chore(deps): update dependency @anthropic-ai/claude-code to v2.1.263 - #87
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update dependency @anthropic-ai/claude-code to v2.1.263#87renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 22, 2026 19:01
79c24ab to
7cf0410
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
2 times, most recently
from
August 23, 2026 18:28
2fb78db to
010cc7b
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 25, 2026 12:56
010cc7b to
7c27f75
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 25, 2026 21:14
7c27f75 to
1a2b1c0
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 26, 2026 01:51
1a2b1c0 to
a217f3b
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 27, 2026 21:49
a217f3b to
c655bb5
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 28, 2026 03:38
c655bb5 to
7d31fb6
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 28, 2026 04:51
7d31fb6 to
3befecb
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 28, 2026 21:37
3befecb to
9e27400
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 29, 2026 22:45
9e27400 to
a1526c9
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 30, 2026 21:57
a1526c9 to
2dbc56a
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 31, 2026 02:10
2dbc56a to
072cde8
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
August 31, 2026 18:51
072cde8 to
d1e6189
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
September 4, 2026 01:34
d1e6189 to
6559364
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
September 4, 2026 18:16
6559364 to
27201e9
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
September 5, 2026 00:30
27201e9 to
a221c99
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
September 5, 2026 22:31
a221c99 to
368e8b3
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
September 7, 2026 03:01
368e8b3 to
658df4d
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
September 7, 2026 20:54
658df4d to
5feabb8
Compare
renovate
Bot
force-pushed
the
renovate/anthropic-ai-claude-code-2.x
branch
from
September 9, 2026 04:26
5feabb8 to
232f55d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.1.234→2.1.263Release Notes
anthropics/claude-code (@anthropic-ai/claude-code)
v2.1.263Compare Source
v2.1.261Compare Source
/statusandclaude doctorthat says why your organization's policy could not be loaded, such as a proxy not passing the endpoint throughbashOutputMaxCharsandtaskOutputMaxCharssettings to raise how much command and background-task output Claude receives inline before it is saved to a file, up to 128K characters--append-subagent-system-prompt-fileto read the subagent system prompt from a file, for prompts too large to pass on the command line/skill-doctorto show which loaded skills go unused and what they cost in context, so you can prune them/add-dir <subdirectory>printing a false "couldn't be resolved" error when the working directory is on a/netautomountenabledPlugins, then falling back to a marketplace clone that could fail[Image #N]chip in the prompt input/clear/teleportinto the connected session, which appeared appended to the original on phone and webgcpAuthRefreshopening a browser at startup when the Google credential check was slow, even though the credential was still valid/usageand the VS Code usage panel dropping a model-specific weekly limit row when the usage endpoint is rate limited or when opened right after startupclaude -p --resume <file>adopting a malformed session ID recorded in the transcript; it now resumes under a fresh session ID insteadX-Forwarded-For; with an access list set, an unreadable entry now gets 403file_uploadfailing with "paths: expected array, received undefined" in local Cowork sessions run from the Claude Desktop appSendMessageto an offline Remote Control session on another machine reading as delivered; the result now says delivery is queued until that machine reconnects<claude-code-hint>tag no longer leaks into the conversation/modelpicker and the VS Code model pill to show a model's name instead of its raw Bedrock, Vertex AI, or LLM gateway ID when Claude Code recognizes itGOOGLE_APPLICATION_CREDENTIALSis set: API client creation no longer re-runs Google Cloud project discovery or spawns extragcloudprocessesrmsafety prompt to also catchrm -rfon positional parameters and inside double-quotedsh -cscriptsAPI_TIMEOUT_MS(10 minutes by default) instead of another 3 minutes, and the messages say what to change/login) to say Claude Code may not be enabled for the organization, instead of advising a new sign-inforceLoginMethod: "gateway"to ignore a leftover API key or claude.ai login and ask for/login; Bedrock, Vertex AI, and Foundry sessions are unaffectedkeybindingFlavorno longer has any effect/contexttoken counting to use a local estimate when the token-counting API is unavailable, instead of extra small-model requests/btwside-question history from earlier sessions being overwritten when a question is asked right after a window reload or while a settings file has errorsv2.1.260Compare Source
/diff/costand the status line'sprompt_cachefield/reload-pluginsto headless sessions, so it appears in the Claude Code Desktop and SDK command lists/advisor(/advisor,/advisor <model>,/advisor off) for the desktop app, Remote Control, and other headless (-p/Agent SDK) sessionsoidc.scope_on_refreshto the Claude apps gateway for IdPs that return an id_token on refresh only when asked foropenidagaindesktoppolicy blocks, includinguserPluginMarketplacesEnabledanduserPluginUploadsEnabledEdit/Write/Readpermission rules whose path contains parentheses being dropped as invalid or ignored by the Bash sandbox, which left "read-only" folders writable[) making every file edit fail withInvalid regular expression; such a deny rule now guards the literal path it spellspermissions.blockReadsOutsideWorkingDirectorieson macOS hiding the user's git config from sandboxed git and hiding a worktree-isolated sub-agent's own checkout/login/statuslisting a signed-in claude.ai account and a configured API key as if both were in effect; the credential not in use is now markedskillOverridesentries keyed on a bundled skill's alias (e.g.checkupfor/doctor) not applying, andSkill(name)deny rules not covering a nested skill listed as<dir>:namemodel: fableagents ignoring the[1m]tag on anANTHROPIC_DEFAULT_FABLE_MODELpin and silently running with a 200K context window/modelpicker not showing Fable 5.1 for organizations that can use it, which was only accepted when typed as/model claude-fable-5-1…)/rewindand--rewind-filesreporting success when checkpoint backup files were missing and nothing was actually restored/rewindleaving stale file-read tracking from the rewound-away turns, which caused "File unchanged since last read" stubs and full-file re-injection after external edits-p --resume/--continue(as used by the desktop app) failing on every retry once a session's worktree directory lost its git metadata; it now fails once, then resumes without the worktreeCLAUDE_CODE_RETRY_WATCHDOG) as retry notices evicted real messagesgitlab.com/group/subgroup/project)owner/repo#123issue references in rendered output linking to github.com when working in a GitLab repository; they now link to the gitlab.com issueRead()deny rules to Bash arguments; it deniednpm run buildunder aRead(./**/build/**)rule in every mode and madecd … && grepprompt even in auto modeagent({schema})rejects a JSON Schema that can never be satisfied up front, and retry-cap errors now include the last validation failure-p/ SDK) sessionsbedrock:CountTokens) instead of a one-token requestEdit(C:\dir\(name)\**), where\(is read as an escaped parenthesis rather than a path separator, to suggest an unambiguous spelling/ultrareviewandclaude ultrareviewto wait up to 45 minutes (previously 30) for long-running cloud reviews/efforton Claude Fable 5.1 so changing effort mid-session no longer invalidates the prompt cacheclaude-apiskill so its Go, Java, and C# samples use current-generation model IDs, and clarified that cheaper worker or sub-agent models should be current-generation tooctrl+l/cmd+kin fullscreen mode to clear the transcript view like a terminalclear; scroll up to see earlier messagesBash(ls) x), which never matched anything, to be reported as invalid settings instead of being silently ignoredclaudeMd) no longer triggers the security approval dialog; hooks, shell-command, sandbox, and unsafeenvsettings still require approval--chrome,/chromeand the browser tools are unavailableorgPluginSettingsin the list form read by Claude Desktop 1.15200.0 and later; older desktops ignore itdesktoppolicy misspells a field in a nested object of amanagedMcpServersororgPluginSettingsentry!bash-mode prompt to run outside the sandbox even when strict sandbox mode (sandbox.allowUnsandboxedCommands: false) is on, like typing into your own terminal--kill-session-after-minto release a session that is only waiting on its user (paused, resumable on the next message) instead of killing it and reporting a failurev2.1.259Compare Source
managedMcpServersmanaged setting: organizations can provide HTTP/SSE MCP servers to every user (same entry shape as.mcp.json); entries that name a command to run are skipped--permission-prompts nonefor unattended headless hosts: anything that would prompt is denied automatically while the active permission mode (including auto mode) keeps decidingglab mr create/merge/close/reopen/note/updateso GitLab merge requests show asMR !Nin the collapsed tool summary and refresh the footer MR badge--jsontoclaude plugin validatefor a machine-readable validation report~/.claude.jsonchanges — workspace trust no longer resets and MCP/project state is no longer lost when running many sessions at onceRead()deny rules not covering files given as option values (--ignore-revs-file=.env,-f.env,@file),git diff/git grepfile operands, orcd DIR && cat FILEcompounds;grep -r/cp -rover a directory holding a denied file now asksmodel:named one; the turn now keeps the session modelCLAUDE_CODE_MAX_CONTEXT_TOKENSbeing ignored for Vertex-style model IDs (@YYYYMMDDsuffix) of model versions Claude Code doesn't recognize--resumefailing (and--continueopening an empty conversation) when a saved session contains an attachment entry with no payloadmodel:on custom commands and skills being ignored in interactive sessionsnote" error in conversations continued from an older versionforceRemoteSettingsRefreshbeing ignored at startup when a policy helper configured by MDM or the managed settings file had already rungit rev-parsefails with a message other than "not a git repository"user.email,organization.id, anduser.account_uuidattributes?/#producing an unusable.gitclone URL/workflowsagent detail: JSON outcomes are pretty-printed with syntax colors and real line breaks, and long outcomes fold behind an expand toggle/install-github-appto explain it is GitHub-only and point to the GitLab CI/CD docs when run inside a GitLab repositoryallowedMcpServersto govern only servers users add: a literalmanaged-mcp.jsonserver your allowlist used to filter out now loads on upgrade; usedeniedMcpServersto keep it offv2.1.258Compare Source
v2.1.257Compare Source
claude-fable-5-1), now the default Fable model — 1M context, $10/$50 per Mtok with $0.25/Mtok cache readstimeFormat) andtimeZonesettings: 12-hour, 24-hour, 24-hour UTC, or a strftime pattern for the turn-end clock and transcript-view timestampsCLAUDE_CODE_SUBAGENT_MODEL_FORCEto applyCLAUDE_CODE_SUBAGENT_MODEL(or the main model) to every subagent, ignoring per-spawn and agent-definition model overridessin/effortto change effort for the current session only, matching/model/doctorwarning for stale sandbox mask files left by a killed sessionpermissions.blockReadsOutsideWorkingDirectories)descriptionon discovered/modelpicker entries (CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY); entries without one still read "From gateway".claude/folder created after startup not being picked up until restart←always starting in the original session's permission mode, overriding the target directory'sdefaultModeand the agent'spermissionModekeybindings.jsonrebinds of Ctrl+G being ignored inclaude agents; its Ctrl+S / Ctrl+T are now rebindable via the newAgentscontextstate.jsondetailrepeating its own dispatch prompt after a scheduled wake-upclaude agentskeeping a background session you re-prompted buried in Completed after it finished again; Completed now orders by the latest finishclaude --bgfrom a directory that was just deleted reporting "backgrounded" and leaving a crashed session row; it now prints the reason and exits 1Authorizationheader overriding the configured credential on Bedrock, Mantle, Vertex, and WIF, and the Vertex setup wizard picking up a leftover Anthropic profile from~/.config/anthropicAuthorizationor profile headers to Foundry, Vertex, and Bedrock, and Foundry Entra ID upstreams not starting whenANTHROPIC_FOUNDRY_API_KEYis set/scheduleroutines whose prompt was saved without a message role and then ran with nothing to doclaude agentsnot saying that a background session is waiting for you to approve a message from another session, or who sent itpolicyHelpertimeoutMsandrefreshIntervalMsvalues above the timer maximum (2147483) causing failures or re-runs every millisecond; they are now clampedexample.com.): adeniedDomainsentry didn't block the host inside the sandbox, and "don't ask again" for such a host kept promptingnatclaude remote-control) counting as consent, so the next request connected without asking/mcpreconnect and enable still connecting a settings-file MCP server that a managed MCP allow/deny list orstrictPluginOnlyCustomizationloaded after startup should blockclaude mcp removeleaving a remote server's stored OAuth credentials behind whenstrictPluginOnlyCustomizationlocks MCP to plugin-only serversclaude remote-control) sessions started from the Claude app ignoring the selected model and running on the machine's default instead--disallowedToolsand session deny rules being dropped after the first settings reload whenallowManagedPermissionRulesOnlyis enabled--resumelisting a backgrounded conversation twice and--continuereopening its stalled pre-background copy;--continuenow also opens finished background sessions!shell command output to expand itclaude agents --jsonbriefly switching the terminal to raw mode and undoing another program's terminal settings on exit←doing nothing in the/btwpanel inside aclaude agentssession: it now returns to the agents list (even mid-answer), and the panel comes back when you reopen the session/recap, prompt suggestions) and re-sending the full conversation uncached each timeclaude -pexiting about 5 seconds after its final result while a Monitor the model armed was still running; it now waits for the watch to fire or time outpermissions.askrule being skipped in auto mode when the matching command ran inside a compound command or subshell, letting it run without the confirmation prompt/add-dirrejecting a directory inside the current working directory; it now loads that directory's skills, commands, and agents like--add-dirdoes at startup/feedbackclaude mcp add/removehanging or exhausting memory when the project's.mcp.jsonis a FIFO or a device-file symlink; it now fails fast with an actionable messageclaude -p --input-format stream-json; it now fails fast with a clear error←or Ctrl+B) while a subagent or other tool was running occasionally making the background session treat that tool as rejected instead of re-running itRead()/Edit()deny rules not applying to< fileredirects and reader commands liketacandegrep; a deny rule on any argument or redirect target now refuses the command$VARreads,"$(…)"and heredocs that never touch git as "too complex to verify that it stays inside the worktree"/modeland/effortshowing a prompt-cache warning after rewinding a conversation back to emptytimeoutorsetsid) surviving a task stop or Claude Code exit.gitdirectory aftercdinto a subdirectory/logininstead of reporting a network errorcc-daemon-*folders in the system temp directory after an interrupted background daemon start; thecleanupPeriodDaysretention sweep now removes them[[ ]]conditionals that zsh parses differently from bash; these commands now prompt for approval/statusnot showing the Organization for that sign-in/status, declining the managed-settings dialog prints why Claude Code exited, and helper timeouts are reported as timeouts/code-review --commentto post findings on GitLab merge requests viaglab mr noteinstead of reporting the target as unsupportedclaude self-hosted-runner --configure-gitto also enable git push negotiation, so the first push of a new branch from a stale clone uploads only the new commits instead of the whole treeCLAUDE_STREAM_IDLE_TIMEOUT_MSare not mistaken for a hung session/forkto keep the original conversation's prompt cache in the new background session: its worktree briefing now arrives as a message instead of a system-prompt change:satisfied:,:telephone:,:collision:, …)--effortto lift a new model's default-effort hold for that session only rather than permanently; an effort picked on claude.ai for a Remote Control session now applies during the holdpolicyHelperin MDM ormanaged-settings.jsonshadowed at launch by cached server-managed settings to run (or exit) as soon as the fetch reports them removed, not at the next launchmanagedSourcesBehavior: "merge"to takesandbox.credentials.awsPairsandsandbox.ripgrepwhole from the highest managed source that sets them instead of combining the sources' valuesCLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY=1) to run even whenCLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFICis set, since it only queries your gatewayclaude --resume <session-id> --bgto continue that session under its own ID when nothing is running it, instead of silently starting a copy; a copy is now announced/btwhistory browsing from←/→toShift+←/Shift+→(or[/]), stepping through your recent side questions and back to the live answerdefaultMode: "bypassPermissions"in.claude/settings.jsonor.claude/settings.local.jsonto be ignored, like"auto"; set it in user or managed settings, or pass--permission-modefableandbestin Claude apps gateway sessions to keep resolving to Fable 5 for now, since gateways not yet configured for Fable 5.1 reject it; pick Fable 5.1 in/modelto use it--add-dir,/add-dir, andadditionalDirectoriesto refuse network paths (UNC shares,/net/<host>automounts) with a message before touching them; on Windows use a mapped drive letterv2.1.252Compare Source
v2.1.251Compare Source
PreModelSwitchandPostModelSwitchhook events (block, confirm, or annotate a model switch);SessionStartresume hooks now receive session staleness and the estimated re-cache cost/usageand arate_limits.spend_limitstatus line field for developers behind a Claude apps gateway with spend limits/cost(hit ratio, misses, tokens re-cached, warm/cold) and a matchingprompt_cacheobject for status line scriptsattach,logs,stop,respawn, andrmtoclaude --help; the--resumemessage for a running background session now names the exactclaude attach <id>commandscriptPathoutside what the session may read before the permission check ranRead(...)deny rules to files reached through a symlinked search pathhighin that caseSendMessageto that session id now delivers through Claude Desktop instead of failing with "not reachable"fromwas the agent type, which is not an address)disableAutoModearriving mid-session not moving an already-running auto-mode session back to default mode/statusand retrying gateway 401s with it, though requests never use it/mcp reconnecton Remote Control showing a generic withheld-detail error instead of the real remedy when a server was disabled in another session--input-format stream-json: client-injected assistant tool calls sent without a message id were merged into the first one and their results lost, including when resuming older sessionsgit worktree add/usage-creditsfor Team and Enterprise members whose admin set the org's usage-credit limit to $0: it now offers to ask the admin instead of saying a cap was reached--worktree --tmuxwith a merge-request number on a gitlab.com origin trying a doomed GitHub-style fetch first instead of fetching the GitLab ref directly/dev/tty, such asemacs -nwandmicroadditionalDirectoriesentry containing a null byte crashing startup, or breaking/add-dirand later settings updates when it came from an SDK host, IDE, or hook; it is now skippedscreenterminal typeclaude mcp add --headerandclaude mcp add-jsonhelp text naming the wrong transportsclaude ultrareviewand/ultrareviewwaiting the full 30 minutes when the cloud session fails to start; they now stop early and report the reasonOPTIND=1/0,RANDOM=2+2); these now prompt for approval←,/background,--bg) losing a Vertex/Bedrock gateway (ANTHROPIC_*_BASE_URL+CLAUDE_CODE_SKIP_*_AUTH) exported in the shell, so every request failedclaude --bg --model fableon Max plans stopping to ask for usage credits while the interactive session on the same account still had Fable allowance/bugand/sharereporting that/feedbackwas disabled; tips,/help, and refusal messages no longer suggest/feedbackwhen an org policy or env var turns it off/scheduleto explain that MCP servers configured in Claude Code can't be attached to cloud routines, instead of a bare "No MCP connectors" message/tasksCLAUDE_CODE_PROVIDER_MANAGED_BY_HOST(e.g. Claude Desktop): a session given a Bedrock model ID or ARN no longer waits for inference-profile discovery/radioto be available on Bedrock, Vertex AI, Foundry, and Claude Platform on AWS, and when telemetry is disabledCLAUDE_CODE_SUBAGENT_MODELto set the default subagent model rather than override everything: an agent definition'smodel:and an explicit per-spawn model now take precedence over itCo-Authored-By: Claude Codewhen the active model isn't a recognized Claude model (e.g. third-party models behind a customANTHROPIC_BASE_URL)/effortto save your default effort level per model, so each model keeps its own setting when you switchDISABLE_TELEMETRYgh auth token,GH_TOKEN, orGITHUB_TOKEN) instead ofgh pr viewANTHROPIC_CUSTOM_HEADERSfrom managed or project settings to require approval when it sets a credential, org/tenant, routing, or API-behavior header (e.g.Authorization,Host).claude/settings.jsonenvto no longer setCLAUDE_CONFIG_DIR,CLAUDE_CODE_TMPDIR, orTMPDIR/TMP/TEMP; set them in your shell, user, or managed settings instead/remote-controlv2.1.250Compare Source
v2.1.248Compare Source
--restricted(orCLAUDE_CODE_RESTRICTED=1): removes the builtConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.