chore(deps): update dependency @anthropic-ai/claude-code to v2.1.223 - #5940
Conversation
|
🤖 Finished Review · ✅ Success · Started 3:53 PM UTC · Completed 4:01 PM UTC |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
ReviewFindingsHigh
Next steps:
Previous runReviewFindingsHigh
Labels: PR updates a dependency version in the sandbox Containerfile Next steps:
|
39dcdb0 to
75383b0
Compare
|
🤖 Finished Review · ✅ Success · Started 4:19 AM UTC · Completed 4:27 AM UTC |
|
🤖 Finished Retro · ✅ Success · Started 8:04 AM UTC · Completed 8:18 AM UTC |
Retro: PR #5940 — Renovate bot claude-code version bumpTimelinePR #5940 was a single-line Renovate bot update bumping
What went well
What could go betterThis single-line version bump triggered 5 agent runs (2 reviews, 2 fix attempts, 1 retro) plus 5 dispatch jobs — a cascade of automation for a change that only needed a human to click Approve. Each step in the cascade is already tracked by existing issues: Protected-path noise on bot dependency PRs:
Redundant re-review after Renovate rebase:
Duplicate inline comments across review rounds:
Fix agent dispatched on unfixable findings:
Skip all agent stages for bot dependency PRs:
Fix agent bot-detection:
Pattern confirmationThis is not an isolated case. Checking the 5 most recent merged Renovate PRs confirms the pattern: every Renovate PR touching No new proposalsAll improvement opportunities identified in this retro are already tracked by existing open issues. The highest-impact single change would be implementing #5360 (skip review/retro for bot dependency PRs), which would eliminate the entire cascade. Alternatively, #3910 (exempt single-ARG version bumps from protected-path) would convert the review verdict from CHANGES_REQUESTED to APPROVED, preventing the fix dispatch chain while preserving the review signal. |
This PR contains the following updates:
2.1.220→2.1.223Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
anthropics/claude-code (@anthropic-ai/claude-code)
v2.1.223Compare Source
"owner/*") to thestrictKnownMarketplacesandblockedMarketplacesmanaged settings for allowing or blocking all marketplace repos under a GitHub org/teleporthint in cloud sessions showing how to continue locally withclaude --teleport <session id>import()to run code outside the workflow sandboxbypassPermissionsmode ignored the org bypass-permissions disable policy/cdcoming back emptyvertex_ai/claude-*orbedrock/anthropic.claude-*modelOverrideskeys that aren't Anthropic model IDs being treated as the session's canonical model ID; unknown keys are now ignored as documentedmanaged-settings.jsonor MDM profile; admin env now merges per keysandbox.filesystem.denyWritecovers the working directorygit pushoutputCLAUDE_CODE_DISABLE_1M_CONTEXTto hold every Claude model with a native 1M window to 200K via auto-compaction, not just a fixed list; a startup warning now appears when auto-compaction isn't holding the session to 200KCLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1to restore the previous behavior/reviewto be an alias of/code-review, which reviews the current diff or a PR (/code-review <level> <pr#>); use/code-review ultrafor a deep cloud review/code-reviewwith no effort level to reuse the level you typed last; type a level like/code-review highto change itv2.1.222Compare Source
/usage-creditson Team and Enterprise showing "you've already sent a usage credit request" for members whose earlier request was dismissed, blocking them from sending a new one/usageoverattributing usage to MCP servers: a server's share now reflects only the requests that actually consumed its tool results, instead of every turn after any call to itmodel: opus-style subagent and teammate family aliases dropping to the parent model instead of stepping down to the newest org-allowed model in the familyANTHROPIC_BASE_URLgateways despite server keep-alive pings arriving on the wire/loginhint insteadSendMessagerejecting a long summary — it now truncates instead, so sends no longer fail on a character limiteffort:setting--ax-screen-readermode — end-of-line deletions now echo just the deleted charactersmanaged-settings.jsonwhenCLAUDE_CODE_PROVIDER_MANAGED_BY_HOSTis setSendMessageare now evaluated by the permission classifier before dispatchdisable-model-invocation: Claude is now told to ask you to run the skill instead of replicating its workflow/diffview, the Remote Control workspace diff, and file-edit diffs in Claude Code on the web sessions to use raw git blob content, ignoring workspace-configured diff drivers and textconv.claude/settings.jsonor.claude/settings.local.json) can no longer turn it on (they can still turn it off); enable it at user scope via/configv2.1.221Compare Source
Ctrl+Alt+For the "Claude Code: Toggle Focus view" commandmode: "mask"for sandbox credential files on Linux and WSL — sandboxed commands read a sentinel copy (the whole file, or just the spans captured by anextractregex) while the sandbox proxy substitutes the real value on egress; on macOS file masking falls back todenyclaude plugin validatewhen a marketplace or plugin name would be rejected by Claude Desktop's managed marketplace syncprompt-auditsubcommand to theclaude-apiskill for auditing prompts and tool descriptions for patterns written for older models[[ ]]regex conditionals; affected commands now prompt for permission--mcp-confignot being connected before the first turn in print mode (-p), which made the model emit tool calls as literal textconstructorxhigh/maxwhen thinking is disabledHOMEenvironment variableCLAUDE_CODE_RESUME_INTERRUPTED_TURN=0not disabling interrupted-turn auto-resume; falsy values are now honored/help,/feedback) being un-invocable in non-interactive sessions/ultrareviewerror messages when a repo shares no history with its base: a checkout with no branches is now refused up front with advice to create one, and refusal hints no longer suggestgit fetch --unshallowon clones that are already completepowershell.exeno longer prompt/plugin installto refresh a stale marketplace catalog and retry before reporting a plugin not found/pluginto activate immediately when safe, instead of always requiring/reload-plugins"."as askillspath, and the root-levelSKILL.mdvalidation error now suggests using the plugin root/statusto show the session kind:interactive, or a background job that isattachedorunattended:thumbsup:,:thumbsdown:, and:love:/forkto create a new worktree of their own instead of working in the original session's checkoutmodelfield validation: non-string values are rejected with a 400 instead of being forwardedConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.