: v2.0.1 (@​andrinoff)

Verifying the artifacts

First, download the checksums.txt file and the checksums.txt.sigstore.json file files, for example, with wget:

wget 'https://github.com/charmbracelet/gum/releases/download/v2.0.1/checksums.txt'
wget 'https://github.com/charmbracelet/gum/releases/download/v2.0.1/checksums.txt.sigstore.json'

Then, verify it using cosign:

cosign verify-blob \
  --certificate-identity 'https://github.com/charmbracelet/meta/.github/workflows/goreleaser.yml@&#8203;refs/heads/main' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  --bundle 'checksums.txt.sigstore.json' \
  ./checksums.txt

If the output is Verified OK, you can safely use it to verify the checksums of other artifacts you downloaded from the release using sha256sum:

sha256sum --ignore-missing -c checksums.txt

Done! You artifacts are now verified!

The Charm logo

Thoughts? Questions? We love hearing from you. Feel free to reach out on X, Discord, Slack, The Fediverse, Bluesky.

@scottames-github-bot

Copy link
Copy Markdown
Contributor
helm/helm (aqua:helm/helm)

v4.3.0: Helm v4.3.0

Compare Source

Helm v4.3.0 is a feature release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

  • Join the discussion in Kubernetes Slack:
    • for questions and just to hang out
    • for discussing PRs, code, and bugs
  • Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom
  • Test, debug, and contribute charts: ArtifactHub/packages

Notable Changes

Installation and Upgrading

Download Helm v4.3.0. The common platform binaries are here:

This release was signed with 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 and can be found at @​scottrigby keybase account. Please use the attached signatures for verifying this release using gpg.

The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with bash.

What's Next

  • 4.3.1 and 3.22.1 are the next patch releases scheduled for October 14, 2026
  • 4.4.0 is the next minor release scheduled for January 13, 2027. There will be no further Helm 3 minor releases (see https://helm.sh/blog/helm-v3-end-of-life)

Changelog

  • chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 bec5b06ed841fe5269972d864d5177944fd5970f (dependabot[bot])
  • chore(deps): bump the k8s-io group across 1 directory with 6 updates d0d42e7dd2b3948281300e5ac2d8d3a74c2a7c8f (dependabot[bot])
  • bump version to 4.3 (#32605) 7328f42a01d7fb96bd41b8fc70abc1fd7258cdb5 (Scott Rigby)
  • chore: Fix independent-merge lint issues ca6681ca55d39913b880871b6aa259efdf15e0b9 (George Jenkins)
  • refactor(repo): Use byte buffer to build index file (#32579) 37752b70b2f9c49dc6ac2f01e2a0aca1f32f0529 (Tom Wieczorek)
  • chore: fix gofumpt extra-rules (#32486) 28e64bd2ddb5412bff6d94d62b0114bb53f40931 (Matthieu MOREL)
  • Remove deprecated internal/chart/v3/ code (#32365) 4dfbaa40c6cd67e1df345889113a7879ec66136c (George Jenkins)
  • fix(template): regression - route registry messages to stderr in template and show (#32217) 9a3c040369361678aef1ab251e83a38b455f5159 (Aaron Mark)
  • refactor: remove per-file decompression size limit (#31748) 11e2010aebedf9f495a5c295635df096de7252f7 (Benoit Tigeot)
  • Updating the Go version b5b498b77403f93de037cba383f424953e87eaaa (Matt Farina)
  • Updating the Go version 6d1f67cf6a9918ebe6c41f05096b6fa3fdde1b5b (Matt Farina)
  • chore(deps): bump the github-actions group across 1 directory with 4 updates (#32574) 0f4decb96b1c4ac45981f495d45eef6cc82e3192 (dependabot[bot])
  • chore(deps): bump the k8s-io group with 7 updates (#32572) fb1930096eacec13ac911b8499905fc94eb09a8f (dependabot[bot])
  • fix: correct 'doest not match' in readiness debug logs 6888b0a280bb6fbb847c85d2a473c425b6a0862d (MsfPablo)
  • fix(provenance): support GnuPG keybox (pubring.kbx) keyrings (#32281) 67d54fd8808ab47e93dad40f4238d5fe28d1efd0 (Ruslan Shaydullin)
  • chore(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 (#32562) e9b85e4de16ad45805843fb121748018cf89094b (dependabot[bot])
  • chore(deps): bump the github-actions group across 1 directory with 4 updates (#32556) c000a408b81266d328db64aea2ff9e2e70844790 (dependabot[bot])
  • chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 (#32555) bafdcde8ecd83119afd7f98363b364138d3b35dc (dependabot[bot])
  • chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#32545) 2a29f1770b62844b27197d2507377361d45ad7c0 (dependabot[bot])
  • chore(deps): bump golang.org/x/text from 0.40.0 to 0.41.0 (#32543) edb94f897d1e0ec3335fb7268f07e0fd2666fbb8 (dependabot[bot])
  • test(loader): cover 8192-byte EOF boundary for LoadValues fd4ed4952b5f9f54344a0c014f7acd7885bd60c6 (Dean Chen)
  • fix(loader): do not drop values files ending at a 4096-byte boundary 601445e88cf1fe66b2885c793d564030aad1d707 (Dean Chen)
  • chore(deps): bump the github-actions group with 4 updates (#32523) f3d68cdbea3076a0283cbd1e3ec44a409ad48a43 (dependabot[bot])
  • fix: bump go.opentelemetry.io/otel to v1.44.0 for GO-2026-5158 (#32521) a0c2f6dade5180fdb08bcc5debef56357cd586ab (Terry Howe)
  • chore(deps): bump github.com/santhosh-tekuri/jsonschema/v6 (#32514) f8a308cd470bc1f087b3f4915ba775af18c5ffab (dependabot[bot])
  • chore(deps): bump the github-actions group with 4 updates 47eb219a71bac4638a9b9db916a5d8c415c553bc (dependabot[bot])
  • chore(deps): bump the github-actions group with 4 updates (#32508) ae877c8bfb943d2cc1aa10b34f0c4fada55e6f56 (dependabot[bot])
  • test(action): poll for the interrupted install goroutine instead of a zero-margin sleep (#32328) a8ab76e86f11e2ece5a3d0262313140e21db249b (Nikolaus Schuetz)
  • chore(deps): bump actions/stale in the github-actions group (#32487) ac1c68746f72e5bbbe5b7e5a052629aab7e5ab61 (dependabot[bot])
  • test(package): fix errorlint + exact path match in lock test e92316751375bafd4621232bb39a1238a22e91c4 (Ilya Kiselev)
  • fix(chart): normalize StampModTimes timestamp + Chart.lock test 3c3be926aaea573cf94931877e8072aefb231b60 (Ilya Kiselev)
  • chore(deps): bump go.yaml.in/yaml/v3 from 3.0.4 to 3.0.5 ce27485634fcbd54be8fc8d99a5e4799456420c9 (dependabot[bot])
  • fix(scripts): clarify cache-busting behavior bc0114c70841e2a05c95e53e20358fb761dbfb2e (Solomon Wakhungu)
  • chore: fix gofumpt issues 24bbb46c62a54000394ce77c4e3fda17d5566ffc (Matthieu MOREL)
  • fix(scripts): address cache-busting review feedback bbaf420a101379dad4f8452129cf26f2fff7e536 (Solomon Wakhungu)
  • Make golangci-lint happy f3edb83df48c505878ffd3ebb89ef6a809e14008 (MrJack)
  • Added missing import 94a3315f4d699c6bb4140550d4c98b46bb4382d2 (MrJack)
  • Readded "unicode/utf8" 500f02d597628d8ca7be8b530edcbedbf397b676 (MrJack)
  • Potential fix for pull request finding f1ede7c9c114c745da2f5c6cef8d27e1eb342498 (MrJack)
  • Apply suggestions from code review 4fcc4e4b3db363654f3dd5240211b195e309970e (MrJack)
  • refactor(rollback): validate description length before cluster reachability check 91520a78063582ab8265d9364815665f688deebc (MrJack)
  • refactor(test): reuse existing rollback.txt golden file e73dfab5fb47c9f3a0f24cb3f3a7a4aa8b65143e (MrJack)
  • Removed extra space in rollback-with-description.txt b177a8e9060720e91c402cdba2224c6d58789fa3 (MrJack)
  • Enhance rune count in pkg/cmd/rollback.go and pkg/action/rollback.go a92611c20241be8e7dc32f9b229afd2a722a06f8 (MrJack)
  • Use rune count to count properly multi-byte UTF-8 characters 8a34f3b7b4d9ffa4e82c7893eb3d8572fd464198 (MrJack)
  • Enhanced rollback description length cb91040c447723a7338a513a6d1604e5daaa1e0b (MrJack)
  • Changed if construction e69e424ab1917f0d53eafe63c408b5280b39624a (MrJack)
  • Set 256 as limit for maxDescriptionLength. 256 comes from MAX value for key and value b606955f095408270914c47eac8414b9061bfb49 (MrJack)
  • feat(rollback): add --description flag to provide rollback reason f8180e6de473bb4b1008b76aa2ac63b8bcd104c0 (MrJack)
  • Update resource_test.go 622f16b37fdb1f1915aece9436165dc53c26b3c5 (Matthieu MOREL)
  • Update labels_test.go 61d99a8bdbc90219c474c96e11790ab6a90cde61 (Matthieu MOREL)
  • Update chartrepo_test.go 532eabf88afa2b119f90ef82d1bf309923cbbb78 (Matthieu MOREL)
  • Update show_test.go bfca0688b1a44b1cf7ae37ac5f64792a8dffe7f1 (Matthieu MOREL)
  • Update rollback_test.go b59dfd39015311d94c04541ec5b91959c6b4b6d3 (Matthieu MOREL)
  • Potential fix for pull request finding a27f3a062027d8b459eed2186076fb9384b82f38 (Matthieu MOREL)
  • chore(pkg): refactor: finer tests conversions to testify part 1 828d01a8786162987482408b7803ceb3f3c176ac (Matthieu MOREL)
  • chore(pkg): refactor: finer tests conversions to testify part 3 9a2be11e6f1af0c89dc0988b88fd339751baa44c (Matthieu MOREL)
  • chore(pkg): refactor: finer tests conversions to testify part 2 4d9c03f51c30f851a03676a1315f492de10210e6 (Matthieu MOREL)
  • chore(internal): refactor: finer tests conversions to testify part 1 5142ca8ddca79a19c8529508c77ab4b27cb23a8f (Matthieu MOREL)
  • chore(deps): bump the k8s-io group across 1 directory with 7 updates (#32459) 8f74dce6ba8d7264ce75f52507616720865e712d (dependabot[bot])
  • chore(deps): bump ossf/scorecard-action in the github-actions group (#32458) 050d3e99b9dc8796ced4b99cb272cba91c43055f (dependabot[bot])
  • chore(deps): bump the github-actions group with 4 updates ea7c838e0875449a4b2fe141a961aa29f1435a5d (dependabot[bot])
  • chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.82.1 fe3f98b5641fe3a0a9fa2575df8698136c2a0029 (dependabot[bot])
  • chore(deps): bump actions/labeler from 6.2.0 to 7.0.0 (#32441) ed246e29f7940fffa4631aa67cfef66c5722d4a7 (dependabot[bot])
  • chore(deps): bump github/codeql-action/upload-sarif (#32440) 5223ceacda672bdd72efe8995d4abd9327c6539c (dependabot[bot])
  • chore(deps): bump github/codeql-action/autobuild from 4.37.1 to 4.37.2 a0f954e277702f87883d18760207b34ba3efbf80 (dependabot[bot])
  • chore(deps): bump github/codeql-action/init from 4.37.1 to 4.37.2 cdccef4818c06e4d1ee9521cfb9bcadc30c282e9 (dependabot[bot])
  • chore(deps): bump github/codeql-action/analyze from 4.37.1 to 4.37.2 065d3a6a3dcda016a9de88a9b32f0e9eedcf0876 (dependabot[bot])
  • chore: group github-actions dependabot updates cd4c5d3bfd7d19be9a3a01ba63a650cf044e1409 (Terry Howe)
  • chore(pkg): refactor: convert tests to testify assert/require part 19 33c28395695c53b579c1f94d3dfcadbe2ff2b862 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 22 0b1aa55cbb14ce3b7c805a6262e2159c4a70bf73 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 21 a934b827fa9569c8769c981b1d4847f72a4c1f94 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 20 1d4665e54c28a41a5631c19f3bff14ef3d4e058f (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 18 fb8a62bf13cbc0ad78d0856678365b246b224997 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 16 0fa9f7d427b99437e51dbb8ada21d19f93898652 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 17 4073566e285d5bfaafaf0cec2b927fa037bfcb2a (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 15 71733656a5c64307f85290bc9fe6480ad637a117 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 14 dc66ee7be786b1ac146a21fb2114b9678aaf25a4 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 13 aae82bf97a4c02c70982c14118912c459db43ec9 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 12 a3fa28ae22934450389ab31343c0ca20321d302c (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 11 dc3e3a5e7efadff49fd26eac511cf18801af0ebc (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 10 2f5a33fb77daca9ade910ed7fe557e3e85fd77f6 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 9 13d1edc5f346e136b249d4c8232e83689f07c3b4 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 8 e5f0e07b96580305c3902eceb738cef230b44bec (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 7 ca1767b81397e5ee3b3a5f7926590ddf1134c9c5 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 2 0daa77fa9bffe2c8359bb079d3e978fe74a0b5a4 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 1 d4ec8e9b87a002d48c2d7a8f3c145c9a324bfaef (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 6 0844b3b8b513e1ae6787c44fc5cfd224bf86c573 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 5 3ff05c835ecb1bbf794089d309556dbc75778ef7 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 4 658a8fac156a92a7462cc9aab98da796da6dc116 (Matthieu MOREL)
  • chore(pkg): refactor: convert tests to testify assert/require part 3 df2d013517b0a237ea8858677558db3129a92911 (Matthieu MOREL)
  • chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#32411) 8c7f3a14d2cbde663847641b1f4274d266e6f0f3 (dependabot[bot])
  • chore(internal): refactor: convert tests to testify assert/require part 4 (#32408) 6c45810119937e8fcbbc4f0b7f56c32a40c52d87 (Matthieu MOREL)
  • chore(internal): refactor: convert tests to testify assert/require part 3 668e7e580a01dbf66da0f620da6b980ee0cb4d80 (Matthieu MOREL)
  • chore(internal): refactor: convert tests to testify assert/require part 5 f1d5979e7d8b9d1e36b3cf703d150e8078c2e16e (Matthieu MOREL)
  • chore(internal): refactor: convert tests to testify assert/require part 6 f3402c1cd69b84d278af5a30551e376d727d27c1 (Matthieu MOREL)
  • chore(internal): refactor: convert tests to testify assert/require part 1 ba31ca0c0b455541f05986e8dcb8a0554fa70dd2 (Matthieu MOREL)
  • chore(internal): refactor: convert tests to testify assert/require part 2 615a29987660b11909f984887b47f7f608757d87 (Matthieu MOREL)
  • fix: pass registry client to downloader.Manager in upgrade 0604d8fb1ee8ea172604cb739c93ea8d5ad068c6 (Gates Wang)
  • perf: enable concurrent status computation to prevent multi-minute delays (#32043) 3bcf965f997499c477436515e6ccf5d51ab82e5e (Zhaofeng Miao)
  • remove legacy import comments from remaining packages (#31933) 82be04d7f2881f59b3a85483eb248417e1d18fc3 (Abhay Chaurasiya)
  • Potential fix for pull request finding c2fda5ac5835cd1eca44a29047c18edcde66e00f (Terry Howe)
  • fix: enhance error handling and improve test assertions (#32352) a2b1a60d51223254bd9c2f08cf3f411eb9d9fc58 (Matthieu MOREL)
  • fix(scripts): add cache-busting to get-helm-3 version check 5a30c7ae8504218fd68d87c5a7d929d0a3bb3891 (Solomon Wakhungu)
  • chore(deps): bump github/codeql-action init and analyze to 4.37.1 0563162dd95dcff0f7b1ac09e0c784ae21b72245 (Terry Howe)
  • chore(deps): bump github/codeql-action/upload-sarif (#32378) 06b95860dc2419062834a5e59921569676b45031 (dependabot[bot])
  • chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#32376) a494169853d1e6f752eb838fedbb00d1a8593b66 (dependabot[bot])
  • chore(deps): bump github/codeql-action/autobuild from 4.37.0 to 4.37.1 eeb37edfeafffdb562b97774f85a394332cf58dd (dependabot[bot])
  • chore: Add AI Vendor specific paths to .gitignore 8cd3a48c34136f14fa6ba60554ef5ab0e12625be (George Jenkins)
  • ci: auto-label PRs targeting main with v4.x 9f3c89a4b50e99a46c23b6942b87b205bdd8c33f (Benoit Tigeot)
  • fix: 'gocritic: filepathJoin path seperator' lint error 96a25ab4f86c2c78de2acfe45a69c0a40055aa3c (George Jenkins)
  • chore(internal): refactor: convert tests to testify assert/require part 3 caac755f199adf5ac4fbbc8c46a741d004ed7276 (Matthieu MOREL)
  • feat: honor SOURCE_DATE_EPOCH for chart archives (#32162) ad93b7df635d032a71201206cc3490e76b83bef4 (Lohit Kolluri)
  • Fix missing conflict retry with server-side apply (#32088) aa1ae3a36017156817e89e59eee0e88af9fc6365 (Jakub Jaruszewski)
  • chore: fix elseif and ifElseChain issues from gocritic (#32289) a02a5713deef0c0c1bf4359dcb0218a9c640224d (Matthieu MOREL)
  • chore(internal): refactor: convert tests to testify assert/require part 2 f280d9c1b5da4e2f25cac76b2fcce58bad35aae9 (Matthieu MOREL)
  • chore(internal): refactor: convert tests to testify assert/require part 1 d72b28ebcbecf1c582e57f17c1272536b90513d1 (Matthieu MOREL)
  • fix(ci): pin govulncheck-action to the v1.1.0 release (#32304) 68977ec0b5a446286668170dd72bdf59695f8cd5 (秀吉)
  • ci: track GitHub Actions updates on dev-v3 via Dependabot b963afaddfe127620c70773e46b1d3a1f9c559e8 (Terry Howe)
  • chore(deps): bump actions/stale from 10.3.0 to 10.4.0 (#32330) fb53c00ae72c08cf6d64289efde3aaeeda6c42fc (dependabot[bot])
  • chore(deps): bump github.com/mattn/go-shellwords from 1.0.13 to 1.0.14 (#32334) dad026acb8caab81411514715c50e50510f558ca (dependabot[bot])
  • chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#32333) 84e63e5c38913594e476b15609fb6c7ab2d60467 (dependabot[bot])
  • Address review comments 73c1fb245120df3f3adb53c12e69f29134147de7 (Matheus Pimenta)
  • Fix vanishing empty lines bfebbb7c1a3cea951dcc33d3253492f6a6df4eb2 (Matheus Pimenta)
  • fix: add missing https:// to Oracle link in ADOPTERS.md (#32324) 7b9a5c8911c7aa53eab1bfde995c63ff626a7ca4 (Akanksha Trehun)
  • fix: remove trailing whitespace in .golangci.yml (#32325) cfa3b24fe6c2a0e4bf22887cc1051d7674c6b348 (Akanksha Trehun)
  • fix(Makefile): update outdated .sha256 comment for Helm v4 (#32323) a91e9f6a249533cfd8fdb98cbd909ecb16bbc813 (Akanksha Trehun)
  • feat(linters): add new revive rules for better code quality 16787d65f5091cf5c5e4f2884ef0027ada117465 (Matthieu MOREL)
  • refactor: enable several checks from gocritic 9662fdd73b848e04889b452335b60250414ef6db (Matthieu MOREL)
  • fix(linters): update golangci-lint to 2.12.2 7bfcdb0fc34894ec6f1622f48608161188b2e2a8 (Matthieu MOREL)
  • chore(deps): bump github/codeql-action/analyze from 4.36.2 to 4.37.0 8118a4da1ed0ba470571ee3e150e4949b373ba9c (Terry Howe)
  • chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 0fc3b9385348b0d346728de3b0969ae2a3b7d47f (Terry Howe)
  • chore(deps): bump github/codeql-action/analyze from 4.36.2 to 4.37.0 71901a4c7cc6280317b892341b5dde5a866c952c (Terry Howe)
  • chore(deps): bump github/codeql-action/init from 4.36.2 to 4.37.0 (#32313) a71eb99db4f0c08fae21d3bfafa3bdfb6465b2a4 (dependabot[bot])
  • chore(deps): bump github/codeql-action/autobuild from 4.36.2 to 4.37.0 (#32305) ea52bdf7e2c5155d629c85aa7eb7f625eef92936 (dependabot[bot])
  • chore(deps): bump golang.org/x/text from 0.39.0 to 0.40.0 (#32309) a242855a7e2c31efd1f0f69ad1c5ae24be0563de (dependabot[bot])
  • chore(deps): bump github/codeql-action/upload-sarif (#32311) f25f9555785b15fc7f41aa2e5e43979b1bca5021 (dependabot[bot])
  • Potential fix for pull request finding ed651de9b12ff98c0aa13985a88bca9aca0aa4fb (Benoit Tigeot)
  • fix(ci): resolve Node 20 deprecation in govulncheck ca24a55c314d2fd84430d88c55ce09a391798d8e (Benoit Tigeot)
  • chore(deps): bump golang.org/x/text from 0.38.0 to 0.39.0 e3fbe2e9d10985fa30aeeb678c376d9556a2b6f7 (dependabot[bot])
  • chore: fix emptyStringTest, nestingReduce and singleCaseSwitch checks issues from gocritic 96b315f188932b7602e1ab1497e2d81d1caa8068 (Matthieu MOREL)
  • Update pkg/cmd/history_test.go c1569ea83ff40ab534f3db531316cb0408717d3c (Matthieu MOREL)
  • test: replace assert.Equal with require.EqualError for improved error handling 65077c10fa3e4f339142f498d84c1c7bfb1d320b (Matthieu MOREL)
  • test: replace assert.Contains with assert.ErrorContains for better error handling 4ade4a5495b81a4cf465906a2414267ed0b1dcc8 (Matthieu MOREL)
  • chore: fix several checks issues from testifylint f34ad6c337a53f0d77d1e24b5d1c6cdd1c57bc63 (Matthieu MOREL)
  • test(cli): use t.Cleanup for resetEnv with t.Setenv 47bde119597961113d769a9d46a565f448565e7a (LarytheLord)
  • test(cli): isolate user-agent rest config test from host kubeconfig 9b30076180b8f73bbe25d0f4cd752207154ad0c1 (LarytheLord)
  • chore: fix several checks issues from gocritic 07259ecc86521db556c4a18331241bbefc6bb6b2 (Matthieu MOREL)
  • fix(engine): prevent Files.Lines panic on empty file 143631f7356d7f2250540c044ae20277f495cc2f (Mahesh Sadupalli)
  • Potential fix for pull request finding d539556a8d03c48258d08207aaf918c202c90df6 (kimsungmin1)
  • chore(deps): bump github/codeql-action/upload-sarif e9eda8c5988d74172862b3b72cb1f8edf2226191 (dependabot[bot])
  • fix(registry): resolve golangci-lint issues in token-auth tests 503acff97580aa803f5d639fb1fbb06ad1226c31 (kimsm28)
  • chore: go mod tidy after rebase on main 4e9ca06856b1aeba65c4d4cd8e4dce4c83445776 (kimsm28)
  • fix(registry): use plain-http registry in token-auth scope test 3cbee7e935eb6e783c36b17d6eb79eb6edcda15b (kimsm28)
  • Update pkg/registry/client.go 26ada49c1ad50af5e11dbb8a65b703251295c689 (Terry Howe)
  • test: improve client_scope_test.go to avoid data races and brittle assertions 9b7a70f0ca4bf0dcfd242962d9eef211188057dd (kimsm28)
  • fix typos in withScopeHint function comment ee181f4570550d61379bf59f2a69b993b74d49cf (kimsm28)
  • fix registry test failures by adjusting DockerRegistryHost and auth server listener management 1f0a72849657c3fe167320f7f5729c377f6dadf8 (kimsm28)
  • fix variable naming requestUrl -> requestURL 8883c9cc7006eef7e3d07836b2d5dd7ca1066168 (kimsm28)
  • fix typo, remove unnecessary code, fix to avoid to use the assertion in http hanlder 530e728ea932109befc4a8165cd9a2bc78170c07 (kimsm28)
  • change suite.Nil, suite.NotNill to more proper function(suite.NoError, suite.Error) 26e5071f6680272d773f0ca22ea946a35c4dce66 (kimsungmin1)
  • change client_scope_test.go to use httptest 8c8d6e3262be77783ef42a47c9593b6e42a3066a (kimsungmin1)
  • fix typo 9d77ccd46ddf9b2675137891c159d1de35674072 (kimsungmin1)
  • remove freeport dependency fc743b2a1be47c69cc3bf58e0fdc023f8844f866 (kimsungmin1)
  • add newline in license header 319e06cda30e706db541066d5fe07249b0ed656c (kimsungmin1)
  • fix scope when helm push to a registry that use token auth 301e3a12d55c279ef3bd0b1976bafd43bc1e0b7b (kimsungmin1)
  • chore(deps): bump github.com/fluxcd/cli-utils from 1.2.1 to 1.2.2 5a9b8a788ff260c031f2d2f3e1b6903bd31b3496 (dependabot[bot])
  • chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 f76136d39f8c1fd6110a23317786c4c53f6f9cb9 (dependabot[bot])
  • Potential fix for pull request finding 144246cd2893f92ee8e477c691837ea27e8c2733 (George Jenkins)
  • chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0 07faec5593aabbde72c357d9c10123b6a3da33c5 (dependabot[bot])
  • Apply suggestions 61bba7c659e3b45ba4db195d58acc668a9c32441 (Will Noble)
  • Properly format the extra field in gzipped packages d887779b9b0eeb720672a7927479fc627e599c24 (Will Noble)
  • refactor(internal): convert tests to testify assert/require addbab2e6444954eb1a9bde86730ee7d11810b46 (George Jenkins)
  • refactor(internal/release): convert tests to testify assert/require 7ab295fcfcf3977599939d76ffbf7a266401bfbc (George Jenkins)
  • refactor(pkg/release): convert tests to testify assert/require 4cce0e9e2a870508864c1d497918e201dc0f339c (George Jenkins)
  • refactor(pkg/registry): convert tests to testify assert/require 8b0a167484a7f6de4a2cb12bf81641873a275d7b (George Jenkins)
  • refactor(internal): convert tests to testify assert/require 3ce02c585a18b38c5dba1177a54c3a0322c53d3c (George Jenkins)
  • refactor(repotest): convert tests to testify assert/require b42faba9d293d45d2654dac5b540adb5b50e5b4f (George Jenkins)
  • chore: enable contextcheck, fatcontext and noctx linters 34cfdfdbe57ec9690113e141395c499a7c00ca6b (Matthieu MOREL)
  • chore(deps): bump github.com/cyphar/filepath-securejoin a0c7d1e1f5ef222fb1be143e9846cebf8b3a2d54 (dependabot[bot])
  • chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 5848047c6b1e854fe7d451e451dbf748225232b9 (dependabot[bot])
  • test: use assert.Empty for zero-length assertions in validate_test c36e4d52bdf92a05a8d2d9f40e5927a1245dce2d (Terry Howe)
  • docs: fix typo in helm version command description dd442c0cc7c3d7f397bbf93ac5a9551a4e2f0139 (s3onghyun)
  • chore(deps): bump the k8s-io group across 1 directory with 7 updates fa68e6cb094e84076bfad53af494d7db7642ceee (dependabot[bot])
  • chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 3d2ff2a1aa3d8696105af5367a254c6824dff4a6 (dependabot[bot])
  • refactor(pkg/strvals): convert tests to testify assert/require daa045d4923007c1ab815b39038b81491506dc0a (George Jenkins)
  • refactor(pkg/cli): convert tests to testify assert/require 16b0760dfd99b5c501cbfc2138a207e1b3512c0f (George Jenkins)
  • Revert "fix(kube): prevent spurious early exit in WaitForDelete during informer sync" d3bd09147bbae09ca85615452bda31b8215e66f5 (George Jenkins)
  • Update pkg/ignore/rules_test.go 9ad5620edc1b51507d111f7f998cc0f5b95e5726 (George Jenkins)
  • docs: improve CONTRIBUTING.md wording fa9cb4919423e80d1693275396f9d8fa6b324baf (devShaik010)
  • refactor(pkg): convert tests to testify assert/require f4d713abb210230b3935c4a9685f1f34a8330970 (George Jenkins)
  • refactor(cmd/helm): convert tests to testify assert/require ed76a36ab9b4c8f5a56049aa201dd8ce04836ecb (George Jenkins)
  • chore: rename savedErr to clear its specific purpose 9c1d5a3b249c6684bfe902455a61e728bbf7dcf6 (Jeaeun Kim)
  • chore: fix lint 99baa2edd493af15ffd98f39808fac5c4a9b12f7 (Jeaeun Kim)
  • chore: store err separately for clarity ea847fef95702ca53ec5ab3c627c696ea1488598 (Jeaeun Kim)
  • chore: Improve error reporting for helm template --debug with --show-only 2014946e550ed7a667b9ae8cfe15a377a2fe94ca (Jeaeun Kim)
  • fix panic on repeated IsReachable calls 1f7869c31f8d96638d238957b20a27d665001d88 (Mohammad Abdolirad)
  • fix: protect FailingKubeClient.RecordedWaitOptions from data race (#31925) a5552edf9fb0e23b475310d943a2ecd1df5aeafd (Terry Howe)
  • fix: route registry client output to stdout instead of stderr (#32056) c2f1b238a114d6d7a85b37f80fc6975bd48e4c09 (Terry Howe)
  • fix(engine): add debug logging when lookup returns empty (#32205) 7058f841af78112f81098e3f434f90d30c43b4fd (Ogulcan Aydogan)
  • chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 74c1702157722e44f72c4a731c652c9e6ed58f83 (dependabot[bot])
  • chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 33b40718860fcb563ef34d0a4af2a1e565fdd108 (dependabot[bot])
  • chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 1019146bb36fde225ee93fdb173d12c91d96b834 (dependabot[bot])
  • chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 7f855dfe8a1176d41808451aa0e8ab7b11664f03 (dependabot[bot])
  • chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2 c603c50aa654b23c46c7e248cdf5cd016f0a3fa8 (dependabot[bot])
  • chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1 f8abbfd7d4ab7d9cd883fab5d24c8175eaec56b4 (dependabot[bot])
  • chore(deps): bump github.com/tetratelabs/wazero from 1.11.0 to 1.12.0 3aa1b742b9228219378ce3d1b978d8d9e30547cd (dependabot[bot])
  • Fix empty and len testifylint violations across test files 488c4a805debe0fc1b2777fa1823e079e79a5869 (Matthieu MOREL)
  • lower resync period 6dc1c1ccf8066b06f5e30c5bf1d2cdd2924c8c43 (Austin Abro)
  • chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 7510b832149ee739b3ace110f8238e1ffd922cca (dependabot[bot])
  • ci: enable bidichk linter to prevent invisible Unicode characters e679ec9f041f9fa484f8539efd4b5e665526b883 (Arnav Nagzirkar)
  • fix(deps): bump golang.org/x/net to v0.55.0 to address GO-2026-5026 54ae27fd841f33fd979476b1c378fe58fe7ff52f (Terry Howe)
  • chore(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 dbb3e353372f6e4abca9155c44d8b9a5f1e97626 (dependabot[bot])
  • chore(deps): bump github/codeql-action from 4.35.5 to 4.36.0 60665e9035ccab375780ef77934bde2ffa674448 (dependabot[bot])
  • docs: update version status for v4 stable release 442e1460b9ec4450a7c12d6b6a59848e7b16d9d1 (Benoit Tigeot)
  • chore(deps): bump actions/stale from 10.2.0 to 10.3.0 ace245b8273e23c9f12993befa535a19ab1bc172 (dependabot[bot])
  • fix(provenance): check error return in Digest e095e690a8b3c31b6dbcb9af02f870cc41fbf18b (Sebastien Tardif)
  • internal/plugin: remove zero-width spaces from plugin name comment 979e68fbbd5a932c67b756884880d7641f268632 (Aleksei Sviridkin)
  • Renamed flag from show-rollback to show-rollback-revision d097d882d473b42c7460d0be674138a3b52c08da (MrJack)
  • fix: skip non-Pod test hooks in GetPodLogs 1a1ec6e3cc052f1358ff668eeb439acd3f8e60c1 (Gregory Man)
  • fix(upstream): upgrade to cli-utils 1.2.1, controller-runtime 0.24.1 and k8s 1.36.1 378ceacd9ce239e5b3de1e7ce7c55cf18e16f69b (Matheus Pimenta)
  • chore(deps): bump github.com/fluxcd/cli-utils from 1.2.0 to 1.2.1 b5a9299eecefe45da13a01188cabac6af4c336d0 (dependabot[bot])
  • chore(deps): bump github/codeql-action from 4.35.4 to 4.35.5 f772ffedc6154f82bc0ac680f9ffa46054112ac0 (dependabot[bot])
  • fix(repo): use structured slog args in index.go ea2343ebeaf7b4b6b115fd1c7b34a159d6a573ff (Sebastien Tardif)
  • docs: fix 'than'->'that' typo in deprecatedAPIError godoc 2032ec5cbaf168de0fadc59959319e4b580ff72e (Kai Tanaka)
  • refactor: use slices.Backward to simplify the code 432fc8a21724cc75e0cd8ec8fd754d2bde42c15f (box4wangjing)
  • Potential fix for pull request finding 53d5f13f46f7dd555be8bd90616abdc77d470000 (Sumit Solanki)
  • fix(downloader): order DiskCache.Get checks for overlayfs empty dirs 6620fec5d19f6c86425501ee64f8cb8a8fb3fa3e (Sumit Solanki)
  • chore(deps): bump golang.org/x/crypto from 0.50.0 to 0.51.0 2cc69251d81ad94e9e0edbea6c31dedf4e2c25d4 (dependabot[bot])
  • chore(deps): bump github/codeql-action from 4.35.3 to 4.35.4 d9b2716be5fbb3309c3176b0c887d91ffb16c048 (dependabot[bot])
  • Bump to version v4.2 (#32102) 19b3656306829cae166f484feb4a1319f47844c0 (George Jenkins)
  • Fix lint errors 03a65a71f7397620315747ecac4ba60b73f63623 (Evans Mungai)
  • fix: address Copilot review on ownership-verified uninstall 007713087bd4f381bb8b74f66f35af9e3dafa376 (Evans Mungai)
  • Potential fix for pull request finding 9728c5af31c7039e9806037c4e59e46eeb43d79c (Evans Mungai)
  • fix: address review feedback 922558fc1a3b3f2c2b7e8ad0f32bd5bcd46ca70e (Sebastien Tardif)
  • fix: fetch logs from all containers in test pods 854f7f6b7217dcfe135df9e4652517d3ec9c3913 (Sebastien Tardif)
  • fix(registry): remove pre-Go-1.20 transport cloner fallback 73f71bceae2674d41fb2f082ee4fa5a842b613cc (Ogulcan Aydogan)
  • testifylint: enable error-is-as and error-nil rules f8ba28bb17f9254bc2c1b6409b24c16a59934a9c (Matthieu MOREL)
  • fix(kube): always propagate context.Canceled in WaitForDelete 5e09ee78ee5861b857a3526a2fd1ddf2f73950e2 (Terry Howe)
  • fix(kube): prevent spurious early exit in WaitForDelete during informer sync 4e24ee41a436889a2542a008eaa0ecab8332a1eb (Terry Howe)
  • fix(version): avoid false range detection on prerelease x/X 740174a2b12074f7ca506ff330a918a4ff335c39 (Benoit Tigeot)
  • fix(version): version range || can has no space b79d7f18813796f101f66eff6c513ded25edf0ad (Benoit Tigeot)
  • feat: report in debug the version we select with version range arg bf78b876c74ee4359a6cebb54e0b97183cdfe129 (Benoit Tigeot)
  • fix: prevent warning when using version range constraints 1e145ee2b243ef97bce0622cf55da8aa17ebb65f (Benoit Tigeot)
  • Add duration functions 722dd3e3a82b06fbda60ebf24edc653e7b74e3f9 (Jorge Rocamora)
  • chore: fix deprecatedComment issues from gocritic 83a0138172e22f5efb7d9852b3ed0fb5fc8117b2 (Matthieu MOREL)
  • chore: enable errorlint linter af31a679244b584317fd8053aee498c4d5ec301c (Matthieu MOREL)
  • chore: fix whitespace linter 1e0f702f00d5fd36c9de9448e3271787bc588273 (Matthieu MOREL)
  • fix: address Copilot review feedback on rollback revision PR 6927cde3f98d9e5f248418805e40c7408e629746 (MrJack)
  • feat(history): add --show-rollback flag for opt-in rollback column e889cff0896d842c7e1854729611ac520a925d0b (MrJack)
  • Update pkg/cmd/testdata/output/history-with-rollback.txt 681ccb19a68dab98b75e407ba38b37c45ee9c5d1 (MrJack)
  • Update pkg/cmd/history_test.go 0737e438aae04fca872b66f185b0f2aab8bd0d86 (MrJack)
  • Added missing pkg/cmd/testdata/output files d52b489459d51d67d9db877f169bd09273b6cd6c (MrJack)
  • feat(history): add rollback revision column to helm history output 300f71b1ebb1b383241a1806a813c6f30a8ff382 (MrJack)
  • Add ownership verification to uninstall action f552950b05066d4d6a9d6cf9a91c26656f4a90fc (Evans Mungai)
  • Additional logging for ownership verification in dry-run mode 6d5b5aab32be039f8f56b0c497a7f4af28ce21f0 (Evans Mungai)
  • feat: add ownership verification before deleting resources during uninstall 906f87ce1d6d7a46bc68601c1217623e40b78877 (Evans Mungai)
junegunn/fzf (aqua:junegunn/fzf)

v0.74.4: 0.74.4

Compare Source

Demo: Non-blocking fzf vim plugin on tmux floating pane

fzf-vim-show.mp4

  • Fixed an escape sequence split across reads being parsed as a fragment, which leaked the rest into the query (#4899)
    • e.g. A terminal answering the startup DECRQM query late left ?2004;2$y, CTRL-UP left 5A, and SGR mouse input left 0;1;1M
  • Fixed --tiebreak=pathname not detecting the last path separator when the line contains a non-ASCII character before it (#4902)
  • Fixed progress in the --listen status payload staying at 100 while a new search was running, which made a snapshot with a new query and the previous result set look complete (#4903)
    • It is now reset when a search starts and reaches 100 on the final result, so progress of 100 means the matches belong to the query reported next to them
  • Fixed adaptive height not reserving a line for the divider of an inline header or footer border, so the list came up one line short for each of them (#4904)
    • e.g. seq 10 | fzf --height=~100% --list-border --header-lines=1 --header-lines-border=inline
  • Fixed fzf erasing the line the prompt was on when it exits, which made the last line of the prompt flicker in fish, bash, and nushell (#4913)
  • Fixed fzf exiting with status 2 while waiting for a key, when --listen is used and 100+ signals interrupt the wait (#4917)
  • Vim plugin
    • fzf no longer blocks the editor, so live previews keep working while fzf is open
      • fzf#run returns an empty list when it runs fzf asynchronously. Use sink, sinklist, or exit to get the result
    • The popup layout now works under Zellij
    • Added popup as a synonym of the tmux layout key
      let g:fzf_layout = { 'popup': '90%,70%' }
    • fzf now opens in a tmux or Zellij floating pane by default, so the window it was started from stays visible and can be used while fzf is running
      • Requires tmux 3.7+ or Zellij 0.44+
      • Set g:fzf_layout to pick a different layout
  • fish
    • Fixed custom CTRL-T command not using the prefixed target directory in some cases (#4498) (@​bitraid)
    • Optimized description alignment of completion items (#4910) (@​bitraid)
  • nushell
    • Added key bindings for Helix editing modes, on nushell 0.115.0 or above (#4914) (@​sim590)
    • Fixed CTRL-T inserting the selected paths unquoted
      • p4p3r (@​P4P3R-HAK) reported the security vulnerability and suggested the fix

@scottames-github-bot

Copy link
Copy Markdown
Contributor
openai/codex (aqua:openai/codex)

rust-v0.154.0: 0.154.0

Compare Source

New Features

  • GPT-6-Astra is now available in the model picker and Amazon Bedrock catalogs. (#42879, #42619)
  • Experimental worktree support lets you create isolated checkouts for new or forked sessions using --worktree or /worktree, then browse and resume them. (#42652, #43069, #43120, #43286)
  • Answer questions inline while Codex continues working, using suggested choices or custom text without losing your main draft. (#42891, #42894, #42897)
  • Windows sessions can now share a background Codex server, with daemon lifecycle commands and managed updates. (#42405, #42392)
  • Vim editing gains R replace mode with undo and dot-repeat, plus more reliable Escape handling in legacy terminals. (#42194, #42584)
  • Copying responses preserves formatting in rich-text apps, and /copy can copy status output or individual session fields. (#42847, #43055)

Bug Fixes

  • Existing sessions pick up newly installed plugin tools and refresh skills and hooks after external plugin upgrades or rollbacks. (#42284, #42593, #42990)
  • MCP connections coordinate OAuth token refreshes and surface login challenges when refresh fails, without automatically replaying rejected tool calls. (#42413, #42552)
  • Startup avoids running workspace-controlled helpers before trust is established, and the macOS sandbox blocks terminal input injection. (#42324, #42590)
  • Remote resume and fork operations preserve saved permissions; fresh sessions and forks respect server model defaults unless explicitly overridden. (#43330, #43177, #43355)
  • Resuming a conversation open in another app now shows a read-only transcript with a retry option while preserving your draft. (#43253)
  • Automatic approval reviews better preserve authorization context through compaction and reject approvals invalidated by new user instructions or answers. (#42844, #42852, #43442)

Documentation

  • Updated the bundled OpenAI Docs skill with GPT-6-Astra migration, compatibility, and prompting guidance. (#42931)

Chores

  • The deprecated codex mcp-server entry point is no longer available. (#42993)

Changelog

Full Changelog: openai/codex@rust-v0.153.0...rust-v0.154.0

  • #42188 Fix punctuation in npm packaging documentation @​copyberry
  • #42192 Use native spawning for bare macOS MCP commands @​copyberry
  • #42194 Add Vim replace mode to the TUI composer @​copyberry
  • #42196 Add managed worktree creation @​copyberry
  • #42199 Refactor shared TUI input routing @​copyberry
  • #42202 Separate TUI preferences from server configuration @​copyberry
  • #42204 Add macOS voice runtime projection @​copyberry
  • #42207 Retry TUI reconnects while threads are closing @​copyberry
  • #42208 Add GNU Linux voice runtime preparation @​copyberry
  • #42209 Add Windows voice runtime preparation @​copyberry
  • #42247 Track history notes thread hint outcomes @​copyberry
  • #42256 Skip Guardian scoring in User approval mode @​copyberry
  • #42270 Report the exec-server release version in environment info @​copyberry
  • #42284 Refresh plugin skills after out-of-process version changes @​copyberry
  • #42288 Fetch rules_rs zlib packages from Ubuntu snapshots @​copyberry
  • #42290 Expand Guardian history coverage across resume and rollback @​copyberry
  • #42293 Preserve verified answers across history compaction @​copyberry
  • #42298 Preserve retained answers across steer rollbacks @​copyberry
  • #42306 Stabilize the detached exec-server session resume test @​copyberry
  • #42309 Separate Windows sandbox provisioning from ACL refresh @​copyberry
  • #42314 Preserve target-native cwd in permission approval requests @​copyberry
  • #42316 Refactor exec-server startup futures @​copyberry
  • #42318 Support packaged managed Codex binary paths @​copyberry
  • #42319 Show live context compaction status in the TUI @​copyberry
  • #42320 Make the app-server thread unload delay configurable @​copyberry
  • #42324 Avoid executing PATH helpers before workspace trust @​copyberry
  • #42325 Render completed assistant messages directly during replay @​copyberry
  • #42326 Harden Windows control socket rendezvous @​copyberry
  • #42328 Support durable reasoning configuration updates @​copyberry
  • #42330 Protect Windows sandbox binaries from inherited write access @​copyberry
  • #42332 Package prepared runtimes with the voice host @​copyberry
  • #42334 Add a Windows sandbox provisioning protocol @​copyberry
  • #42337 Add an authenticated Windows sandbox provisioning client @​copyberry
  • #42341 Add Windows sandbox service lifecycle scaffolding @​copyberry
  • #42342 Harden Windows sandbox provisioning file handling @​copyberry
  • #42344 Prepare managed policy validation for Windows sandbox provisioning @​copyberry
  • #42348 Add Windows sandbox client authentication @​copyberry
  • #42351 Enable authenticated Windows sandbox provisioning @​copyberry
  • #42353 Add experimental Windows sandbox service provisioning @​copyberry
  • #42354 Add free-form asynchronous user messages @​copyberry
  • #42356 Initialize questions in buffered replay test messages @​copyberry
  • #42358 Extend rate limit reads with usage capabilities @​copyberry
  • #42364 Support graceful daemon shutdown on Windows @​copyberry
  • #42366 List managed worktrees for a repository @​copyberry
  • #42369 Keep SQLite history projection moving past invalid records @​copyberry
  • #42370 Improve MCP server startup error logging @​copyberry
  • #42372 Add Luna Reserve usage fallback to the TUI @​copyberry
  • #42373 Add attributed exec process lifecycle telemetry @​copyberry
  • #42374 Extract PID startup into a dedicated module @​copyberry
  • #42375 Clean up Windows sandbox resources on app uninstall @​copyberry
  • #42377 Make app-server realtime sessions always available @​copyberry
  • #42378 Route rollout reads through the canonical JSON decoder @​copyberry
  • #42380 Require confirmation for safety-buffered retries @​copyberry
  • #42381 Support managed app-server lifecycle on Windows @​copyberry
  • #42383 Update rmcp to 3.2.0 @​copyberry
  • #42384 Add an RMCP OAuth credential store adapter @​copyberry
  • #42385 Add experimental context management activation @​copyberry
  • #42386 Expose loaded thread environments in app-server responses @​copyberry
  • #42388 Recover deferred environments after provisioning failure @​copyberry
  • #42391 Authorize apply_patch in the executor path context @​copyberry
  • #42392 Support managed daemon updates on Windows @​copyberry
  • #42395 Expose the Codex version to commands and turn metadata @​copyberry
  • #42397 Extract focused TUI logic into submodules @​copyberry
  • #42399 Preserve restored input after resolved misalignment errors @​copyberry
  • #42401 Discover TUI collaboration modes from the app server @​copyberry
  • #42403 Expose the last accepted environment ready report @​copyberry
  • #42404 Read voice helper frames independently of pipe chunks @​copyberry
  • #42405 Support the app-server daemon on Windows @​copyberry
  • #42406 Honor explicit plugin mentions during MCP startup @​copyberry
  • #42408 Harden embedded composer input handling @​copyberry
  • #42410 Allow reviewing and continuing misalignment-paused chats @​copyberry
  • #42413 Enable coordinated MCP OAuth refresh @​copyberry
  • #42417 Expose managed application network requirements @​copyberry
  • #42419 Add session resume to the agent command center @​copyberry
  • #42422 Honor model requirements in Guardian computer-use scoring @​copyberry
  • #42425 Discover TUI experimental features from the server @​copyberry
  • #42428 Use the shared composer in the agent command center @​copyberry
  • #42432 Box the TUI resume picker future @​copyberry
  • #42445 Include originator in plugin measurement analytics @​copyberry
  • #42451 Acknowledge pending TUI steers by submission ID @​copyberry
  • #42453 Discover permission profiles from the app server @​copyberry
  • #42455 Show live task details in the agent command center @​copyberry
  • #42458 Expose thread originators through the app-server API @​copyberry
  • #42529 Register the Guardian thread context feature flag @​copyberry
  • #42552 Preserve MCP authentication challenges on tool calls @​copyberry
  • #42577 Preserve target-native paths in command approvals @​copyberry
  • #42579 Persist verified user answers in Guardian thread context @​copyberry
  • #42584 Recover Vim escape input in legacy terminals @​copyberry
  • #42588 Require Guardian review for incompatible compaction checkpoints @​copyberry
  • #42590 Harden the macOS sandbox against terminal input injection @​copyberry
  • #42593 Reload user config after local plugin installation @​copyberry
  • #42596 Record Windows sandbox private desktop usage @​copyberry
  • #42598 Report MCP tool discovery errors in server status @​copyberry
  • #42602 Deprecate detached review delivery @​copyberry
  • #42603 Expose global metrics installation in codex-otel @​copyberry
  • #42606 Support trusted headers for remote exec WebSockets @​copyberry
  • #42607 Add GPT-6-Astra to the bundled model catalog @​copyberry
  • #42609 Condense TUI startup warnings @​copyberry
  • #42619 Add GPT-6-Astra to Amazon Bedrock catalogs @​copyberry
  • #42623 Bound Noise handshakes by the exec server initialization timeout @​copyberry
  • #42624 Centralize prompt image detail modes @​copyberry
  • #42631 Initialize the packaged GStreamer runtime in the voice host @​copyberry
  • #42634 Add an injectable attachment store to ThreadManager @​copyberry
  • #42638 Update GPT-6-Astra Fast tier speed description @​copyberry
  • #42639 Warn when saved model defaults are overridden @​copyberry
  • #42640 Harden TUI parsing of assistant markup @​copyberry
  • #42641 Restore the inline TUI after full-screen overlays @​copyberry
  • #42650 Render assistant file citations as local links @​copyberry
  • #42652 Add managed worktrees to codex exec @​copyberry
  • #42654 Update the stable exec-server test to Codex 0.153.1 @​copyberry
  • #42657 Use a generic fallback model name in status tests @​copyberry
  • #42667 Tailor TUI cyber refusal notices to Daybreak eligibility @​copyberry
  • #42668 Cancel remote control enrollment on stdio shutdown @​copyberry
  • #42671 Preserve TUI sessions while starting replacement threads @​copyberry
  • #42674 Persist server-advertised experimental features from the TUI @​copyberry
  • #42676 Add WebRTC negotiation to the voice host @​copyberry
  • #42677 Narrow async user message guidance @​copyberry
  • #42682 Fix the worktrees experimental feature test fixture @​copyberry
  • #42716 Allow trusted symlinks beneath CODEX_HOME on macOS @​copyberry
  • #42718 Gate unified exec TTY support behind a feature flag @​copyberry
  • #42741 Make the TUI symlink startup test Bazel-compatible @​copyberry
  • #42744 Honor model-provided Guardian review policies @​copyberry
  • #42746 Handle pending network reviews after process completion @​copyberry
  • #42749 Improve automatic thread naming in the TUI @​copyberry
  • #42752 Preserve response IDs for fast collaborator tool events @​copyberry
  • #42755 Stabilize the interactive tmux startup safety test @​copyberry
  • #42758 Propagate response tickets to Guardian reviews @​copyberry
  • #42762 Retain user instructions in guardian thread context @​copyberry
  • #42767 Avoid port races in streamable HTTP tests @​copyberry
  • #42770 Preserve acceptance order in retained thread context @​copyberry
  • #42773 Avoid holding metadata permit during cold resume config load @​copyberry
  • #42781 Add direct SigV4 transport to exec-server @​copyberry
  • #42791 Keep TUI prompt history tied to local settings @​copyberry
  • #42792 Extract the note input view into its own module @​copyberry
  • #42798 Add data-use disclosures to the user report dialog @​copyberry
  • #42801 Keep the Windows sandbox command runner hidden @​copyberry
  • #42807 Add request-scoped Guardian approval decisions @​copyberry
  • #42811 Enable staging login issuer overrides in packaged builds @​copyberry
  • #42814 Support custom report event titles @​copyberry
  • #42819 Route Guardian approvals independently of async scoring @​copyberry
  • #42821 Report managed filesystem policy in codex doctor @​copyberry
  • #42823 Expose managed WebMCP policy through the app server @​copyberry
  • #42824 Refine user input guidance for GPT-6 @​copyberry
  • #42832 Preserve root authorization context in Guardian reviews @​copyberry
  • #42833 Preserve SystemRoot for Windows sandbox wrapper setup @​copyberry
  • #42835 Preserve Windows managed deny reads in the sandbox CLI @​copyberry
  • #42836 Make GPT-6-Astra user input guidance conditional @​copyberry
  • #42838 Preserve executor paths in Guardian approval reviews @​copyberry
  • #42841 Add a native Windows MXC sandbox adapter @​copyberry
  • #42842 Add Astra sparkle effects to the TUI composer @​copyberry
  • #42844 Retain user instructions in Guardian context @​copyberry
  • #42847 Preserve Markdown formatting when copying TUI responses @​copyberry
  • #42850 Use jemalloc for Linux musl binaries @​copyberry
  • #42852 Harden Guardian reviews after context compaction @​copyberry
  • #42854 Persist Daybreak preferences in thread metadata @​copyberry
  • #42863 Preserve precedence across feature requirement aliases @​copyberry
  • #42870 Avoid redundant filesystem sandbox path resolution @​copyberry
  • #42879 List GPT-6-Astra in the model picker @​copyberry
  • #42883 Add client-side exec-server RPC attempt metrics @​copyberry
  • #42889 Add TUI building blocks for inline async question editing @​copyberry
  • #42891 Integrate asynchronous questions into the TUI @​copyberry
  • #42894 Support selectable answers for asynchronous TUI questions @​copyberry
  • #42897 Add inline Other answers to async question choices @​copyberry
  • #42900 Establish root turn identity for independent tasks and memory requests @​copyberry
  • #42903 Preserve TUI question state and integrate history and queue navigation @​copyberry
  • #42904 Use static instructions for the Default collaboration mode @​copyberry
  • #42931 Update OpenAI Docs skill guidance for GPT-6 Astra @​copyberry
  • #42933 Wait for turn analytics before shutting down the Guardian v2 test @​copyberry
  • #42990 Refresh session hooks after external plugin updates @​copyberry
  • #42993 Remove the deprecated codex mcp-server command @​copyberry
  • #43000 Preserve the resolved multi-agent version when reverting threads @​copyberry
  • #43002 Replace Guardian tickets with parent response IDs @​copyberry
  • #43005 Add Guardian V2 failure reasons and connection timing metrics @​copyberry
  • #43031 Keep refreshed MCP tool catalogs with their clients @​copyberry
  • #43039 Refresh live thread tools through app/installed @​copyberry
  • #43043 Avoid filesystem scans when seeding the agents overview @​copyberry
  • #43055 Allow /copy to copy status output and individual fields @​copyberry
  • #43069 Support managed worktrees for interactive sessions and forks @​copyberry
  • #43070 Clarify comments in CI setup and the Rust workflow @​copyberry
  • #43074 Show a retryable error when the apps popup fails to load @​copyberry
  • #43079 Add opt-in local audio devices to the voice helper @​copyberry
  • #43083 Supply Bazel-managed CMake and Ninja for the bundled Opus build @​copyberry
  • #43090 Send processed microphone audio over RTP in voice-host @​copyberry
  • #43097 Add a helper-backed realtime WebRTC session API @​copyberry
  • #43099 Add receipt-verified native voice SDK export @​copyberry
  • #43100 Add bounded incoming Opus RTP handling to the voice host @​copyberry
  • #43102 Include GIO in voice SDKs and native runtimes @​copyberry
  • #43104 Move Guardian thread context into guardianv2 configuration @​copyberry
  • #43109 Add explicit toolchain inputs for native voice builds @​copyberry
  • #43110 Record reasoning effort changes in conversation history behind a flag @​copyberry
  • #43111 Add a Bazel target for native voice dependencies @​copyberry
  • #43113 Save subagent and memory opt-ins through the app server @​copyberry
  • #43114 Add Bazel preparation for native voice runtimes @​copyberry
  • #43117 Link Unix Bazel bindings against the prepared voice runtime @​copyberry
  • #43120 Add managed worktree creation to TUI session commands @​copyberry
  • #43121 Require a prepared runtime when assembling voice helper packages @​copyberry
  • #43125 Add explicit Windows tool selection for native voice builds @​copyberry
  • #43126 Expose native Windows build tools through Bazel targets @​copyberry
  • #43144 Add Windows MSVC Bazel targets for native voice libraries @​copyberry
  • #43147 Gate experimental context by model capability at session startup @​copyberry
  • #43177 Use server model defaults for fresh TUI startup @​copyberry
  • #43178 Allow guarded legacy resume with background migration enabled @​copyberry
  • #43244 Add bounded GStreamer playback components to the voice host @​copyberry
  • #43248 Connect voice-host RTP audio to speaker playback @​copyberry
  • #43253 Show read-only conversations when resume encounters an active writer @​copyberry
  • #43261 Use server defaults when starting TUI background tasks @​copyberry
  • #43265 Add experimental user verification API contracts @​copyberry
  • #43279 Include linked worktrees in TUI session discovery @​copyberry
  • #43281 Move npm package staging into a separate release workflow job @​copyberry
  • #43282 Make Bazel binary stamping opt-in @​copyberry
  • #43286 Add a managed worktree browser to the TUI @​copyberry
  • #43289 Add capability-gated MCP user-verification handling @​copyberry
  • #43298 Defer managed worktree transitions to fresh TUI loop iterations @​copyberry
  • #43304 Isolate Bazel build commit metadata from Rust compilation inputs @​copyberry
  • #43308 Replace Windows app-server shutdown files with socket requests @​copyberry
  • #43315 Resolve session labels uniquely before acting on them @​copyberry
  • #43325 Sort JSON schema object keys for consistent Cargo and Bazel output @​copyberry
  • #43330 Preserve saved permissions when resuming or forking remote tasks @​copyberry
  • #43340 Enable remote named permission profile selection in the TUI @​copyberry
  • #43352 Add opt-in MCP user-verification transport @​copyberry
  • #43355 Let the app server resolve implicit model settings for CLI forks @​copyberry
  • #43359 Show the server's model provider ID in TUI status @​copyberry
  • #43360 Use app-server metadata for TUI session restoration @​copyberry
  • #43376 Defer resume picker and directory changes to a fresh TUI stack @​copyberry
  • #43408 Avoid WebSocket connection waits in Guardian v2 classification @​copyberry
  • #43419 Initialize cwd in TUI resume and fork test fixtures @​copyberry
  • #43421 Remove the app-server README and its contributor guidance references @​copyberry
  • #43423 Remove the app-server docs update requirement from AGENTS.md @​copyberry
  • #43426 Handle Luna HTTP requests in guardian history tests @​copyberry
  • #43428 Notify opted-in stdio MCP servers of auth changes @​copyberry
  • #43432 Route approvals through the extension decision API @​copyberry
  • #43442 Keep Guardian review evidence consistent and reject stale approvals @​copyberry
  • #43444 Pin V8 release manifests and prevent published release replacement @​copyberry
  • #43447 Route MCP elicitations through the shared approval decision path @​copyberry
  • #43454 Add diagnostic labels to shell snapshot capture metrics @​copyberry
  • #43456 Wait for thread idle before rollback in model-switching tests @​copyberry
  • #43458 Centralize Guardian context mode and checkpoint policy @​copyberry
  • #43462 Remove legacy Guardian approval review paths @​copyberry
  • #43472 Recover missing Guardian root instructions in acceptance order @​copyberry
  • #43478 Retain inherited Guardian instructions in standalone forks @​copyberry
  • #43490 Expose shared Guardian reviewer helpers through guardian_review @​copyberry
  • #43491 Include unloaded children in multi-agent v2 environment context @​copyberry
  • #43494 Limit archive rollout reads to requested threads @​copyberry
  • #43495 Allow internal sessions to fork from selected history @​copyberry
  • #43504 Treat zombie processes as inactive in the Unix PID backend @​copyberry
  • #43513 Expose a stable executor build identity in environment metadata @​copyberry
  • #43519 Set recursion_limit to 256 for app-server, exec, and TUI @​copyberry
snyk/cli (aqua:snyk/cli)

v1.1307.2: v1.1307.2

Compare Source

1.1307.2 (2026-09-09)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

@scottames-github-bot

scottames-github-bot Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor
anthropics/claude-code (github:anthropics/claude-code)

v2.1.270: v2.1.270

Compare Source

What's changed

  • Fixed read-only git commands in Bash unexpectedly asking for permission after a session had been running for a while (regression in 2.1.269)

v2.1.269: v2.1.269

Compare Source

What's changed

  • Added claude plugin eval: run a plugin's eval suite against Claude Code and get scored, reproducible results (JSON + HTML report); see claude plugin eval --help
  • Added /output-style [name] to list and switch output styles, including over Remote Control and in cloud and other headless sessions
  • Added a diff of the files a Bash command changed to the Bash tool result when the Bash tool handles file edits (setting bashEditDiffEnabled)
  • Added OTEL_METRICS_INCLUDE_REPOSITORY to tag OpenTelemetry metrics and events with vcs.* repository attributes; commit events get vcs.ref.head.* with OTEL_LOG_TOOL_DETAILS
  • Added CLAUDE_CODE_GATEWAY_MODEL_DISCOVERY_TIMEOUT_MS to extend the LLM gateway /v1/models discovery timeout (default 3s)
  • Added a spinner tip suggesting /focus for a view with just your prompt, a one-line work summary, and the response
  • Added CLAUDE_CODE_WORKFLOW_MAX_CONCURRENT_AGENTS (1–256) to raise the Workflow tool's per-run concurrent agent limit for inference-bound fan-outs
  • Fixed the prompt cache being partially invalidated on the turn after a response was cut off at the output-token limit and automatically resumed
  • Fixed a case where resuming a session after interrupting Claude mid-thought could change how earlier context was re-sent, hurting prompt-cache reuse
  • Fixed F1/F2/F4 not working in kitty-protocol terminals and Delete in st, Alt+arrows acting as Escape in rxvt-unicode, and Shift+punctuation typing the unshifted key in WezTerm (regression in 2.1.247)
  • Fixed remote and headless sessions reporting "waiting for your input" while background agents were still running (set CLAUDE_CODE_BG_TASKS_REPORT_RUNNING=0 to restore the old behavior)
  • Fixed the terminal's replies to capability queries (^[[?1;2c) appearing as stray text at startup in some terminals
  • Fixed rows at the top or bottom of the transcript going blank in fullscreen after resizing the terminal
  • Fixed a deny or ask permission rule starting with ! applying beyond the settings source that wrote it; such a rule now applies only within its own source, and a bare ! negation is ignored
  • Fixed the git status Claude is told after a compaction: it is now the current status, not the one from the start of the session
  • Fixed synced plugin MCP servers not connecting when a remote session resumes
  • Fixed resumed headless sessions losing a turn's replies when the model was switched or a request was retried mid-turn
  • Fixed terminal escape codes, line breaks and oversized text from a background task's on-disk record reaching the task list and task notifications when work is resumed
  • Fixed CMYK JPEG images failing to attach with "cannot decode"; they are now converted and resized like other JPEGs
  • Fixed the managed settings approval dialog not naming the collector for a gRPC telemetry endpoint set without a scheme
  • Fixed plugin headersHelper consent prompts showing a URL path that could be misread as a different host
  • Fixed plugin errors showing [redacted URL] in place of a relative Windows path with a folder name that starts with @&#8203;
  • Fixed missing cursor in the permission-rule, auto-mode-rule, add-directory, session-rename and feedback-review text fields when the terminal's native cursor is enabled
  • Fixed repeated clicks on a /fork receipt, each under a second apart, never backgrounding the session right away while it waited for the current tool to finish
  • Fixed plugin LSP servers that reject shutdown params (e.g. rust-analyzer) being left running at session end; exit is now sent even if shutdown fails
  • Fixed the attribution reminder overriding a CLAUDE.md or memory rule against commit and pull request attribution; lines set by managed settings still apply
  • Fixed prompt suggestions being dropped for text in Japanese, Chinese, Thai and other languages written without spaces between words
  • Fixed synchronized output being assumed from the terminal's name in GNOME Terminal and Konsole versions that do not support it
  • Fixed permission_denials in --output-format stream-json results omitting Read, Edit and Write calls blocked by a path-scoped deny rule
  • Fixed sessions run through the SDK or the desktop app showing an unknown status in other sessions' agent list
  • Fixed /insights failing on Bedrock, Vertex, Foundry, and gateway deployments whose account can't reach the default Opus model by using the session model there instead
  • Fixed organization policy limits not loading for the session when another Claude Code process refreshed the login at the same moment
  • Fixed Claude Desktop sessions using Bedrock, Vertex, or a gateway not getting the contextual "what Claude needs" turn-end notification text
  • Fixed MCP servers reconnecting when an updated config only changed the order of the server URL's query parameters
  • Fixed the prompt box's top border splitting into extra lines when viewing a background agent whose name or description has line breaks or is wider than the terminal
  • Fixed sessions getting permanently stuck on "Prompt is too long" when auto-compaction had no complete earlier exchange to summarize (mostly Agent SDK sessions with very large prompts)
  • Fixed /goal runs silently stalling after API errors, network drops, or token limits: the goal now retries with backoff, or pauses and says why, including until a usage limit resets
  • Fixed prompt cache misses in cloud sessions by waiting briefly for server configuration before the first request
  • Fixed /btw answers that contained made-up tool calls and output: the side question is now told not to write them, and any that appear are flagged as not executed
  • Fixed CLAUDE_CODE_RESUME_INTERRUPTED_TURN re-running a turn that had failed with an API error over 6 hours earlier, or longer ago than CLAUDE_CODE_RESUME_INTERRUPTED_TURN_MAX_AGE_MS when set
  • Fixed organization plugins enabled through managed settings not loading in headless sessions and on Claude Desktop (once Desktop bundles this CLI version); they load from the next session
  • Fixed plugin archives extracted for a session being readable by other local users, extracted files keeping world-writable bits from the archive, and stale files surviving re-extraction
  • Fixed Edit() deny rules and the write-path check not applying to the file a Bash tee command writes; a Bash(tee:*) allow rule no longer covers destinations outside the working directories
  • Fixed stray characters like 22c, or a terminal's color or version reply, being typed into the prompt at startup over slow connections (ssh, browser terminals)
  • Fixed the terminal's block cursor showing under the interface in rxvt-unicode after leaving or re-entering fullscreen
  • Fixed the cursor block staying visible after returning from an external editor in fullscreen mode on rxvt-unicode
  • Fixed the interface being drawn twice after returning from an external editor (Ctrl+G) outside fullscreen mode
  • Fixed the interface being drawn twice in Konsole after returning from an external editor
  • Windows: Fixed PowerShell tool commands sent to the background stopping when Claude Code exits
  • Improved the /diff panel to open fully rendered in one step instead of showing a loading state first
  • Improved prompt suggestion filtering for Japanese, Chinese and Korean text: mixed-script and single-word suggestions are kept, and meta or evaluative text is dropped as it is for English
  • Improved the Skill tool's "Unknown skill" error to name the plugin skill's full name when a bare name matches exactly one plugin skill
  • Improved keyboard support over SSH and in unrecognized terminals: terminals that answer the kitty keyboard query (such as foot and Alacritty 0.16+) now get Shift+Enter and Ctrl+Shift shortcuts
  • Improved responsiveness in long sessions: transcript updates no longer re-process the whole conversation to build the collapsed tool-use summaries
  • Improved first-party sessions with telemetry disabled: an alwaysLoad MCP server that finishes connecting mid-conversation is usable on the next turn without a tool-search round trip
  • Changed /ultrareview --post to post the PR comment directly when the findings arrive and print the comment link, instead of starting a second cloud session to post it
  • Changed artifact database reads that save into the session scratchpad so they no longer stop for working-folder approval
  • Changed skills synced from claude.ai in cloud sessions to be named anthropic-skills:<name>, matching Claude Desktop; the bare name still works when nothing else uses it
  • [VSCode] Added an agent map: an "N agents" footer pill opens a map of the session's sub-agents with per-agent cards, Stop agent, and read-only transcripts
  • [VSCode] Added a Hooks dialog to the command menu for viewing hooks and adding, editing, or removing them in user, project, and local settings; managed, plugin, and session hooks stay read-only
  • [VSCode] Added live progress rows for running subagents under the tool-call groups in Focus view
  • [VSCode] Added a Permission rules dialog that lists permission rules and adds or removes them in user, project, and local settings; startup-option, session-only, and managed rules stay read-only
  • [VSCode] Added a Cancel button to the Switch account screen that returns to your session as the current account
  • [VSCode] Fixed Focus view showing a turn started by a delivered plain-text prompt, such as a scheduled task's, as part of the previous turn
  • [VSCode] Fixed the footer's prompt cache clock hiding its minutes when the panel is narrow
  • [VSCode] Fixed the session list keeping sessions from the default folder when CLAUDE_CONFIG_DIR is set in a settings file or the environmentVariables setting
  • [VSCode] Fixed a plan preview that finished loading late sometimes hiding its comment box or showing an older plan
  • [VSCode] Fixed a plan preview accepting comments that went nowhere after its Claude tab closed
  • [VSCode] Fixed the prompt cache clock and reopen notice for a session compacted after its last reply and then closed, which now reads as cold when reopened
  • [VSCode] Fixed a session renamed in the extension while Remote Control is on keeping its old name on claude.ai/code
  • [VSCode] Fixed the "Enable Remote Control for all sessions" toggle keeping its last position after the setting was reset to default from a terminal
  • [VSCode] Fixed restored Claude tabs not counting as open in the session list after a window reload until clicked, and their row opening a second tab
  • [VSCode] Fixed Switch account making a tab forget its dismissed usage-limit warnings when you sign back in as the same account
  • [VSCode] Fixed a session rename being replaced by the generated name after a window reload when the session was renamed during a long turn
  • [VSCode] Fixed the sidebar usage meter keeping a stale per-model weekly limit row after the account loses that limit
  • [VSCode] Fixed a rare case where an @​-mention sent with the keyboard shortcut while a new chat view was still starting could be inserted into the input long after the keystroke
  • [VSCode] Fixed the session list jumping down when the Account & usage header appeared a moment after opening the Claude side bar
  • [VSCode] Improved documents and messages written for someone other than the user: Claude now writes them for that audience and names it at the top of its reply
  • [VSCode] Improved screen reader and keyboard accessibility in the slash-command menu, @​-mention menu, output-style picker, Send/Stop button, permission and question cards, and onboarding checklist
  • [VSCode] Changed the current-file chip in the message box: an X now removes it, replacing the Hide toggle
  • [VSCode] Removed the Claude Code items from a session tab's right-click menu and the editor title bar's "..." menu; they could not act on the tab the menu was opened on
  • [Claude Code on the web] Added taking back a queued message in a cloud session before Claude reads it: remove it from the queue, or press Esc or Up, and the text returns to the message box
  • [Claude Code on the web] Fixed /model default in a cloud session leaving every later message failing in organizations that restrict which models Claude Code can use
  • [Claude Code on the web] Fixed one-off scheduled routines occasionally running a second time after a transient server error
  • [Claude Code on the web] Fixed routine runs that use subagents sometimes being treated as finished too early, which could skip the retry after a real failure or start a duplicate run
  • [Claude Code on the web] Fixed file links in cloud session transcripts opening a GitHub 404 when Claude was working from a subfolder of the repository
  • [Claude Code on the web] Changed the Cloud environments admin page to list every environment instead of capping each table at five rows behind a Show more control that could be unreachable
  • [Claude Code on the web] Changed claude.ai/code for Free-plan users to open the plans page with a path to upgrade, instead of a "Disabled by org admin" page with no way forward
  • [Claude Tag] Added a confirmation dialog before Connect all or Disconnect on a GitHub installation in admin settings, to guard against accidental organization-wide changes
  • [Claude Tag] Fixed threads occasionally going silent after a failed turn because the failure notice was dropped when Slack briefly rate-limited it; the notice is now retried
  • [Claude Tag] Fixed Claude accepting a switch to a model your organization hasn't enabled and then quietly answering with a fallback model; it now declines and says an admin can enable it
  • [Claude Tag] Fixed a table posting as raw pipe text when Claude attached files to the same message; the table now posts as a normal reply and the files follow with a plain caption
  • [Claude Tag] Fixed @&#8203;Claude !restart at the top level of a channel where Claude isn't active starting an unrelated conversation; it now privately says there is nothing to restart
  • [Claude Tag] Fixed plugin rows in Slack access settings showing an unlabeled raw ID with no way to turn the plugin off; they now show its name and link to the bundle that manages it
  • [Claude Tag] Fixed the shared-session banner and Share dialog on sessions started from Slack claiming the whole organization could open the link; they now name the Slack channel's audience
  • [Claude Tag] Improved load time of the admin settings page and its Slack channel picker, most noticeably for organizations with many channels or several connected workspaces
  • [Claude Tag] Improved scheduled routines in Slack channels: a routine run can now reply in an existing thread instead of always posting a new top-level channel message
  • [Claude Tag] Improved the timestamp on Claude's live progress checklists to show each reader's local time and how long ago it was updated, instead of a fixed UTC time

v2.1.268: v2.1.268

Compare Source

What's changed

  • Added to the Claude apps gateway: with pricing: set in gateway.yaml, signed-in Claude Code clients receive the same rates through managed settings, so /cost and telemetry match the spend meter
  • Added a startup warning for gateways when access_control.allow_cidrs is empty, and a one-time warning the first time a request arrives from a public address
  • Added the gatewayInternalNetworks managed setting, letting administrators allow /login to a Claude apps gateway on their organization's own public IPv4 block
  • Added claude self-hosted-runner --remove-session-state (default off): delete each session's per-session directories under <base-dir>/_sessions/ when the session ends
  • Added configDirectory to the output of claude auth status --json
  • Added --json to claude plugin install, uninstall, update, enable and disable, and errorDetails/noteDetails to each row of claude plugin list --json
  • Added browser-tab icons for published artifacts, chosen by Claude to match each page
  • Fixed every turn failing with HTTP 400 on third-party Anthropic-compatible endpoints (ANTHROPIC_BASE_URL) since 2.1.265: a regex in the Artifact tool's input schema that those endpoints reject
  • Fixed WebFetch hanging indefinitely on a server that keeps the response open without finishing; a fetch now fails after 300 seconds. Set CLAUDE_CODE_WEBFETCH_DEADLINE_MS to override the deadline (0 turns it off)
  • Fixed a respawned in-process teammate picking up tools or a system prompt from a same-named agent file in a folder you have not trusted
  • Fixed sustained high CPU usage: a busy loop in long-running idle sessions no longer pins a CPU core, and rapid terminal focus reports during a session recap no longer keep the CPU high
  • Fixed Claude sometimes replying "your message came through empty" after an MCP tool call
  • Fixed deny and ask permission rules on symlinked directories (/etc, /tmp, /var on macOS; /bin on Linux) not applying when a path was given by its real location, and Bash commands ignoring deny rules written on a symlinked path spelling
  • Fixed a case where a Read or Edit deny rule did not apply when an env -C, eval or similar command the permission checker cannot analyze was on the same line
  • Fixed plugin and marketplace errors showing a token or password from a git source URL
  • Fixed /mcp and /plugin server details, claude mcp list/get, and MCP login errors showing secrets resolved from ${VAR} placeholders in MCP configs
  • Fixed prompt caching and extended thinking breaking mid-session for SDK sessions using excludeDynamicSections: the first message is no longer re-rendered each request
  • Fixed entitled users being told a model is restricted after restart or in the Desktop Code tab when a cached model-access denial was stale
  • Fixed a running session silently switching to the organization's default model when another Claude Code process refreshed a stale model-access entry
  • Fixed long-context 429s on Fable models showing the usage-credits consent prompt instead of the 1M-context message on Pro and Team plans
  • Fixed workload identity federation via a profile (as claude-code-action configures it): processes sharing the profile could fail mid-run with 401 … jti reused
  • Fixed MCP server OAuth sign-in failing with "No available ports for OAuth redirect" when the local callback port range can't be bound
  • Fixed the conversation summary produced by /compact and auto-compact mangling text that contained $ sequences
  • Fixed resuming a conversation that ended with /compact: its restored-file notes now load in the same order on every resume
  • Fixed SDK prompt suggestions, side questions and /rename sending the conversation from before a compaction
  • Fixed @&#8203; file and / command suggestions not appearing after recalling a previous prompt with the up arrow and editing it
  • Fixed claude agents: pressing ← again at a natural pace to go back to the agent list no longer gets ignored until you pause for over a second
  • Fixed claude agents session delete getting stuck when a worktree can't be removed: the message names the cause and next step, and for a git worktree ctrl+x again deletes the directory anyway
  • Fixed background agent and workflow rows in the agents panel expanding to many lines when their text contained line breaks
  • Fixed Claude in Slack sessions losing their Slack tools when org managed settings set an MCP allowlist
  • Fixed Claude in Chrome asking to allow the host "https" when a navigation URL had a scheme but a host that could not be parsed
  • Fixed the spinner wrapping onto several lines when the current task's label is long; the label and the "Next:" task line now stay within one terminal row
  • Fixed the /bug and /feedback description field showing no cursor when the terminal's native cursor is enabled
  • Fixed Remote Control sessions served by claude remote-control showing a generated name instead of their session title in ListAgents
  • Fixed claude plugin validate rejecting plugin paths whose directory name begins with two dots, which the plugin loader accepts
  • Fixed plugins silently skipping a default monitors file or root SKILL.md that could not be checked
  • Fixed WebFetch's error for localhost and other dotless hostnames to explain why the URL is refused and suggest curl
  • Fixed PermissionRequest hooks not firing in --print mode
  • Fixed policy-helper warnings not printing on headless (-p) runs
  • Fixed /resume listing a /fork background session under its parent's name instead of its own fork name
  • Fixed /remote-control and other claude.ai-gated commands to suggest /login when signed out instead of showing a Claude for Enterprise migration message
  • Fixed CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS not extending SessionEnd hooks that have no per-hook timeout (they were still cancelled after 1.5 seconds)
  • Fixed /autofix-pr and other cloud-session commands saying to retry or install the Claude GitHub App when no GitHub account is connected; they now point to /web-setup or the web connect page
  • Fixed cloud-session commands such as /teleport and /remote-env to explain when an organization policy turns them off, instead of answering "Unknown command"
  • Fixed Bash sandbox instructions over-stating confinement: no unenforced path lists when filesystem isolation is off, and strict mode no longer claims commands can never run unsandboxed
  • Improved fullscreen mode: adding or removing a prompt line (Shift+Enter) now repaints as fast as typing a character instead of re-rendering the visible transcript
  • Improved --continue / --resume: the conversation appears immediately instead of waiting for SessionStart hooks, and the first message no longer re-reads the whole transcript
  • Improved responsiveness during tool-heavy turns by no longer redrawing the transcript for a hidden per-tool-batch reminder
  • Improved startup time in projects with .claude/workflows/ scripts: listing them no longer parses each script
  • Improved auto mode denials: the message Claude receives now names the rule that blocked the action and asks Claude to try a safer method and finish unrelated work before stopping to ask you
  • Improved Claude in Chrome: long page reads now stay inline instead of being saved to a file and read back
  • Improved the MEMORY.md truncation warning to say how many lines were cut and where the cut starts
  • Improved the terminal permission prompt for artifacts: it now leads with the ask's question
  • Improved the prompt footer: an editor or /diff selection now shows inside the prompt input, and fullscreen mode shows Remote Control status in the header instead of the footer
  • Improved the "Usage credits required for 1M context" message to say that usage credits turned on mid-session take effect after restarting Claude Code
  • Improved /plugin: installing, enabling or disabling a plugin now takes effect when you close the menu; /reload-plugins is no longer needed afterwards
  • Changed the system prompt on Bedrock, Vertex and Foundry to deliver environment, model and settings details as attachments, matching first-party sessions
  • Changed Bedrock, Vertex and Foundry sessions to keep the tool list byte-stable across a conversation (late-connecting tools load deferred instead of rewriting it), matching first-party sessions
  • Changed the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) to be offered only on Claude 3.x, Opus 4.0–4.7, Sonnet 4.0–4.6, Haiku 4.5; set CLAUDE_CODE_ENABLE_TODO_TOOLS=1 elsewhere
  • Changed the artifact data-edit permission prompt in the terminal to a card that shows the document count and who can open the artifact
  • Changed local Cowork sessions set to skip all approvals: the Artifact tool now refuses a local file outside the session's folders, or behind a symlink, instead of reading it without asking
  • Changed plain WebFetch deny and ask rules to no longer apply to Artifact tool reads and updates; use an Artifact rule (or WebFetch(domain:claude.ai)) to block or gate them
  • Changed the "N MCP servers need authentication" startup notice to announce each server once instead of at every launch
  • [VSCode] Fixed the session list, settings toggles, and chat tabs when CLAUDE_CONFIG_DIR is set in a settings file or the environmentVariables setting
  • [VSCode] Fixed the model pill, model picker and command menu going blank in open tabs for a few seconds after a login, logout or account switch
  • [VSCode] Fixed Auto disappearing from the mode picker in new-tab or just-reloaded conversations when a project or local setting overrides the model named in ~/.claude/settings.json
  • [VSCode] Fixed session names reverting to the last prompt after a window reload when a SessionStart hook is configured
  • [VSCode] Fixed the footer's model pill and Remote Control pill waiting for the new tab's Claude process to start when another tab in the window is already up
  • [VSCode] Fixed a second Claude process running through its full startup when a session tab's launch arrived more than half a second after its config read
  • [VSCode] Fixed resuming a session from the session list ignoring claudeCode.preferredLocation: "sidebar" (it always opened a panel), and programmatic opens resetting that setting to "panel"
  • [VSCode] Fixed Windows issues: the WSL install prompt no longer appears on machines without WSL installed, and IDE diagnostics are now returned correctly for Windows files when WSL is installed
  • [VSCode] Fixed the custom style builder saving a User level style in a folder the CLI does not read when CLAUDE_CONFIG_DIR is set through settings
  • [VSCode] Added Left and Right arrow keys to change where an always-allow permission rule is saved, for keyboard and screen reader users
  • [VSCode] Added a "Claude Code: Focus last message" command that moves keyboard focus to the newest message in the conversation, for keyboard and screen reader users
  • [VSCode] Changed the Manage plugins dialog to apply installs, enables, disables and uninstalls to open sessions without a restart
  • [VSCode] Changed some artifact permission prompts to omit the "don't ask again" choice, matching the terminal
  • [Claude Code on the web] Fixed cloud sessions running longer than about six hours silently losing files saved to persisted session folders; saves now persist for up to a day
  • [Claude Code on the web] Fixed "Invalid effort level" errors when a routine resumes a session, or a session starts with no set effort, in orgs where an admin caps a model's effort
  • [Claude Code on the web] Improved routine creation from a conversation: when the new routine has no connectors, Claude now says so and how to add them instead of only confirming it
  • [Claude Tag] Fixed the admin settings page hanging on a loading skeleton or going blank after a transient load failure; a section that fails to load now shows a Retry button
  • [Claude Tag] Added a link from a Slack channel's configure page back to the organization's Claude in Slack admin settings
  • [Claude Tag] Fixed a Slack Enterprise Grid channel losing its Claude settings (repository, environment, access) after a Slack admin moved it to another workspace
  • [Claude Tag] Improved how Claude explains a blocked action: it now says whether a permission check, its own decision to confirm first, or missing access stopped it
  • [Claude Tag] Improved reply speed: Claude now runs several read-only lookups (searching Slack, reading a thread, finding people) at once instead of one after another
  • [Claude Tag] Improved formatting of comparisons: sentence-length comparisons now come as lists instead of wide tables that scroll sideways, and long table cells wrap
  • [Claude Tag] Fixed @&#8203;Claude !restart in a thread with its own session sometimes also posting a contradictory "this thread is handled by the channel session" notice
  • [Claude Tag] Improved the message shown when your Claude account is in a different organization than the Slack workspace: it now explains how to connect the workspace to your org
  • [Claude Tag] Fixed Markdown links whose URL is wrapped in angle brackets showing as literal bracket text in Slack instead of a clickable link
  • [Claude Tag] Fixed a workspace guest's top-level @​mention in a channel where guests may use Claude sometimes getting a "your Slack account isn't connected" reply instead of an answer
  • [Claude Tag] Fixed a channel's long-running session being replaced with a fresh one mid-conversation; the scheduled refresh now waits until the channel and its threads are quiet
  • [Claude Tag] Fixed channel-settings cards clicked more than once telling the proposing session the change was refused after it had already applied; the outcome is now sent once
  • [Claude Tag] Changed memory in public channels: each channel now keeps its own notes, and Claude no longer recalls notes it saved in other public channels; workspace notes stay shared
  • [Code Review] Added a note under the still-open findings list in follow-up reviews: resolving a finding's thread, not just replying to it, stops later reviews from counting it as open
  • [Code Review] Fixed reviews sometimes ending as incomplete when one of the agents verifying a finding failed midway; the review now replaces that agent and reaches a verdict
  • [Code Review] Fixed a push-triggered review that was queued behind a running review still posting after the pull request had been converted to draft
  • [Code Review] Fixed reviews ignoring a directory's CLAUDE.md conventions when the PR edited a root file (e.g. README.md) that only shares a name with a file that CLAUDE.md lists

v2.1.267: v2.1.267

Compare Source

What's changed

  • Added maxEffortLevel setting (top-level or per model under modelSettings): caps the effort level on every provider, including Bedrock, Vertex and Foundry; users can still pick a lower level
  • Added --system-prompt-snapshot off to render the system prompt fresh on every request instead of reusing the conversation's recorded prompt (for iterating on prompt text)
  • Fixed Cowork scheduled tasks in the cloud failing at startup for organizations whose managed settings require sandboxing
  • Fixed /context and other local command output rendering blank on mobile clients
  • Fixed shift+enter and option+backspace not working after reconnecting to a tmux or ssh session inside an agent view
  • Fixed the dim last-prompt header not appearing at the top of the conversation when scrolling up in fullscreen mode
  • Fixed Workflow agent() calls with large output schemas being refused in auto mode instead of being checked by the safety classifier
  • Fixed a case where a marketplace entry path containing a backslash could bypass the containment check for fetched marketplaces on macOS and Linux
  • Fixed expired AWS or Google Cloud credentials under a host app such as Claude Desktop retrying ten times with a generic "request failed" before the re-authenticate error appeared
  • Fixed resuming a session after /compact or another slash command ran via -p --resume: a spurious "Continue from where you left off." turn is no longer inserted
  • Fixed resuming a large session (transcript over 5 MB): parallel tool calls and their hook output are no longer dropped from the reloaded conversation
  • Fixed managed allowedHttpHookUrls, httpHookAllowedEnvVars and allowedChannelPlugins to admit nothing, not everything, when unreadable
  • Fixed /login on machines whose managed settings require Claude apps gateway sign-in: Esc now closes the dialog instead of doing nothing
  • Fixed artifact publishes cut off by a dropped connection mid-upload: they now retry once when Claude Code can tell the upload never completed, instead of reporting an unknown outcome
  • Fixed effort: frontmatter on custom commands, skills, and subagents being ignored on models whose default effort is still pinned (Opus 4.7, Opus 4.8, Fable 5)
  • Fixed artifact publish failing with an unhelpful error when the page file isn't valid UTF-8 or contains a replacement character (U+FFFD); the error now names the line and column to fix
  • Fixed claude agents @&#8203; directory menu not listing repositories created after the session started
  • Fixed Remote Control clients that join a Claude Desktop or VS Code session showing a stale permission mode until it was changed again
  • Fixed claude remote-control exiting and dropping every attached session when its server credential expires (about 30 days after start); the host now re-registers and keeps going
  • Fixed the usage-limit warning flickering on and off during a session when requests for different models or modes report different limit windows
  • Fixed earlier reasoning being dropped when an MCP server re-sends, or a built-in tool re-renders, a tool the model already loaded
  • Fixed a tool that disappears mid-conversation, from a disconnected MCP server or an upgrade, rewriting the tool list and discarding earlier thinking
  • Fixed a background worker forked from a conversation adding EnterWorktree to the conversation's tool block mid-session, which broke prompt-cache reuse
  • Fixed mid-session MCP and plugin tools being added to the tool list in sessions without ToolSearch, which broke prompt-cache reuse; supported models now receive them as deferred definitions
  • Fixed switching models with /model re-sending every tool definition (a prompt-cache miss); commit and PR attribution text now arrives as a conversation note that updates on model changes
  • Fixed resumed sessions rewriting the inline tool set when an MCP connector reconnects at a different moment than before
  • Fixed resumed sessions re-rendering tool descriptions instead of replaying the recorded ones when the first turn ran a tool
  • Fixed prompt-cache misses and dropped extended thinking when a claude.ai connector's tools change between a session and its resume
  • Fixed resumed sessions rewriting earlier MCP tool announcements (and dropping extended thinking) before their connectors reconnect
  • Fixed a prompt-cache break when a print-mode (-p) conversation is resumed interactively: the system prompt prefix no longer changes
  • Improved the /diff panel: it no longer flashes "0 files changed" and a spinner before settling, and its empty state is centered in the panel
  • Improved the Bash tool's description guidance so Claude describes what a command does in plain words instead of echoing the command
  • Improved sandbox guidance so Claude suggests /copy when clipboard commands such as pbcopy fail inside the sandbox
  • Improved --resume first-render time for sessions with many Bash tool calls
  • Improved prompt input responsiveness: keystrokes no longer occasionally wait a frame behind spinner or streaming repaints
  • Improved prompt-cache stability: subagents and sessions started with --system-prompt or --append-system-prompt now record the system prompt and tool definitions once instead of re-rendering them
  • Improved Artifact tool publish errors: when a publish is refused, the message now says why and what to do about it
  • Self-hosted runner: Changed --use-anthropic-git-proxy to be reported to the server at registration and to print a warning for each session that still clones through the legacy git proxy
  • Gateway: Changed forward_user_identity upstreams to return a 429 as-is to a developer whose email was forwarded, instead of failing over to the next upstream, so the proxy's per-user limits hold
  • [VSCode] Fixed the extension host hanging at 100% CPU when forking, editing an earlier message, or rewinding in a conversation whose saved transcript contains a cyclic parent link
  • [VSCode] Fixed pasting a screenshot on WSL2/WSLg inserting raw image bytes into the chat input; the image is now attached when the clipboard provides it, otherwise the paste is ignored
  • [VSCode] Fixed chat diff blocks always rendering with a dark editor theme; they now follow the active VS Code color theme, including high contrast
  • [VSCode] Fixed mixed right-to-left and English text rendering in the wrong order while typing in the message input
  • [VSCode] Fixed accepting an edit in the diff view on a file with Windows (CRLF) line endings failing with "String not found in file"
  • [VSCode] Fixed @​-mentions dropping files whose paths contain spaces
  • [VSCode] Fixed the sessions list view failing to load in windows connected over Remote-SSH when the workspace folder exists only on the remote host
  • [VSCode] Fixed runaway ripgrep processes when viewing files in large or symlink-heavy workspaces
  • [Claude Code on the web] Fixed GitHub Enterprise Server sessions showing your GitHub account as disconnected once its token expired; PR and issue operations now refresh it automatically
  • [Claude Code on the web] Fixed gh and GitHub API calls failing in organizations without the Claude GitHub App; they now use your connected GitHub account and say so when none is connected
  • [Claude Tag] Added a "Use a custom connector" link to the preset connection forms in Claude Tag admin settings, so you can switch to a custom connection without starting over
  • [Claude Tag] Fixed Claude replying "The API rejected the request as invalid" when the organization has run out of usage credits; the reply now says so and explains how to add more
  • [Claude Tag] Fixed thread requests to edit or delete a message Claude posted at the channel's top level being answered with a correction instead of reaching the session that posted it
  • [Claude Tag] Fixed Connect on Tool access requests under Admin settings > Review requests failing with "Authorization failed" or showing the requested access bundle as deleted

@scottames-github-bot

scottames-github-bot Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor
backnotprop/plannotator (github:backnotprop/plannotator)

v0.27.14: v0.27.14

Compare Source

Follow @​plannotator on X for updates

Missed recent releases?

Release Highlights
v0.27.13 Open a review on a specific base (--base, --diff-type), symlink containment on /api/doc, CI flake fix, Amp decision relay
v0.27.12 Unified decision control, token hover cards, local-vs-remote diff, approval notes
v0.27.11 OpenCode server leak fix, durable local feedback archive, unknown-subcommand fix
v0.27.10 Auto-viewed files on scroll, annotation undo/redo, OpenCode 2 slash commands restored, npm 12 agent terminal fix
v0.27.9 WebMCP browser-agent tools, HTML refresh from disk, host seams, lazy renderers, Windows uninstall fix
v0.27.8 Pi keeps its prompt cache across plan transitions, thumbs-up returns to HTML annotation, embed picker seam
v0.27.7 Pi host crash fix on Windows, Call Flow tree cap, jj fork-point base, plannotator knowledge skill + llms.txt
v0.27.6 Live app annotation lands on Pi, one interaction model for HTML pages
v0.27.5 Annotate your running app, Agent TUI placement, collapsed lockfiles, VS Code theme fix
v0.27.4 Portable Guided Review exports, guides.show share links, guide CLI, jj Call Flow
v0.27.3 Folder watcher freeze fix on large repos, first SBOM-attested release pipeline
v0.27.2 Mobile plan and code review, Codex CLI 0.147 fix, configurable markdown extensions

What's New in v0.27.14

A community release. Eleven pull requests, nine of them from contributors, and one first-time contributor who arrived with two Pi fixes. Six of the changes close issues people filed. The theme is the long tail: Pi plans that lose their progress, Codex threads split across files, a browser setting that silently did nothing under WSL, a toolbar that grew off the bottom of the screen. Each one was reported by someone who hit it, and each one is fixed.

Pi: plan progress survives compaction and session forks

On Pi, the approved plan's progress widget tracked [DONE:n] markers in memory only. After a context compaction, a session fork, or a restart, the counter reset to 0/N and the checkboxes in the plan file were never written back, so a half-finished plan looked untouched.

Completion state is now persisted into the approved plan's markdown itself. A new plannotator_mark_done tool lets the agent mark each step as it finishes, the checkbox flips in the file immediately, and a restored session reads its progress back from the plan instead of starting over. Older in-progress executions are recovered on restore by writing their markers back into the plan. The tool is scoped to the executing phase and refuses to run outside it, and the tool set changes only at phase entry, so Pi's prompt cache is untouched.

#1496 by @​a4180p, closing #1376 reported by @​huangxinsteam-oss, with @​michaelmior confirming the same failure.

Pi: Ask AI renders completed messages and reports errors

Ask AI on Pi built its response from streamed text_delta events. A Pi provider that did not emit usable deltas produced an empty answer, and a failed request, such as an upstream 429, ended as a successful empty response with no indication anything went wrong.

The provider now maps text blocks from Pi's message_end event, which Pi documents as the authoritative completed message, and forwards a failed request's error message to the UI. Normal delta streaming still takes precedence, so nothing is rendered twice.

#1495 by @​a4180p.

Codex: annotate-last works when a thread spans several rollout files

One Codex thread can be written across several rollout JSONL files. plannotator last picked the first file whose name matched the thread id, from an unsorted directory listing, which could be an empty or aborted segment. The command then failed with "No rendered assistant message found" while the message sat in a sibling file.

Every rollout for the thread is now considered, newest first, and annotate-last uses the first one that actually contains a rendered assistant message. The Stop hook's plan detection takes the newest existing rollout for the current session and deliberately does not fall back across segments, so an older segment can never resurrect a stale plan. Single-file threads behave exactly as before. The fix was verified against the Codex CLI with a synthetic multi-segment session home.

#1493 by @​FNDEVVE, closing #1367 reported by @​arklanq-patronus.

PLANNOTATOR_BROWSER works under WSL, and says so when it fails

Under WSL, PLANNOTATOR_BROWSER was always routed through cmd.exe /c start, so a Linux path or script could never launch. The failure was swallowed, and a headless session reported success while the reviewer never saw a window.

Both runtimes now classify the configured value first. Windows targets (chrome.exe, C:\..., /mnt/c/...) keep the cmd.exe route; POSIX paths and bare names that resolve on the Linux PATH are executed directly. When an explicitly configured browser fails to launch, one line on stderr names the executable and the error before the usual fallback prints the URL. The Pi runtime now reports opened: false on spawn errors instead of claiming success. macOS and non-WSL Linux behavior is unchanged.

#1494 by @​FNDEVVE, closing #1472 reported by @​Pallieter.

Code review: the annotation toolbar stays on screen when suggested code expands

Selecting lines near the bottom of a diff and expanding Add suggested code pushed the submit row past the bottom edge. The toolbar's vertical clamp reserved a fixed 200 pixels while its maximum height was the whole viewport, so internal scrolling never engaged and the toolbar simply grew off screen. Ask AI mode had the same problem.

The toolbar now measures its real height after every change and keeps the whole box inside the visible area: an anchored toolbar flips above its anchor when it would not fit below, a toolbar taller than the viewport pins to the top with a bounded height so it scrolls internally, and a dragged toolbar keeps its position but clamps into bounds.

#1491 by @​FNDEVVE, closing #1424 reported by @​tekumara.

Mod+E enters and leaves Edit Mode in place

Plan review and annotate had an Edit button but no keyboard route into markdown Edit Mode. Mod+E now toggles it: entering keeps your scroll position and drafts, and pressing it again commits your edits and returns you to the same place in the rendered document. The chord is ignored while you are typing in an input, a text area, or a comment composer, so it cannot steal a keystroke. It is listed in the in-app shortcut help and on the docs page.

#1492 by @​FNDEVVE, closing #1479 requested by @​ogizanagi.

JJ: line-of-work bases stay put

On Jujutsu repos, the automatic "line of work" base could move under a review. A moving remote bookmark or an ambiguous fork-point revset could pull unrelated changes into the diff, or label a current-change diff as line of work. The base is now resolved once to an immutable commit id, ambiguous or unavailable fork points are reported instead of guessed, and the fallback to the current change keeps your line-of-work preference for the next switch. Detected fork points are exposed for explicit selection, the base label shows a short commit id instead of a 40-character hash, and the Bun and Pi servers stay aligned.

#1497 by @​graemefolk.

Additional Changes

  • Skill autocomplete menu no longer clips: typing / or $ in the annotate comment composer opened the skill menu inside the composer card, whose scroll container clipped every row past the card edge. The composer now allows visible overflow only while the menu is open and restores its scrolling when it closes. #1488 by @​leoreisdias
  • Data directory resolved per call: four modules captured PLANNOTATOR_DATA_DIR at import time and froze every derived path, so a data directory set after import was ignored, and the Codex, Tour, and Guide review schemas could stay stale across versions. All of them now resolve on each call, and the schema files are rewritten once per process so a version upgrade never reads an older schema. #1490 by @​FNDEVVE, closing #1477 filed by @​bendrucker
  • Dependency refresh: 33 minor and patch updates across the workspace, including @&#8203;pierre/diffs 1.3.6. Three packages are held back on purpose and now excluded from Dependabot. The Bun runtime stays pinned at 1.3.14. #1501
  • Commit-rail switches keep the base picker: a regression introduced on main after v0.27.13 and caught by the pre-release QA gate before it shipped. #1508

Install / Update

macOS / Linux:

curl -fsSL https://plannotator.ai/install.sh | bash

Windows:

irm https://plannotator.ai/install.ps1 | iex

Claude Code Plugin: Run /plugin in Claude Code, find plannotator, and click "Update now".

Pi: Update @&#8203;plannotator/pi-extension to 0.27.14 and restart Pi.

OpenCode: Clear cache and restart:

rm -rf ~/.bun/install/cache/@&#8203;plannotator

What's Changed

  • fix(pi): persist approved plan checklist progress by @​a4180p in #1496
  • fix(pi): render completed messages and errors by @​a4180p in #1495
  • fix(codex): fall back across rollout files for annotate-last and the Stop hook by @​FNDEVVE in #1493
  • fix(browser): honor POSIX PLANNOTATOR_BROWSER under WSL and warn on launch failure by @​FNDEVVE in #1494
  • fix(review): keep the annotation toolbar inside the viewport when suggested code expands by @​FNDEVVE in #1491
  • feat(editor): Mod+E shortcut to enter and leave Edit mode in place by @​FNDEVVE in #1492
  • fix(shared): resolve data-dir paths per call instead of capturing at import by @​FNDEVVE in #1490
  • fix(review): stabilize JJ line-of-work bases by @​graemefolk in #1497
  • fix(ui): prevent skill autocomplete menu clipping by @​leoreisdias in #1488
  • chore(deps): bun minor+patch group in #1501
  • fix(review): stop echoing the launch-frozen git context on commit switches in #1508

New Contributors

  • @​a4180p made their first contribution in #1495

Contributors

@​FNDEVVE carried this release: five merged pull requests in a week, three of them closing issues other people filed, each with a stash-the-fix control proving the new tests fail on the old code. @​a4180p arrived with two Pi fixes at once, and the checklist persistence one closes a bug that had cost people real plan progress. @​graemefolk kept pushing on Jujutsu support and made the line-of-work base honest about what it can and cannot resolve. @​leoreisdias fixed the skill menu clipping with a DOM regression test that names the clipping ancestor, so the failure cannot come back quietly.

The reports made the fixes possible:

  • @​huangxinsteam-oss reported the Pi progress reset (#1376), and @​michaelmior confirmed it
  • @​arklanq-patronus reported the multi-file Codex thread failure (#1367)
  • @​Pallieter reported the silent PLANNOTATOR_BROWSER failure (#1472)
  • @​tekumara reported the toolbar running off the bottom of the diff (#1424)
  • @​ogizanagi requested the Edit Mode shortcut (#1479)
  • @​bendrucker filed the import-time data directory capture (#1477) after root-causing the CI flake in the last release

Thank you. Plannotator gets better because you tell us where it falls short.

Full Changelog: backnotprop/plannotator@v0.27.13...v0.27.14

v0.27.13: v0.27.13

Compare Source

Follow @​plannotator on X for updates

Missed recent releases?

Release Highlights
v0.27.12 Unified decision control, token hover cards, local-vs-remote diff, approval notes
v0.27.11 OpenCode server leak fix, durable local feedback archive, unknown-subcommand fix
v0.27.10 Auto-viewed files on scroll, annotation undo/redo, OpenCode 2 slash commands restored, npm 12 agent terminal fix
v0.27.9 WebMCP browser-agent tools, HTML refresh from disk, host seams, lazy renderers, Windows uninstall fix
v0.27.8 Pi keeps its prompt cache across plan transitions, thumbs-up returns to HTML annotation, embed picker seam
v0.27.7 Pi host crash fix on Windows, Call Flow tree cap, jj fork-point base, plannotator knowledge skill + llms.txt
v0.27.6 Live app annotation lands on Pi, one interaction model for HTML pages
v0.27.5 Annotate your running app, Agent TUI placement, collapsed lockfiles, VS Code theme fix
v0.27.4 Portable Guided Review exports, guides.show share links, guide CLI, jj Call Flow
v0.27.3 Folder watcher freeze fix on large repos, first SBOM-attested release pipeline
v0.27.2 Mobile plan and code review, Codex CLI 0.147 fix, configurable markdown extensions
v0.27.1 Open-in-editor launch fix, file headers respect Viewed/Git-add visibility toggles

What's New in v0.27.13

Six pull requests, four of them from community contributors, two from first-time contributors. The headline answers a request straight from X: open a code review against the base you actually mean, not always the trunk. Alongside it: a security hardening of the document endpoint, the end of our longest-standing CI flake, and a Amp delivery fix.

Open a review on a specific base

plannotator review always opened against the detected trunk, even when you were reviewing one layer of a stacked branch. A user on X put it plainly: "it always opens vs. main even if it explicitly understands that I'm reviewing a stack."

Now the review can open exactly where you point it:

# stack: main → feature/part-1 → feature/part-2 (you are here)
plannotator review --base feature/part-1
# opens on "All changes since feature/part-1": just what this layer adds

plannotator review --base feature/part-1 --diff-type merge-base
# the committed-only view of the same layer

--base takes anything git resolves: a branch, origin/branch, a tag, a commit, HEAD~3. --diff-type picks the opening view from the same nine modes the dropdown offers. Both are a starting state, nothing more: the session opens there, everything stays changeable in the UI, and neither flag ever touches your saved defaults. A base that does not exist fails at launch with a clear message and a "did you mean" suggestion instead of silently producing a wrong diff.

This matters most when an agent opens the review for you. The agent knows which layer it just built, so it can hand you a review already looking at the right thing instead of telling you which dropdown to click. The installed skills teach exactly that: reviewing a stack layer, pass --base <the branch below yours>.

The flags work across every host that launches reviews through the CLI, and error honestly on surfaces where a base has no meaning (jj, GitButler, Perforce, multi-repo workspaces, and PR URLs, whose base comes from the platform). #1484

One behavior change shipped with this. The review command used to silently ignore flags it did not recognize; a typo like --bse main opened a review as if you had typed nothing, and in the worst case an unknown flag could swallow the PR URL next to it. Unknown dash-prefixed flags now fail loudly with a usage hint, matching how annotate has always behaved. Plain words stay tolerated, so slash-command hosts that forward your raw sentence keep working. OpenCode and Pi slash commands also now reject CLI-only transport flags such as --tailscale that they previously accepted and ignored. #1483

Symlinks can no longer read outside the project

A symlink committed into a repository you are reviewing could point anywhere on your disk, and the endpoint that serves linked documents would follow it: the requested path looked like it was inside the project, but the content came from outside it. Document reads are now gated on real-path containment in both server runtimes: a path must land inside the project both as written and after resolving symlinks, or the request is refused.

Legitimate symlink setups keep working, including symlinked project roots (macOS temp directories) and links that resolve within the project. Three edge behaviors changed on purpose: a symlink escaping the project returns 403 on every path through the endpoint, HTML files over the 2MB annotate cap now return 413 where one path previously served them in full, and a file that exists but cannot be opened returns 500 instead of 404.

Contributed by @​bendrucker in a first contribution that went well beyond its own scope: along the way he reproduced our longest-standing CI flake, disproved our working theory with actual experiments, and traced it to the real root cause below. #1437

The CI flake is dead, and tests stay out of your data

Four annotate-server tests had been failing intermittently on CI for weeks (#1464), passing on rerun, resisting diagnosis. The root cause turned out to be a single line: shared storage captured the data directory once at module import, so a test that imported it under a temporary override poisoned every later test in the process, and test-file discovery order decided who got hit. The same freeze meant a full test run could write into a contributor's real ~/.plannotator.

Storage now resolves its directory per call, and the test suite sandboxes PLANNOTATOR_DATA_DIR for every run, with regression tests locking both halves down. Two contributors converged on the same root cause independently within a day, from different starting points: @​FNDEVVE working from our test-isolation issue, and @​bendrucker debugging his own PR's CI failures. Closes #1455 and #1464. #1473

Amp: feedback is routed by decision, never guessed from prose

The Amp plugin classified review outcomes by searching the rendered feedback text for phrases, so a genuine comment like "this path has no feedback loop, add one" pattern-matched as no-action and was silently dropped. The CLI now offers plannotator review --json, emitting one structured { decision, message } record from the same builder as the plaintext output, and Amp routes purely on the decision field. The prose classifier is gone. An outdated CLI produces a recoverable update notice with the captured output, never a guessed decision.

Contributed by @​FNDEVVE, closing #1456. #1476

Additional Changes

  • Selection toolbar stays on screen on phones: selecting short text near a screen edge in compact touch layouts overflowed the floating toolbar past the viewport, clipping its buttons. It now clamps inside the screen (respecting notch safe areas) and keeps its centered position whenever that fits. Desktop placement is untouched. Contributed by @​katya4oyu in their first contribution. #1471
  • The view dropdown follows the live base: the "All changes since " option label was baked at session start from the detected trunk and never updated, so it could contradict the base picker sitting next to it. It now renders from the active base.

Install / Update

macOS / Linux:

curl -fsSL https://plannotator.ai/install.sh | bash

Windows:

irm https://plannotator.ai/install.ps1 | iex

Claude Code Plugin: Run /plugin in Claude Code, find plannotator, and click "Update now".

Pi: Update @&#8203;plannotator/pi-extension to 0.27.13 and restart Pi.

OpenCode: Clear cache and restart:

rm -rf ~/.bun/install/cache/@&#8203;plannotator

What's Changed

  • feat(review): open a review on a specific base and diff type in #1484
  • fix(review): strict argument parsing for unknown review flags in #1483
  • fix(doc): deny symlink escapes on /api/doc reads by @​bendrucker in #1437
  • fix(test): isolate test-run data from contributor history by @​FNDEVVE in #1473
  • fix(amp): relay structured decisions without prose classification by @​FNDEVVE in #1476
  • fix(ui): keep selection toolbar within compact touch viewport by @​katya4oyu in #1471

New Contributors

  • @​bendrucker made their first contribution in #1437
  • @​katya4oyu made their first contribution in #1471

Community

This release is mostly the community's. @​bendrucker shipped the symlink containment work through two rebases we caused, and when CI failed on his branch he did the diagnosis himself: reproduced it deterministically, tested and disproved our working theory, and root-caused a flake that had dogged this project for weeks, then filed the follow-up (#1477) for the remaining cases. @​FNDEVVE swept our own issue tracker and closed two filed issues in as many days, with fixes careful enough that one of them independently matched bendrucker's root cause line for line. @​katya4oyu fixed a real phone papercut with a minimal, well-tested change that read the repo's conventions closely enough to regenerate a build manifest most first PRs miss. And the headline feature exists because a user on X told us the review always opened against the wrong base when reviewing a stack. They were right.

Thank you. Plannotator gets better because you tell us where it falls short.

Full Changelog: backnotprop/plannotator@v0.27.12...v0.27.13

janosmiko/lfk (github:janosmiko/lfk)

v0.18.12: v0.18.12

Compare Source

0.18.12 (2026-09-11)

Features

Bug Fixes

  • reap browser opener process and close probe handle (#761) (ae84899)
  • reset the explorer layout to normal on config reload (#764) (7368824)

v0.18.11: v0.18.11

Compare Source

0.18.11 (2026-09-10)

Features

  • quarantine a pod out of its Service selectors (#751) (24bfdb1)
  • show what constrains the selected object (#755) (b985970)

Bug Fixes

  • land owner jumps on the visible sidebar row (#759) (623d313), closes #748
  • open the constraints view for workloads only and size its columns (#758) (cd1cdcc)
  • scope the instant metrics throttle by namespace (#749) (eb50b95)

v0.18.10: v0.18.10

Compare Source

0.18.10 (2026-09-09)

Features

  • add KYAML output to copy, export, and the YAML viewer (#732) (3f204ac)
  • browse Dynamic Resource Allocation objects (#737) (1424a37)
  • browse MutatingAdmissionPolicy and binding objects (#734) (78e075c)
  • browse PodCertificateRequest and ClusterTrustBundle objects (#738) (f02f204)
  • jump from a pod to its ResourceClaim with c (#746) (97ece1e)
  • resize pod container resources in place (#747) (72575dd)
  • show the right-sizing data span when it is shorter than the window (#740) (cef699d)

Bug Fixes

  • drop kubeconfig files that declare no clusters, users or contexts (#741) (ba3eacf)
  • drop kubeconfig files whose only cluster has no server (#745) (73c5117)
  • keep user-supplied values out of config warnings (#744) (a38904c)
  • log the kubeconfig_dir shape instead of its raw value (#739) (c9106b4)
  • show a real Changed age on container rows (#736) (eaf73e1)
  • show the resources a Helm release manages in its resource map (#743) (b275a9e), closes #742
  • treat HPA minReplicas 0 as scaled to zero (#735) (38e10d7)
modem-dev/hunk (github:modem-dev/hunk)

v0.22.0: v0.22.0

Compare Source

What's Changed

New Contributors

Full Changelog: modem-dev/hunk@v0.21.0...v0.22.0

nolabs-ai/nono (github:nolabs-ai/nono)

v0.77.0: v0.77.0

Compare Source

What's Changed

New Contributors

Full Changelog: nolabs-ai/nono@v0.76.0...v0.77.0

SocketDev/socket-cli (npm:socket)

v1.1.171: v1.1.171

Compare Source

What's Changed

Full Changelog: SocketDev/socket-cli@v1.1.170...v1.1.171

semgrep/semgrep (pipx:semgrep)

v1.177.0: Release v1.177.0

Compare Source

1.177.0 - 2026-09-10

### Added

  • Added native Supply Chain support for Bazel workspaces using rules_jvm_external. Semgrep now recognizes a maven_install.json pinned lockfile (versions 0.1.0 and 3, as emitted by rules_jvm_external 3.x through current) paired with a MODULE.bazel (or legacy WORKSPACE / WORKSPACE.bazel) marker as a Maven-ecosystem subproject, and attributes findings to the workspace root rather than the lockfile's directory. Workspace-declared root artifacts are identified via __INPUT_ARTIFACTS_HASH for accurate direct-vs-transitive classification; dependencies are emitted with Unknown transitivity when that field is not available. This is the first milestone of native Bazel coverage; broader ecosystem support (rules_python, rules_go, rules_js) and Bazel-aware reachability attribution follow. (SC-2008)
  • Several performance improvements for regex-only rules where the underlying
    regex are inefficient to run on our default regex engine (currently PCRE2). For
    example, a rule matching FOOBAR(a+)\1 will skip any file that does not
    contain FOOBAR without running the regex. (scrt-979)

### Changed

  • Prefilter conditions now evaluate their cheap string predicates before their
    expensive regex predicates. Since evaluation short-circuits, a file that a
    string check already rules in or out no longer pays for regex predicates
    (which is what a pattern's prefilter falls back to when no literal substring
    can be extracted from it, and which can be slow on files with very long
    lines). (prefilter-rank-conjuncts)
  • Supply Chain scans can report dependencies from their Gradle module build files instead of the root manifest. This behavior is disabled by default during rollout and can be tested with --x-gradle-module-attribution. Enabling it can change finding IDs because finding paths change; the ID calculation is unchanged. (SC-2560)

### Fixed

  • Speed up semgrep ci filtering when a deployment has many triage-ignored findings. (triage-ignored-performance)

  • Semgrep no longer crashes with an OCaml stack trace when a proxy environment
    variable holds an unusable value. HTTP_PROXY, HTTPS_PROXY, or ALL_PROXY
    set to an empty value is now ignored with a warning, and the scan
    proceeds without a proxy. A non-empty value that is not a usable proxy URL
    now exits with an error message, with any credentials in the URL
    redacted, instead of failing inside the HTTP client.

    Semgrep also now adds the missing scheme to a proxy URL supplied
    without one; https for HTTPS_PROXY and http` otherwise. (ENGINE-2208)

  • Supply Chain: lockfileless Gradle scans now report a "Resource Inaccessible"
    resolution error when a repository refuses a request (for example a 401 from a
    private registry), instead of exiting successfully with a silently incomplete
    dependency list. (sc-3358)

### Infra/Release Changes

  • Improves shutdown time during scans with --trace. (otel-shutdown-flush)
jdx/usage (usage)

v6.9.0: v6.9.0: Default-subcommand flag routing, standalone Args parsing, and smaller help builds

Compare Source

Flags belonging to a default subcommand can now select it without typing its name, a derived Args type can be parsed on its own, help colours can be remapped, and a series of help-rendering changes trims binary size for usage-rs adopters. Bash completion also stops mangling colon-separated candidates.

Added

  • (parse) Opt-in default-subcommand flag routing (#1413, @​jdx). With default_subcommand_flags, leading flags that belong only to the configured default subcommand route to it, so em -ua @&#8203;world parses as em install -ua @&#8203;world. Explicit command names and aliases still win, parent-only flags and bare invocations stay on the parent, a mixed short bundle such as -pua keeps the parent's -p, and -- or an unknown flag stops the lookahead. Completion also offers the default command's flags at the root. Supported in KDL specs, the Rust derive, and the Go runtime; existing routing is unchanged without the opt-in. usage lint reports default_subcommand_flags declared without a default_subcommand.

    default_subcommand "install"
    default_subcommand_flags #true
    #[usage(default_subcommand = "install", default_subcommand_flags)]
  • (parse) Parse a derived Args type without an enclosing CLI (#1419, @​jdx). usage::parse_args_from::<T> treats the slice as that command's words; usage::parse_args_from_argv::<T> strips argv0 first. Both reuse the command's compiled flags, positionals, defaults, validation, and nested subcommands, and return the ordinary parse errors, including help and version requests. Available behind the spec feature.

    let install = usage::parse_args_from::<Install>(&args)?;
  • (help) Remap semantic help colours with a Palette (#1414, @​lu-zero). The heading, option, metavar, and command roles were previously fixed SGR colours. help::Palette remaps any of them using the existing {$…} tag vocabulary (for example "cyan+bold"), and Style::palette applies it; role names expand once, so mapping metavar to "heading" uses the built-in heading colour. Hosts that own the exit path get embedded_outcome_paletted / embedded_outcome_into_paletted (and embedded::outcome_paletted); parse() and plain rendering are unchanged.

    let palette = usage::help::Palette::DEFAULT.metavar("cyan+bold");
    match Ex::embedded_outcome_paletted(&argv, palette) { /* … */ }

Changed

  • (cli) Smaller binaries and faster help rendering (#1396, #1399, #1400, #1401, @​jdx). Help sorting and rendering do less work and share more code, plain (uncoloured) help skips colour-span analysis, and the flag diagnostics share one formatter. Help output is byte-identical; on the oxc binaries used for measurement this removed roughly 360 KiB combined, and plain --help rendered about 18% faster locally. Two new opt-ins let CLIs trim further:

    • Flattened subcommand pages, HelpAll, and recursive render_all now live behind a help-advanced feature (enabled by default in usage-rs and usage-argv). A CLI that uses none of them can disable defaults and omit it:

      usage = { package = "usage-rs", version = "6", default-features = false, features = ["help", "diagnostics", "completions"] }
    • #[usage(spec_endpoint_file = "cli.usage.kdl")] answers __usage_spec__ from a KDL file included at compile time, keeping the endpoint without linking the runtime serializer. to_kdl() still generates from live metadata, so regenerate the file after CLI changes and test the two for drift.

    Compatibility note: dependents that already set default-features = false and declare flatten_help or a HelpAll flag must add help-advanced; the derive now rejects those declarations at compile time, and hand-written metadata requesting advanced help panics when rendered instead of being silently ignored.

Fixed

  • (bash) Preserve colon-prefixed completion words (#1405, @​jdx). When : is in COMP_WORDBREAKS, Readline replaces only the fragment after the last colon, so candidates such as update:deps:no-cooldown were inserted with a duplicated update:deps: prefix. The generated Bash script now forwards the current Readline word and COMP_WORDBREAKS to the __complete_word__ request, and the binary reports the prefix Readline keeps so the script can trim it; escaped colons, consecutive colons, and a cursor on a colon are handled. Path candidates are unaffected. Regenerate Bash completion scripts to pick up the fix (reported in Bash completion duplicates colon-prefixed task names on second Tab jdx/mise#12970).

New Contributors

  • @​lu-zero made their first contribution in #1414

Full Changelog: jdx/usage@v6.8.0...v6.9.0

💚 Sponsor usage

usage is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If usage powers CLI specs, docs, or completions for a tool you maintain or use, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep usage fast, free, and independent.

Skipped Packages

Non-GitHub Sources

GitHub Release Notes Unavailable

  • droid: No GitHub release was found for 0.218.1

@renovate
renovate Bot force-pushed the renovate/mise-packages branch 2 times, most recently from b093da9 to d03a912 Compare September 16, 2026 20:35
@renovate
renovate Bot force-pushed the renovate/mise-packages branch from 1eabd11 to 59ce169 Compare September 16, 2026 21:56
@renovate
renovate Bot merged commit 40fcf85 into main Sep 16, 2026
6 checks passed
@renovate
renovate Bot deleted the renovate/mise-packages branch September 16, 2026 22:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant