{"releases":[{"id":"db22caa6-2b36-4f75-beb5-6773bfe64bec","source_id":"claude-code","dedupe_key":"claude-code:2.1.289","version":"2.1.289","title":"claude code 2.1.289","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21289","published_at":"2026-10-03T20:12:02.717Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines\n- Fixed the terminal freezing on short code blocks with many unclosed `<script>` tags or deeply nested `${` substitutions\n- Fixed `Read` deny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink\n- [VSCode] Reverted a 2.1.288 change to `claude auth status` that may have made sign-outs more frequent\n- Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width\n- Fixed `plugin list`, `plugin eval` and `plugin update` showing a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked `--plugin-dir`\n- Fixed installed mods not loading in the first session after an upgrade\n- Fixed a plugin's rows above the prompt showing a stale row while the Background tasks dialog was open in fullscreen\n- Fixed plugin panes drawing nothing when a link used a localhost address, an `@` in its path, an uppercase host or a `file:` path\n- Fixed a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server's sign-in tools\n- Fixed a freeze or forced quit at launch when a plugin drew a Box with a border style the terminal does not know\n- Fixed supervised and background sessions ending when a plugin's on-screen handler threw asynchronously\n- Fixed sessions ending with an interface error when a plugin region with no height kept growing\n- Fixed Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value (e.g. `TZ=\"$HOME\" rm -rf build`) when the sandbox auto-allows commands\n- Fixed a Bash deny or ask rule being skipped under sandbox auto-allow when a bare variable assignment came before the command\n- Fixed `claude plugin validate` skipping the plugin when the folder also holds a marketplace manifest\n- Added `agent.spawn` for teammates, one agent id across plugin hook events, and idle and waiting states in `$.agent.list()`\n- Fixed sessions ending with \"unrecoverable interface error\" when a value a mod's `ui.render` hook wrote made a row throw while drawn; the engine now draws its own row instead\n- Fixed text with a tab, a stray escape and a C1 control, or a short text with a tab and CRLF line endings, drawing over the rows below it\n- Fixed right-aligned content in a mod's pane or band drawing under the close mark or `[-]`, which now also keep one column in from the terminal's edge\n- Fixed a mod's `Client` that fails while drawn taking down everything the mod drew around it; it now fails alone and raises `ui.fault`\n- Fixed `claude plugin validate` failing an Anthropic marketplace's own plugin and listing a clean `plugin.json` in `--json`\n- Fixed a mod's band that fails to draw briefly telling the cards under it to step aside\n- Fixed a failed plugin component showing `Error` or nothing as its reason when the failure carried no message\n- Improved the line a mod's author sees when its band or pane fails to draw: it names the mod and says nothing was drawn\n- Fixed published artifact pages freezing or crashing the reader's browser tab on short code blocks with many unclosed `<script>` tags\n- Fixed a mod's Client region staying failed for the whole session after the terminal threw while drawing it","body_html":null,"content_hash":"3226a716fffa6c02427d0ebb228b2bf94280acccb2336ab3fa0b273566b72fae","updated_at":"2026-10-05T18:14:33.808Z"},{"id":"66f16eb1-0ceb-4204-8668-a0ab0ef3496a","source_id":"claude-code","dedupe_key":"claude-code:2.1.288","version":"2.1.288","title":"claude code 2.1.288","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21288","published_at":"2026-10-02T18:30:40.093Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added `$.ui.selection()` for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row\n- Added a built-in `gh api` to cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal\n- Added recovery for a prompt cleared with Ctrl+C: pressing Up on the empty prompt brings the draft back, including pasted text and images\n- Added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call\n- Added `--max-findings <n>|all` to /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass `--max-findings default`\n- Added Ctrl+F to find a session by name and Alt+↑/↓ to jump between groups in the agents view; both, and rename, can be rebound in keybindings.json\n- Added a screen reader mode announcement of the new permission mode when you approve a plan, including with Shift+Tab\n- Fixed mid-response API timeouts failing the turn: non-interactive sessions and subagents now continue from the partial response, and thinking-only responses are retried\n- Fixed long conversations failing with \"Prompt is too long\" instead of auto-compacting when the last reply reported zero token usage\n- Fixed `--resume` sometimes dropping files and other context that a compaction had just restored\n- Fixed a resumed session sometimes not saving the last response of a turn, so that the next `--resume` showed the prompt unanswered\n- Fixed resume occasionally loading a transcript cut short when the same session rewrote the file during the load\n- Fixed resuming a conversation started on 2.1.286 or earlier dropping the model's earlier thinking\n- Fixed session titles, memory recall and prompt hooks failing on Mantle or behind gateways that reject structured outputs; added `CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS` to turn structured outputs off\n- Fixed auto mode denials pointing Claude at a Bash permission rule when the blocked tool was not Bash\n- Fixed auto mode on Bedrock and Mantle switching to the local classifier for the rest of the session after a request to an older model, such as a WebFetch summary or a `sonnet` subagent\n- Fixed cloud sessions that restarted on a newly picked model replying with that model after the server refused it\n- Fixed Cowork cloud sessions staying marked as waiting for input after a WebFetch permission prompt for an unapproved URL went unanswered for five minutes\n- Fixed prompt suggestions not appearing on a phone that joins a Cowork cloud session started on another device\n- Fixed a mod's button sometimes running a different button's action when pressed on a view drawn before Claude Code restarted\n- Fixed a plugin's pane showing nothing when one `Code` element held a diff that does not parse; it now draws as plain code\n- Fixed plugin LSP servers receiving literal `${user_config.*}` and `${CLAUDE_PLUGIN_ROOT}` placeholders in `initializationOptions` and `settings` instead of substituted values or manifest defaults\n- Fixed a plugin's `tool.call` hook making Bash fail and file searches read the wrong folder in subagents that run in a worktree\n- Fixed `git-subdir` plugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04's 2.34)\n- Fixed plugins loaded with `--plugin-dir` not showing \"Configure options\" in `/plugin`\n- Fixed background sessions ending when a plugin was reloaded or disabled while one of its timers or reads was still running\n- Fixed sandboxed heredocs with an unquoted delimiter (`python3 <<EOF`) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple `$VAR` references\n- Fixed Bash tool permission check to prompt before a `BASHPID` assignment whose value the shell would evaluate as arithmetic, instead of allowing it silently\n- Fixed fullscreen sessions exiting with \"unrecoverable interface error\" when opening the background tasks dialog while a plugin or mod showed rows above the prompt\n- Fixed Claude reporting a message to another session as delivered when that session held it: the notice now says it wasn't delivered and names the session, and in SDK sessions Claude can now learn of it mid-turn\n- Fixed OpenTelemetry `claude_code.tool.blocked_on_user` spans reporting `unknown` source or decision in `-p` and SDK sessions and for PreToolUse hook approvals\n- Fixed permission asks that ended unanswered, in `-p` or on an interrupted turn, emitting no `tool_decision` event\n- Fixed Edit and Retry in Cowork cloud sessions refusing a message sent before `/compact` even though its history was still saved\n- Fixed unattended sessions (`CLAUDE_CODE_RETRY_WATCHDOG`) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts\n- Fixed `/login` reporting \"Login successful\" when credentials could not be saved to secure storage; it now shows the failure, and offers a retry when the new login didn't take effect (anthropics/claude-code#73861)\n- Fixed a Stop during Bedrock credential lookup sometimes moving the session to a fallback model instead of ending the request\n- Fixed a second `gcpAuthRefresh`/`awsAuthRefresh` browser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in\n- Fixed agent teams: a plugin-defined agent spawned by name now runs with its own prompt, tools, disallowedTools and effort instead of the defaults\n- Fixed headless (`-p` / SDK) sessions occasionally ignoring SIGTERM when a supervisor such as `timeout` or systemd sends SIGCONT alongside it\n- Fixed restarted cloud sessions restoring a model that the organization's enforced model list refuses\n- Fixed MCP tool calls sometimes running twice when a remote server's result was over 16 MB or could not be parsed\n- Fixed subagents in Claude Desktop's Code tab getting none of the tools of a user-configured MCP server named `memory`\n- Fixed Claude in Chrome asking before every screenshot and page read on a site you allowed when auto mode is unavailable (such as with `disableAutoMode` or an older model); typing, navigation and JavaScript still ask\n- Fixed `claude plugin install` failing for GitHub-source plugins on macOS and Linux machines with no GitHub SSH key: the clone now falls back to HTTPS and prints a notice\n- Fixed `sandbox.credentials.files` entries on git config files not taking effect while `permissions.blockReadsOutsideWorkingDirectories` is on\n- Fixed Claude leaving out your organization's design systems when starting slides or a design with the Artifact tool on Team and Enterprise plans or machines with managed settings\n- Fixed the keyboard not working on Windows after Claude Code restarts itself (first sign-in to a Claude apps gateway, provider setup, `/tui`)\n- Fixed a stall when launching an agent whose `tools:` lists very many `Agent(...)` entries\n- Fixed sessions on Claude 3 Opus and Claude 3 Sonnet failing on every turn after a whole PDF entered the conversation\n- Fixed the npm auto-updater reporting success when the platform-native binary failed to download and only the placeholder `claude` stub was installed\n- Fixed Remote Control cleanup archiving a session that is still connected or was just re-attached by another Claude Code process\n- Fixed `owner/repo` plugin marketplaces showing only the second attempt's error when both the SSH and HTTPS fetch fail; both errors are now shown, with the transport tried first on top\n- Fixed path-scoped `.claude/rules` and nested CLAUDE.md files not loading when Write or Edit creates or changes a file in their scope (previously only Read loaded them)\n- Fixed a dangerous `rm` (such as one on `/` or the home directory) inside a `bash -c` or `sh -c` script running without a prompt in bypassPermissions mode or under a shell allow rule (anthropics/claude-code#96300)\n- Fixed LSP tool calls hanging indefinitely when a language server uses dynamic capability registration or stops responding; requests now time out after 60s (per-server `requestTimeout`)\n- Fixed `idle_prompt` notification hooks firing while background agents are still running (anthropics/claude-code#93672)\n- Fixed PreToolUse and PermissionRequest hooks being skipped when matching them failed or the tool's input could not be serialized to JSON; the call is now blocked\n- Fixed the first request in a fresh environment or after a model switch using the built-in output limit and auto-compact window, not the server's; that request may now wait up to 1.5 seconds\n- Fixed the \"What should Claude do instead?\" hint showing on the Interrupted row after sending queued messages with ctrl+enter\n- Fixed `/login` in a `--bare` session running a sign-in the session never reads, which could replace your saved login; it now says which credentials work\n- Fixed the InstructionsLoaded hook omitting agent_id and agent_type when a subagent's file access loads a rule or nested CLAUDE.md; rules and nested CLAUDE.md files loaded on file access now also report effort\n- Fixed the Agent tool in `claude mcp serve` always reporting no available agents and rejecting every subagent_type\n- Fixed the terminal cursor not following the typed text in the fullscreen transcript viewer's search and in `/theme`'s custom color search\n- Fixed `/permissions` in screen reader mode: typing a rule's number now picks it instead of opening the search box\n- Improved auto mode: when a conversation grows too long for the client-side safety classifier to review, it is now compacted instead of prompting for, or failing, every tool call\n- Improved screen reader mode: short announcements, such as a deleted word, now stay on screen until your next key press or until something above them on screen changes\n- Improved screen reader mode: answered questions in question dialogs now say \"answered\" beside their box\n- Improved the `/usage-credits` message shown to Team and Enterprise members whose organization has turned off usage credit requests\n- Improved cloud sessions: a new conversation's first turn no longer waits for a stdio MCP server whose config sets `alwaysLoad: false`\n- Improved \"You should know\" notes to say \"we\", \"the main agent\" or \"you\" depending on who was responsible for a decision\n- Improved the error for an artifact database write refused at the database's size limit: it now states the limit and what frees space\n- Improved Bash permission prompts to give a shorter reason when part of a command can't be checked before it runs\n- Self-hosted runner: Improved the built-in `gh api`: a refused gh command now prints its `gh api` equivalent, `--paginate` follows every page of a repository's lists, and a nested `claude` no longer removes it\n- Improved Remote Control's recovery from an expired server credential: sessions stay connected during renewal and are kept if it gives up after a server outage\n- Changed the background command time limit to apply only in unattended sessions (`-p`, Agent SDK, CI, cloud); terminal, desktop app and VS Code sessions have no limit\n- Changed the client-side auto mode classifier to ignore an `ANTHROPIC_DEFAULT_SONNET_MODEL` pin that names Claude Sonnet 5.5 or Opus 5.5 and use Claude Sonnet 5 instead\n- Changed `claude project purge` to `claude purge`; the old name still works and prints a notice\n- Changed the agents view `n:` filter (and Ctrl+F search) so Enter opens the session whose name matches best instead of the top row\n- Changed `/autocompact` to save the auto-compact window per model, so each model keeps its own setting when you switch\n- Changed MCP URL prompts from servers that can't report when you're done to wait for \"I'm done, continue\" before the tool call continues, so you can finish in the browser first\n- [VSCode] Fixed a claude.ai connector staying on \"Needs authentication\" after you authorize it: the MCP servers dialog now offers Check connection\n- [VSCode] Fixed the opt-in New Conversation shortcut (Cmd/Ctrl+N) starting a conversation in every visible Claude view instead of only the one you are in\n- [VSCode] Fixed the chat view resuming the next saved session after you archive the one it shows; it now starts a new conversation instead\n- [Cloud sessions] Fixed the Cloud sessions switch in Claude Code admin settings staying locked off while an unrelated security setting was loading or had failed to load\n- [Cloud sessions] Fixed pressing Stop while a self-hosted runner was still starting not cancelling the queued message, which could then run once the runner was up\n- [Claude Tag] Fixed Claude Tag admin settings offering a \"Remove this scope\" option, which always failed, on channels whose settings were created automatically\n- [Claude Tag] Improved Claude to also follow a related Slack thread in another channel that it only read, so updates there reach the conversation that depends on them\n- [Claude Tag] Improved save errors on a channel's Configure page: too-long channel instructions now say to shorten them, and a save refused for lost access no longer says to try again\n- Fixed `claude plugin test` reporting mods as turned off remotely when it had only read an out-of-date saved setting","body_html":null,"content_hash":"c1dbefed34cbe578ea2fa6f4d206a4793a68b53e0a38c81d5d1470f1515540c5","updated_at":"2026-10-05T18:14:33.808Z"},{"id":"47a1f620-187b-4402-9e3f-9c5755e364b4","source_id":"grok","dedupe_key":"grok:grok-voice-transcribe-10-end-of-life","version":"1.0","title":"grok-voice-transcribe-1.0 end of life","url":"https://docs.x.ai/developers/release-notes#grok-voice-transcribe-10-end-of-life","published_at":"2026-10-02T00:00:00.000Z","date_reconciled":1,"digest_import":1,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T18:08:02.751Z","body_md":"grok-voice-transcribe-1.0 is deprecated and reaches end of life on October 2, 2026. All requests to that slug are routed to grok-voice-transcribe-2.0 at the same price, with higher accuracy. See the Speech to Text docs.","body_html":"<p><code>grok-voice-transcribe-1.0</code> is deprecated and reaches end of life on October 2, 2026. All requests to that slug are routed to <code>grok-voice-transcribe-2.0</code> at the same price, with higher accuracy. See the <a href=\"https://docs.x.ai/developers/model-capabilities/audio/speech-to-text\">Speech to Text docs</a>.</p>","content_hash":"64eeebf170952ad398e86083acad8584b533b509fa79a92d01f0f57e3fe5b382","updated_at":"2026-10-05T19:07:18.890Z"},{"id":"a5cbab01-e370-4395-9a1a-83b27836ca23","source_id":"codex","dedupe_key":"codex:rust-v0.160.0","version":"0.160.0","title":"0.160.0","url":"https://github.com/openai/codex/releases/tag/rust-v0.160.0","published_at":"2026-10-01T20:19:13Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:38:02.977Z","body_md":"## New Features\n\n- Browse older tasks in the agent command center with a keyboard-accessible “Show more” action. (#49106)\n- Select transcript text and paste with middle-click in fullscreen mode on supported local Linux X11 terminals. (#49112)\n- Start sessions outside a project with workspace defaults when policy permits, and restore saved permissions when resuming. (#49160)\n- Added opt-in Guardian review capabilities to retrieve earlier user instructions and include context from agent handoffs. (#49036, #49057)\n\n## Bug Fixes\n\n- Unsent queued messages now resume after reconnection once uncertain submissions are resolved, avoiding duplicate sends. (#49105)\n- The terminal UI now preserves server provider, reasoning-summary, and verbosity settings and shows the correct sessions in resume and fork history. (#49144, #49161, #49171)\n- Fixed Windows sandbox PowerShell fallbacks and long-path permission repairs, and suppressed unwanted console windows from background helpers. (#49019, #49058, #49098, #49164, #49386)\n- Subagents now retain environments that are still starting and receive their configuration or preparation failure. (#49075)\n- Prevented SQLite stalls during connection setup and logging, and surfaced initialization errors instead of masking them as timeouts. (#49032, #49102)\n- Explicit provider model catalogs no longer include unsupported bundled models or reuse stale entries after refresh failures. (#49135)\n\n## Documentation\n\n- Clarified how provider credentials use the configured storage backend and how `env_key` identifies the API-key environment variable. (#49118)\n\n## Chores\n\n- Reduced repeated plugin-loading work by caching parsed manifests and reusing HTTP connections for remote plugin requests. (#49099, #49100)\n- Added background reclamation of unused log database space to reduce disk usage. (#49069)\n\n## Changelog\n\nFull Changelog: https://github.com/openai/codex/compare/rust-v0.159.0...rust-v0.160.0\n\n- #48983 Avoid full metadata rewrites for thread timestamp updates @jif-oai\n- #49000 Isolate the memory startup metadata test from Git enrichment @jif-oai\n- #49019 Use a compatible PowerShell fallback for the Windows MXC sandbox @iceweasel-oai\n- #49028 Use the numeric ioctl value in the macOS sandbox policy @aionescu-oai\n- #49031 Clarify ChatGPT sign-in success copy @bc-openai\n- #49032 Avoid SQLite stalls from connection setup and stderr span logging @jif-oai\n- #49036 Add opt-in conversation history retrieval to Guardian reviews @felixxia-oai\n- #49037 Show the Plan mode cycling hint in the fullscreen status line @fcoury-oai\n- #49038 Preserve encrypted agent messages in Guardian reviews @felixxia-oai\n- #49041 Copy selections within inline code as plain text @fcoury-oai\n- #49043 Update Pro plan display names in the TUI @etraut-openai\n- #49057 Add handoff-aware root context for Guardian reviews @jif-oai\n- #49058 Fix Windows sandbox ACL repair for long runtime paths @darius-oai\n- #49060 Update Guardian messaging snapshots for native agent messages @dkovalenko-oai\n- #49065 Update Guardian handoff snapshot for separate agent messages @cassirer-openai\n- #49067 Keep configuration values out of Windows sandbox policy events @zm-oai\n- #49069 Reclaim unused SQLite log database pages in the background @dkovalenko-oai\n- #49073 Surface realtime voice catalog failures in the TUI @etraut-openai\n- #49074 Propagate Cargo package versions to Bazel Rust targets @tamird\n- #49075 Preserve pending environments when spawning subagents @sayan-oai\n- #49076 Avoid collecting unused Git metadata in skill analytics @tamird\n- #49079 Update and centralize TUI subscription labels @etraut-openai\n- #49082 Skip remote Git discovery for Guardian diff paths @jif-oai\n- #49084 Track app-server running turns incrementally @tamird\n- #49089 Render follow-up directive labels in the TUI and copied responses @etraut-openai\n- #49093 Simplify startup promotions to platform-specific desktop app tips @etraut-openai\n- #49096 Update `h2` from 0.4.16 to 0.4.19 in Cargo and Bazel lockfiles @cassirer-openai\n- #49097 Notify lifecycle extensions of compaction usage limits @xli-oai\n- #49098 Resolve Windows sandbox PowerShell fallbacks on the exec server @zm-oai\n- #49099 Cache parsed plugin manifests across plugin workflows @dkovalenko-oai\n- #49100 Reuse the HTTP connection pool for remote plugin requests @dkovalenko-oai\n- #49102 Preserve SQLite vacuum modes and surface pool initialization errors @bc-openai\n- #49103 Balance Windows Bazel test shards using duration estimates @jgershen-oai\n- #49105 Resume unsent TUI input after reconnecting @etraut-openai\n- #49106 Add history pagination to the agent command center @bc-openai\n- #49112 Add X11 primary selection and middle-click paste support @fcoury-oai\n- #49114 Point remote compaction tests at the mock ChatGPT server @OLI-OAI\n- #49117 Attribute analytics requests to each thread's product SKU @papayo-oai\n- #49118 Correct provider authentication storage documentation @celia-oai\n- #49119 Add recovery guidance to content-filter retries @won-openai\n- #49127 Deduplicate cloud and executor skill listings before budgeting @TAFOYA-OAI\n- #49130 Move content-filter guidance into the shared Responses retry handler @won-openai\n- #49135 Treat explicit provider model catalogs as authoritative @andrewgu-oai\n- #49136 Remove the plus separator after Option symbols in TUI key hints @bc-openai\n- #49138 Expose original error details to turn lifecycle contributors @bryanashley\n- #49144 Preserve server reasoning summary and verbosity settings in the TUI @etraut-openai\n- #49145 Hide reasoning summary settings in `/status` for server connections @etraut-openai\n- #49147 Simplify cloud task base URL normalization @akira-oai\n- #49153 Omit blockquote markers when copying quoted selections in the TUI @bc-openai\n- #49160 Support projectless TUI sessions with workspace defaults @etraut-openai\n- #49161 Honor app-server provider defaults in the TUI @etraut-openai\n- #49164 Suppress Windows console windows for background subprocesses @etraut-openai\n- #49171 Fix model provider lookup for TUI history @etraut-openai\n- #49386 [0.160] Backport remaining Windows console fix to frozen alpha.6 @andrewgu-oai\n- #49763 [0.160] Backport maintenance-line catalog and security reminder updates @andrewgu-oai\n\n\n","body_html":null,"content_hash":"88f2cf6222ddfcc4ac2535d3475c5d7f28fd90f8fe756a3752378f41eeef853f","updated_at":"2026-10-05T08:38:02.977Z"},{"id":"e9cfb8e6-1ec8-4b38-b85f-18c863113f33","source_id":"claude-code","dedupe_key":"claude-code:2.1.287","version":"2.1.287","title":"claude code 2.1.287","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21287","published_at":"2026-10-01T16:59:25.986Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added Claude Mods: plugins may now modify deeper behavior\n- Added You should know, a built-in mod where a side agent watches your back and flags things you or Claude might miss. Turn it on with `/plugin enable cc-plugin-you-should-know@builtin` (for first-party sessions with telemetry on)\n- Added an `n:<text>` filter to the agents view that matches session names and tasks; a filter now shows matches in collapsed sections and Enter opens the first match\n- Added `prompt_text` to the OpenTelemetry `user_prompt` event, a copy of `prompt` for backends that nest dotted keys; drop or mask it wherever you drop or mask `prompt` (anthropics/claude-code#70763)\n- Added URL prompts from MCP servers on the 2025-11-25 protocol, for example to sign in. If a server no longer connects after this update, add \"bareElicitationCapability\": true to its MCP config entry\n- Windows: Added a startup warning when denying the Bash tool also turns off the PowerShell tool, so Claude has no shell tool\n- Self-hosted runner: Added a built-in `gh api` (REST only) for sessions that use Anthropic-managed git on macOS and Linux machines where the GitHub CLI is not installed\n- Fixed fast mode staying off in remote sessions owned by an agent with no user account, even when the organization allows it\n- Fixed Remote Control not receiving messages for minutes at a time when a reconnect request got no response; it now gives up after 30 seconds and retries\n- Fixed hooks configured with `asyncRewake` waking Claude over and over with \"found issues\" notifications when the hook's script file is missing; the broken hook is now reported once\n- Fixed tool heartbeats not reaching SDK hosts while the model's response stream was stalled with no data arriving\n- Fixed Bedrock and Vertex startup model checks ignoring an enforced `availableModels` list, which could collapse `/model` to one Opus row\n- Fixed the Claude in Chrome browser picker showing a JSON parse error when Chrome could not be reached\n- Fixed picking Fable in `/model` on a claude.ai login saving the current version's id, so your saved default now follows the newest Fable like Opus and Sonnet do\n- Fixed switching between Opus 5.5 and Sonnet 5.5 (`/model`, `opusplan`) rewriting earlier MCP tool announcements, which could drop earlier extended thinking\n- Fixed Amazon Bedrock Guardrails blocks that arrive mid-response ending the turn with an API error instead of the guardrail's message when the reply began with thinking\n- Fixed a dangerous `rm` (such as one on `/` or the home directory) losing its always-ask safeguard when the same command also redirected output to a `~` or wildcard path\n- Fixed `claude -p` and SDK sessions repeating a model fallback on every later message after the model was switched while a reply was running\n- Fixed a folder's CLAUDE.md being attached a second time after resuming a session or after a compaction\n- Fixed background sessions that could not be reopened from `claude agents` after the agent exited and removed the worktree the session was started in\n- Fixed `/advisor` pairing checks: Sonnet 5.5 can now advise Opus 4.7 and 4.8, and advisors the API would refuse are flagged up front instead of being silently dropped\n- Fixed Bash permission prompts showing internal parser names such as \"Contains simple_expansion\" instead of a plain explanation\n- Fixed a cause of fullscreen sessions on slow or busy machines exiting with \"Claude Code exited after an unrecoverable interface error\" while a scroll key was held in a long conversation\n- Fixed organization per-tool permission ceilings being silently dropped for an MCP tool named `__proto__`\n- Fixed Claude being told to page large MCP results saved as JSON with Read's offset and limit, which cannot split one long line\n- Fixed the commit attribution reminder being delivered inside a tool result after a compaction\n- Fixed screen reader mode leaving the cursor away from the typed text in search boxes (such as /resume and /permissions) and sign-in code fields\n- Fixed screen reader mode refusing Enter with nothing typed on /rewind's summarize options, whose added context is optional\n- Fixed screen reader mode showing a \"Tab to amend\" hint on approval prompts, where Tab does nothing\n- Fixed screen reader mode listing arrow keys that do nothing in /permissions and /mcp, and saying \"Select with numbers\" in empty menus or while a search box has the keys\n- Fixed screen reader mode leaving out the changed lines in file edit approval prompts and other diffs\n- Fixed screen reader mode sending the `claude --teleport` progress screen, and an MCP form field while it is being checked, to the screen reader again on every spinner frame\n- Fixed `CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS` not removing the structured-output format from session-title and prompt-hook requests, which Bedrock-backed gateways reject\n- Fixed screen reader mode leaving out the top lines of a second approval prompt, a changed /config row or the rejected-plan line when the previous screen was taller than the terminal window\n- Fixed `--include-partial-messages` sending a cut-short reply's `message_stop` late or never, so apps could show the reply as still in progress\n- Fixed `claude agents` sometimes not showing the permission prompt a background session is waiting on\n- Fixed `/ultrareview` giving advice about `.git/info/attributes` when the upload stops on a committed `.gitattributes` it cannot read, such as one saved as UTF-16\n- Fixed `claude remote-control` failing to register behind an HTTP proxy with a misleading \"Check your organization permissions\" error (anthropics/claude-code#97352)\n- Fixed sandboxed Bash commands on Linux inheriting an open handle on the Claude Code executable\n- Fixed the running-tool dot and three spinners still moving with the \"Reduce motion\" setting on, and /rewind's confirm screen updating its \"ago\" time while you type a note\n- Fixed times in `claude agents` changing every second in screen reader mode; they now change at most every 10 seconds\n- Fixed a revoked claude.ai login showing a generic `API Error: 401` instead of \"OAuth token revoked\"; in `-p` mode the error now starts with \"Failed to authenticate\"\n- Fixed `/ultrareview` upload refusals advising you to copy a variable named by a repository's settings file into your own user settings\n- Fixed `--output-format stream-json` and the SDK not streaming the turns of a `context: fork` skill run by typing `/<skill>` as the prompt, as they do for the Skill tool's fork\n- Fixed /feedback and /bug: the pre-filled GitHub issue no longer includes your recent error messages, and the confirmation screen now lists them as part of the report\n- Fixed `claude plugin marketplace add --sparse` and `git-subdir` plugin installs failing with \"transport 'http' not allowed\" when the repository is served over plain http\n- Fixed cloud sessions sometimes losing the earlier conversation when the session restarted while it was being compacted\n- Fixed a plugin reload that overlapped the startup `--plugin-url` download corrupting the session's cached copy of the plugin archive\n- Fixed `/desktop` quoting partial output when opening Claude Desktop timed out or printed too much output; the error now names the cause\n- Fixed an MCP connector tool call occasionally running twice, or the connector's calls failing until restart, when its server changed which MCP protocol version it supports\n- Fixed SessionStart hooks from synced plugins not running in new cloud sessions\n- Fixed the transcript's \"N hooks ran\" summary and the verbose debug log's matched-hooks count including Claude Code's internal callbacks, so one configured hook no longer shows as two\n- Fixed files Claude sends from cloud and Remote Control sessions failing when the upload finished just after the 30-second timeout; it now waits 35 seconds\n- Fixed repositories added mid-session in cloud and SDK sessions not loading their skills and plugins, and loading CLAUDE.md late, after Claude changed directory\n- Fixed PNG, JPEG and WebP images over 8,000 pixels on a side failing to send from a remote session; Claude now sends a scaled-down copy\n- Fixed messages sent from the Claude apps with 17 to 20 attached files delivering only the first 16\n- Fixed headless sessions reporting an MCP server as needing authentication after one refused call, even though later calls succeed\n- macOS: Fixed Remote Control sessions started with `claude remote-control` stopping mid-turn when the Mac went to idle sleep\n- Windows: Fixed interactive `claude` hanging or crashing with \"Raw mode is not supported\" when its input is piped or redirected; it now says why and exits (use `-p` for piped input)\n- Bedrock, Vertex, Mantle: Fixed model availability checks under `CLAUDE_CODE_SKIP_*_AUTH` sending a different `Authorization` header than real requests when `ANTHROPIC_CUSTOM_HEADERS` repeats it\n- Improved `/config`: settings that cycle show ‹ › and step both ways with ←/→, narrow terminals stack each value under its label, and PgUp/PgDn page the list\n- Improved plugin marketplace errors to say in plain words why a marketplace was ignored or refused, and what to do\n- Improved plugin listings to note when a plugin's dependencies were not installed, and updating a plugin now retries an install that did not finish\n- Improved the Claude apps gateway's error when Amazon Bedrock rejects a model ID: developers now see which model is unavailable, and the gateway log names the ID that was sent\n- Improved SDK sessions so a message sent with priority \"now\" no longer cancels a running web fetch or web search; it keeps loading in the background\n- Improved `/memory`: the left and right arrow keys now flip its on/off settings, such as Auto-memory\n- Improved `/skill` names typed mid-message: Claude is now told they are skills, including `disable-model-invocation` ones\n- Improved the contrast of the prompt input border in light themes and of the ❯ before your earlier messages\n- Improved delivery of files Claude sends from cloud sessions and Remote Control: an upload that fails on a timeout, a network error or a 502, 503 or 504 is now retried once\n- Improved what Claude says when a file cannot be sent for a reason that may be temporary: it now mentions that you can ask for the file again in a few minutes\n- Improved the prompt for a held message from another session to show the message between dashed lines, matching other permission prompts\n- Improved MCP and other tool permission prompts to show the tool call between dashed lines, matching file edit prompts\n- Improved MCP startup in headless mode: a remote server whose first connect fails transiently is now retried without waiting for the slowest server to finish connecting\n- Improved files Claude sends from a remote session: large files now stream from disk instead of being read into memory, and a file over the size limit is refused with the server's limit named\n- Improved the explanation Claude gives when the server refuses a file it sends from a Remote Control or cloud session, such as an oversized image\n- Improved handling of large MCP tool results: less memory, smaller session files, and no extra upload to count tokens for results far over the limit\n- Windows: Improved Bash tool speed by removing a subshell that ran before every command\n- Changed a shell write through a repo-committed symlink onto a sensitive file or out of the working tree to name where it lands and wait for a person, on lines with a `~` target too\n- Changed Opus 4.7+ and Fable to use a 1M context window by default on Bedrock, Vertex, Foundry and the Claude apps gateway, with no `[1m]` suffix (`CLAUDE_CODE_DISABLE_1M_CONTEXT=1` keeps 200K)\n- Changed replies from `claude agents` to arrive as queued messages; slash commands other than `/stop` sent while a turn is running now run when it ends\n- Changed whole-tool `Bash` allow rules and allowing hooks to prompt for, not run, shell writes to files Claude Code's file tools refuse outright (the Anthropic profile store, the host credentials file)\n- Changed right-click paste on Windows and Linux, and middle-click paste on Linux, to happen when the button is released; moving the pointer away before releasing cancels it\n- Changed MCP server `alwaysLoad: false` to defer all of that server's tools behind tool search\n- Changed screen reader mode to write new or changed lines without first pausing with the cursor at the start of the line; set `CLAUDE_AX_PREPARK_MS=50` to restore the pause\n- Changed automatic model switches after a flagged message to keep your current effort level instead of the new model's default\n- Changed waiting permission prompts to show oldest first, so a new prompt no longer covers the one you're reading (prompts with a countdown still open on top)\n- [VSCode] Added \"Run in background\" to a running command or sub-agent, to move it to the background and keep working\n- [VSCode] Added the output of background shells and Monitors to their cards in the agent map\n- [VSCode] Fixed settings dialogs blaming a timeout when Claude Code's reply was too large to confirm a save\n- [VSCode] Fixed reopening a cloud session that the side bar already brought to this machine opening it again in a new tab; the side bar is shown instead\n- [VSCode] Fixed the side bar's Web tab not listing cloud sessions started after the window loaded; a failed load now says \"Remote server is not connected\" instead of \"No web sessions yet\"\n- [VSCode] Fixed a tab restored after a reload starting a second Claude process on a conversation the side bar already has open; it now shows the \"still open somewhere else\" notice\n- [VSCode] Fixed tool-row file links, session-list links and two hints showing in plain text\n- [VSCode] Fixed a background agent's still-running command showing as failed once the main turn ended\n- [VSCode] Fixed a user's own `/usage` or `/context` command opening the extension's dialog instead of running when picked from the command menu\n- [VSCode] Fixed file links in the plan preview tab doing nothing when clicked; they now open the file like links in chat replies\n- [VSCode] Fixed opening a tool's input or output in an editor tab failing with \"Timeout waiting after 1000ms\" on remote hosts such as WSL when the tab is slow to appear\n- [VSCode] Improved the Manage plugins dialog: a failed marketplace add, remove or refresh now says what went wrong\n- [VSCode] Changed the Claude in Chrome \"Enabled by default\" switch to also connect the editor's own sessions, which still ask before browser actions\n- [Cloud sessions] Fixed occasional failures to fetch from or push to GitHub when GitHub briefly refused a newly issued access token\n- [Claude Tag] Fixed Claude posting a failure warning, such as a spend limit notice, in a Slack thread when a background event like GitHub activity woke it and nobody was waiting on a reply\n- [Claude Tag] Fixed Claude Tag's spend limits page in admin settings leaving out recently created and private channels in organizations with many channels\n- [Claude Tag] Improved Claude's task list in long Slack threads: background work no longer reposts it as a new message on its own, so people following the thread aren't notified\n- [Code Review] Fixed finding comments and their \"Why this was flagged\" text stopping mid-sentence; they now end on a complete sentence\n- [Code Review] Fixed Code Review skipping a pull request after a new push when its review had failed twice on the previous commit; it now reviews the latest commit\n- [Code Review] Improved the failed-review card on a pull request whose conversation is locked: it now says the lock blocked the review and that nothing was posted or charged","body_html":null,"content_hash":"a2e1e6d86cf8d5fb4d01bad2068b92bf124b3d75398518511bc814e5075c833a","updated_at":"2026-10-05T18:14:33.808Z"},{"id":"aebf0af0-6d88-4d8d-af52-6e69e5a03324","source_id":"codex","dedupe_key":"codex:rust-v0.159.3","version":"0.159.3","title":"0.159.3","url":"https://github.com/openai/codex/releases/tag/rust-v0.159.3","published_at":"2026-09-30T22:57:34Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:38:02.977Z","body_md":"## New Features\n\n- Eligible local sessions signed in with ChatGPT can now show optional reminders to complete account security setup. (#49744)\n\n## Changelog\n\nFull Changelog: https://github.com/openai/codex/compare/rust-v0.159.2...rust-v0.159.3\n\n- #49744 [0.159] Backport account security setup reminders for 0.159.3 @andrewgu-oai\n\n\n","body_html":null,"content_hash":"8bde9ef99aa59ca1e960bb01ec7d2cbac32d6ed82369e4b74dec7490ee60277b","updated_at":"2026-10-05T08:38:02.977Z"},{"id":"ff5c8db3-f048-4fd4-8951-3aa49897e93a","source_id":"claude-code","dedupe_key":"claude-code:2.1.286","version":"2.1.286","title":"claude code 2.1.286","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21286","published_at":"2026-09-30T17:14:38.859Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added a count such as \"2 of 5\" to the permission prompt when several permission requests stack up\n- Added mouse support for the \"N more\" rows of lists in fullscreen mode: click one to jump to that end of the list, with hover and pressed states\n- Fixed several Claude Code processes and IDE extensions each opening a login browser when gcpAuthRefresh or awsAuthRefresh credentials expire\n- Fixed `claude --resume` and `--continue` sometimes losing every turn after a batch of parallel tool calls when the earlier session crashed or was killed\n- Fixed API 400 errors after a tool or hook returned an object, number or boolean instead of text, including in resumed sessions\n- Fixed cloud sessions with very large histories never waking up because the container was stopped while the transcript was still loading\n- Fixed the Claude apps gateway's spend meter pricing 1-hour prompt cache writes at the cheaper 5-minute rate, and counting only the first model call's input tokens on streamed turns that run a server-side tool such as web search\n- Fixed macOS sessions still showing \"Not logged in\" or \"Login expired\" after `/login` succeeds in another Claude Code window when a leftover `~/.claude/.credentials.json` exists\n- Fixed every turn failing when the Anthropic API refuses the model your default or a model alias resolves to: Claude Code now retries once on the previous model of the same tier\n- Fixed Remote Control sessions (including `claude remote-control`) staying connected after your organization's policy turns Remote Control off; they now disconnect with a notice\n- Fixed refusal and `--fallback-model` retries failing when the fallback model can't run fast; they now run at standard speed, with a one-time notice in interactive sessions\n- Fixed headless sessions repeating the \"MCP servers require authentication\" reminder after a successful re-authentication when the MCP discovery cache is enabled\n- Fixed `claude auth status` reporting a Console sign-in's stored API key as `claude.ai`; it now reports `api_key`, and the VS Code extension treats that session as an API key session\n- Fixed `/status` listing an Anthropic profile beside an API key as if both were in effect; the profile is now marked as not in use\n- Fixed Claude not being told when a file attached to a message sent over Remote Control did not arrive, and a file sometimes getting only 10 seconds for its last download try\n- Fixed a Remote Control message that arrived while Claude Code was exiting being marked delivered and then never answered; it now stays queued for the session's next run\n- Fixed MCP error messages showing a credential's value when \"Bearer\" or \"Basic\" came before its key name\n- Fixed percent-encoded Bearer tokens being only partly masked in error messages\n- Fixed redacted logs and transcripts showing a secret whose key name has an invisible character inside, such as a zero-width space\n- Fixed logs and transcripts showing part of a URL password that contains punctuation such as `)`, quotes, `]`, `&` or a second `@`, or that runs past a `/` to a bracketed host such as `[::1]` in an ssh URL\n- Fixed the session transcript in the zip that `/feedback` saves to disk containing invalid JSON lines after secret redaction\n- Fixed MCP connectors listing no tools for up to a day after their server dropped the older MCP handshake\n- Fixed a repeat MCP sign-in request from Claude replacing the pending sign-in link, which could stop that link from working\n- Fixed `/usage` not crediting an MCP server for a tool call made while that server was still connecting or had only just connected, such as right after a restart\n- Fixed plugins enabled on claude.ai occasionally going missing from Claude Code for a session after a transient server error\n- Fixed a message typed into a running subagent showing twice in its transcript after the subagent read it\n- Fixed subagent hand-back messages showing a raw task id instead of the agent's name when the subagent had no registered name\n- Fixed foreground subagents sometimes missing the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) in sessions that have them enabled\n- Fixed subagents spawned with worktree isolation loading the project CLAUDE.md and its imports a second time from the worktree copy on their first file read\n- Fixed Workflow tool subagents being restarted from their original prompt when a connection stalled for a few minutes mid-response\n- Fixed `/compact`, `/clear`, and `/rewind` typed while viewing a background agent's or teammate's transcript silently acting on the main conversation: a dialog now names the target and asks first\n- Fixed background jobs showing done while waiting for your approval\n- Fixed the commit attribution reminder being re-sent inside tool output when a model fallback lasts only one turn\n- Fixed a click on the space between words of a collapsed row (such as \"Thought for 4s\") highlighting the row without expanding it in fullscreen mode\n- Fixed a row with no details, such as an action row with a long name, pushing every other row's details to the right in list screens\n- Fixed files with very long names not reaching a cloud session when attached to it\n- Fixed plugin errors for a marketplace Claude Code refuses to load: they now say why and how to fix it instead of \"not found\"\n- Fixed `/plugin`'s Discover tab showing a marketplace name unquoted in its \"Checking … for new plugins\" line when its rows already show that name in quotes\n- Improved commit guidance: when your project or user skills include one named `verify`, Claude is now told to run it right before committing, except for docs-only and tests-only commits\n- Improved send now (ctrl+enter) in a subagent's view: it now moves the subagent's running command to the background so your message is read right away\n- Improved replies from background agents to your messages so they no longer open with a separate recap of what you said\n- Improved claude.ai artifact link reads: WebFetch now asks the same questions as the Artifact tool's read (no artifact prompt while the session's network access is on, one per artifact while it is off), and an auto-mode yes no longer counts where only you can answer\n- Improved fetch, skill, file read, sandbox network, Claude in Chrome, workflow script and notebook edit permission prompts to match the look of file edit prompts\n- Improved Bash, PowerShell and Monitor permission prompts to show the command between dashed lines, matching file edit prompts\n- Improved list scrollbars in fullscreen mode: in most lists the bar no longer shifts as the \"N more\" rows come and go, and it now has ↑/↓ arrows you can click or hold to scroll\n- Improved the external editor (Ctrl+G): editors that take a line number now open on the line your cursor is on in the prompt\n- Improved slash command suggestion responsiveness while typing when many skills or plugin commands are installed; command descriptions now match by word prefix\n- Improved the output style picker: it now opens on your current style instead of Default, with each style's description on the line under its name; number keys no longer pick a style\n- Improved `/hooks`: the closing line of a hook's detail screen now says \"this hook\" instead of \"it\"\n- Improved the model fallback notice and the autocompact-thrashing error to say when a fallback dropped the context window from 1M to 200K tokens\n- Improved responsiveness of SDK and `-p` sessions when a host re-sends an MCP server enable for a server that is already connected\n- Improved the protocol page a Claude apps gateway serves at `/protocol`: it now says not to reject unknown input and matches what Claude Code sends today\n- Changed prompts sent while nothing is running or queued to show in the normal text color right away instead of gray\n- Changed how failed API requests are retried: one limit now covers a whole model call, so with the default retry settings a failing call sends at most 14 requests\n- Changed `--bare` to connect only the MCP servers named on the command line, send the model no system reminders, and start no background tasks; under `--bare`, a shell command that reaches its timeout now stops instead of moving to the background\n- Changed the send-now key (ctrl+enter) to move a skill's own shell command to the background instead of ending it\n- Changed the WebFetch error for a rate-limited domain safety check to tell Claude not to retry it in a loop\n- Changed plugin installs to refuse npm sources that are git repositories or folders, and to install plugin dependencies only from registry packages\n- Changed list screens (`/artifacts`, `/mcp`, `/skills`, `/hooks` and others) to always line up each row's details in one column after the names\n- Changed the overflow rows of lists to read \"↑ N more\" / \"↓ N more\" instead of \"N more above\" / \"N more below\"\n- Changed `/hooks` to open on one list of your configured hooks grouped by event, so viewing a hook takes one Enter instead of three\n- Changed the theme picker to a scrolling list that fits your terminal instead of pushing the preview off screen; number keys no longer pick a theme\n- Changed `/exit`'s Remove worktree to run after Claude Code stops the servers and shells it started there, which on Windows could keep the folder from being deleted\n- Changed the `claude-api` skill's Managed Agents examples to create environments with limited networking\n- Removed the browser link from `/ultrareview` and `claude ultrareview` output\n- Windows: Fixed `claude --bg` and the agents view refusing a folder that `claude` already trusts when its trust record was saved with different letter case\n- [VSCode] Added bookmarks: save Claude's responses and keep them in view in a Bookmarks side panel\n- [VSCode] Added the questions Claude asks and your answers to the conversation: after you answer a question card, a Questions row shows each question with your picks\n- [VSCode] Added option previews to question cards in the chat panel: the highlighted choice's mockup or snippet shows beside or under the options\n- [VSCode] Added rows under a message that open to the terminal output, browser tab, browser instructions and selected code sent with it\n- [VSCode] Fixed a second copy of a conversation opening in a tab when it was already open in the side bar; the side bar now switches to it\n- [VSCode] Fixed settings dialogs reporting a failed save, without re-checking, when Claude Code printed more than 1 MB of output\n- [VSCode] Fixed an endless \"Teleporting session…\" spinner when the extension stops responding\n- [VSCode] Improved the Manage plugins dialog: it says when a turned-off plugin is still on because of other settings, and explains a plugin folder clash\n- [VSCode] Changed Stop and Escape to end only the current turn; background agents keep running and can be stopped one by one from the agent map\n- [VSCode] Changed the \"✻ Claude Code\" status bar item to show in every window, so you can open Claude when no file is open\n- [Cloud sessions] Fixed an answered question card or approved tool call getting no reply when the session had gone idle after Claude sent a message\n- [Cloud sessions] Fixed clearing an organization environment's setup script in admin settings leaving new cloud sessions still running the old script\n- [Cloud sessions] Fixed the Runner actions menu on the self-hosted environments admin page closing on its own a few seconds after it opened\n- [Cloud sessions] Fixed routine runs whose cloud session never started showing as Succeeded in the Runs pane, the routine's page and the sidebar; they now show as Failed\n- [Cloud sessions] Fixed clicking an audio or video file in a cloud session's Outputs card opening an empty file search instead of playing the file\n- [Cloud sessions] Changed a routine's page to read \"Due\" with the scheduled time, instead of a next run time in the past, when a scheduled run is late and hasn't started\n- [Claude Tag] Added an Add channel button to Claude Tag's spend limits page in admin settings, so a limit can be set on any channel, including a private one, from its channel ID or Slack link\n- [Claude Tag] Fixed memory recall finding nothing in organizations that cannot use the default Sonnet model\n- [Claude Tag] Fixed a Slack channel losing its Claude settings when an Enterprise Grid admin moves it to another workspace and the first post afterward doesn't mention Claude\n- [Claude Tag] Fixed Claude in a Slack thread occasionally starting over on a fresh machine, losing work it hadn't pushed, when your reply answered a question it had just asked\n- [Claude Tag] Fixed public channel names on Claude Tag's spend limits page in admin settings showing as raw Slack IDs in larger organizations\n- [Claude Tag] Improved the titles of sessions started from Slack as shown on claude.ai: they now read as the words you typed, without Slack user IDs or escape codes","body_html":null,"content_hash":"75ee5768855cb6890da200ce2b42c128f47678689243cdaa137fb3542fa2df03","updated_at":"2026-10-05T18:14:33.808Z"},{"id":"d219601d-48c8-48bd-a0d6-ceadeb98d2bf","source_id":"codex","dedupe_key":"codex:rust-v0.159.2","version":"0.159.2","title":"0.159.2","url":"https://github.com/openai/codex/releases/tag/rust-v0.159.2","published_at":"2026-09-29T23:57:16Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:38:02.977Z","body_md":"## Bug Fixes\n\n- Suppressed console windows flashing on Windows when Codex launches background processes and sandboxed commands. (#49385)\n\n## Changelog\n\nFull Changelog: https://github.com/openai/codex/compare/rust-v0.159.1...rust-v0.159.2\n\n- #49385 [0.159] Backport Windows console suppression for 0.159.2 @andrewgu-oai\n\n\n","body_html":null,"content_hash":"8c620a228e791958d88a8c6823173d35b56c23ab825e25caa2e9c3e3ec280f40","updated_at":"2026-10-05T08:38:02.977Z"},{"id":"e0565a43-a4fc-4395-ab8a-bdc50a047889","source_id":"codex","dedupe_key":"codex:rust-v0.159.1","version":"0.159.1","title":"0.159.1","url":"https://github.com/openai/codex/releases/tag/rust-v0.159.1","published_at":"2026-09-29T20:32:34Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:38:02.977Z","body_md":"## New Features\n- Added GPT-6.1 Sol as the default model in the bundled catalog and Amazon Bedrock Mantle and Runtime catalogs. (#49323, #49342)\n\n## Changelog\n\nFull Changelog: https://github.com/openai/codex/compare/rust-v0.159.0...rust-v0.159.1\n\n- #49323 [0.159] Prepare 0.159.1 release backports @andrewgu-oai\n- #49342 [0.159] Backport GPT-6.1 Sol Bedrock catalogs @celia-oai\n\n\n","body_html":null,"content_hash":"9115cfb37642f108815cc0bba8e1b6a3827715cb415c7e243049bc9472c15874","updated_at":"2026-10-05T08:38:02.977Z"},{"id":"d8cc7638-03a1-42a4-8b6a-35485cf3b9d6","source_id":"claude-code","dedupe_key":"claude-code:2.1.285","version":"2.1.285","title":"claude code 2.1.285","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21285","published_at":"2026-09-29T17:32:09.173Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added `CLAUDE_CODE_DISABLE_WEB_FETCH` environment variable to turn off the WebFetch tool\n- Added `claude --desktop` to open the Claude desktop app on the current directory, or on a session with `--continue` / `--resume <id>`\n- Added `claude plugin configure <plugin>` to show a plugin's options and which are unset, or save new values read from stdin with `--values-stdin`\n- Added `<server>.<key>=<value>` to `claude plugin install --config`, so a bundled `.mcpb` MCP server's own settings can be set at install time and it starts without visiting `/plugin` → Configure\n- Added `allowedProviders` managed setting to limit which API providers a machine may use (Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway)\n- Added `CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES` environment variable to cap re-sends of a non-streaming fallback request that timed out\n- Fixed `claude -p` with `CLAUDE_CODE_FORK_SUBAGENT=1`: a subagent's own Agent call now runs in the foreground, so the subagent gets the child's result\n- Fixed plugin and marketplace installs and updates over SSH ignoring the ssh program set in `GIT_SSH` or in your git config's `core.sshCommand`\n- Fixed Claude Code refusing to start when the OS denies reading the managed settings file; it now warns and starts without that file's policies. Other read errors and unparseable files stop every session\n- Fixed cloud sessions that restarted after their conversation was compacted refusing the next update to an artifact the session had already read or published\n- Fixed `claude plugin disable` and `enable` with a full `name@marketplace` id changing a settings entry in another letter case instead of the installed plugin's own\n- Fixed files attached to a message sent over Remote Control being left out after a single failed download; a network error, timeout or server error is now retried up to twice\n- Fixed switching models mid-session with a `set_model` request (such as the Agent SDK's `setModel`) leaving the new model on the built-in output-token limit and auto-compact window until restart\n- Fixed redacted logs and transcripts showing part of a URL password that contains `@`, or all of it when the URL writes its `@` as `%40`\n- Fixed SSH passphrase and new-host prompts from worktree and `/teleport` fetches taking over the terminal; these fetches now fail fast instead of asking\n- Fixed switching off an MCP server added mid-session in SDK and `-p` sessions leaving its tools available\n- Fixed `claude -p --permission-prompt-tool`: a background subagent's permission request now goes to the prompt tool instead of being auto-denied\n- Fixed `claude mcp list` and `claude mcp get`, and the not-found error of `claude mcp remove`, `login` and `logout`, printing line breaks and terminal escape sequences from MCP server names and values\n- Fixed sandbox auto-allow asking for approval on every run of many inline scripts (`python3 -c`, `node -e`) just because they contain `=`\n- Fixed fork subagents not keeping the session's plan mode or `dontAsk` mode: a fork now runs under its parent's permission mode and cannot exit plan mode\n- Fixed `claude remote-control --help` saying `--[no-]chrome` defaults to the machine's `/chrome` setting; spawned sessions keep Claude in Chrome off unless `--chrome` is passed\n- Fixed background subagents in auto mode prompting a second, redundant reply after each report\n- Fixed cloud session creation and `/remote-env` reading only the newest 20 of an account's environments\n- Fixed Remote Control marking a message as read as soon as it arrived instead of when Claude started on it, and losing a message still queued when the terminal quit (it now arrives on the next resume)\n- Fixed installing a plugin with `claude plugin install` or `/plugin` putting it into an installed plugin's cache or data folder when their ids differ only in `.`, `-`, `@` or (macOS, Windows) capitals; the install is now refused\n- Fixed hooks and SDK permission callbacks seeing a missing or outdated plan on ExitPlanMode when the plan was written in the same response\n- Fixed the first reply in cloud sessions arriving tens of milliseconds late, a regression in 2.1.283\n- Fixed sessions that authenticate with `ANTHROPIC_AUTH_TOKEN` against the Anthropic API never loading the organization's policy\n- Fixed a failed `agent()`, `parallel()` or `pipeline()` call that a workflow script awaits later, or not at all, being treated as an unhandled promise rejection, which could end a background session\n- Fixed synchronous hooks hanging Claude Code while a background process the hook started (for example `some-daemon &`) kept its output open; the hook now finishes shortly after its own process exits\n- Fixed WebFetch reporting a rate-limited domain safety check as a network or enterprise policy block\n- Fixed the fullscreen ctrl+o transcript freezing briefly when opened on turns with hundreds of file reads or searches; tool calls still running when the transcript opens now show their results when they finish\n- Fixed Amazon Bedrock mid-stream `modelTimeoutException` and `serviceUnavailableException` errors showing a raw JSON body instead of the error message\n- Fixed `/autofix-pr` and `/schedule` saying the Claude GitHub App is not installed on a repository whose install status had not been checked yet\n- Fixed dismissing a row (x) in `/artifacts` unlinking its file from the artifact, so publishing the same file again created a new artifact instead of updating it\n- Fixed Artifact tool publishes after a conversation rewind (Esc Esc) overwriting a file's newer content that Claude had read only in the rewound turns; the publish is now refused until Claude re-reads the file\n- Fixed an `Artifact` allow rule (\"don't ask again\") letting the Artifact tool publish a file outside the working directories without asking; add the file's folder with `--add-dir` for the rule to cover it\n- Fixed `/cost` and SDK `modelUsage` reporting a turn under the wrong model when the server answered a refusal with a different fallback model than the client expected\n- Fixed the Artifact tool so that publishing a page no longer lets Claude overwrite its source file without re-reading it when Claude's earlier read was cut short or the file had changed since\n- Fixed auto mode skipping its classifier for Artifact tool asset uploads and reads of someone else's artifact when you had approved that artifact earlier in another permission mode\n- Fixed a misleading \"core.worktree is set\" error from `/ultrareview` when the project folder briefly could not be read\n- Fixed `/ultrareview` on macOS and Linux failing to upload the working tree from a git worktree whose per-worktree config sets `core.longpaths`\n- Fixed the Artifact tool sometimes reporting a publish as a conflict with another session after retrying a temporary server error, when the first attempt had actually succeeded\n- Fixed `/ultrareview` uploads including uncommitted changes to credential files whose name has a colon before the extension, such as `server:8443.key`\n- Fixed a rare auth failure when two sessions recover a login refresh lock left by a crashed process at the same time\n- Fixed the PowerShell tool's permission check skipping deny and ask rules, and caching that failure for later checks, when its command parser failed to start (for example when the machine was out of memory)\n- Fixed `/ultrareview` uploads on macOS and Linux running slowly on some unusual file names, and their credential-file check missing file or folder names with many backup or editor marks\n- Fixed a cancelled shell command or hook still starting, and running to its end, when the cancel arrived while it was being set up\n- Fixed vim mode: after editing in the external editor (Ctrl+G), `x` or `r` in NORMAL mode no longer breaks a pasted-text placeholder at the end of the prompt\n- Fixed responses blocked by the API's output content filter being re-sent and retried, sometimes for minutes, instead of showing the filter's error right away\n- Fixed plugins silently skipping a bundled `.mcpb` MCP server that still needs configuration: `/plugin`, the install message and `claude plugin install` now say so and point to Configure\n- Fixed compacting or resuming a session failing, opening without its history, or crashing when its saved transcript holds a compaction marker or loop wakeup entry with missing or malformed fields\n- WSL: Fixed `/ultrareview` refusing to upload a checkout on a Linux volume when a changed file's name has a colon or ends in a dot or space\n- Fixed `CLAUDE_CODE_RESUME_INTERRUPTED_TURN` re-running a turn that had ended at `--max-turns`\n- Fixed sign-in that could wait forever after the browser showed success\n- Windows: Fixed `/ultrareview` uploading a linked worktree of a repository rooted at your home folder in some cases\n- Fixed cloud sessions reporting the uploads folder as missing before any file had been uploaded\n- Fixed a reply sent from `claude agents` to a background session waiting on a permission prompt sometimes approving the pending command\n- Fixed `claude attach`, `logs`, `stop`, `respawn` and `rm` starting a new session with the command name as its prompt when options came before it, such as from a shell alias\n- Fixed `claude mcp list` leaving out WebSocket (`ws`) MCP servers; each is now listed with its URL and health status\n- Fixed `claude mcp get` showing no Type, Command, Args, or Environment for stdio servers whose config entry omits the `type` field\n- Fixed `.claude/settings.local.json` allow rules being held back outside a git repository when git's trace2 output is configured\n- Fixed the `/claude-api` eval runner scaffold and report builder writing through a symlink or hard link planted at an output file\n- Fixed the `/claude-api` eval runner scaffold counting responses cut off at `max_tokens` in the score averages; they are now marked truncated and counted separately\n- Fixed `&nbsp;` showing as literal text in the terminal when a reply uses it to indent text, such as row labels in a markdown table\n- Fixed a brief freeze (up to a second) partway through long sessions outside fullscreen mode, which came back after `/clear` or `/compact`\n- Fixed an approved Edit never going through when its target is a device, such as a file symlinked to /dev/null, and the approval came from the IDE diff view or changed the edit\n- Fixed a failing API request being retried up to 21 times when streaming kept failing; the non-streaming fallback now shares the request's retry budget instead of getting a fresh set of retries\n- Improved Claude in Chrome: the native host now reports your computer's name, so connected browsers can be labeled by computer instead of \"Browser 1\" / \"Browser 2\"\n- Improved Bedrock and Vertex AI sessions to switch to an older available model of the same tier, instead of failing, when an admin removes access to the default model; session titles and summaries now fall back with it\n- Improved plugin marketplace errors to name why a git address is refused instead of citing enterprise policy\n- Improved validation of git URLs for plugins, marketplaces and the current repository's remote\n- Improved Artifact tool results: they now suggest publishing in the same step as writing or editing the page, which can save a round trip\n- Improved Remote Control: a `/btw` side question asked of a session hosted by an app such as Claude Desktop now sees the turn in progress, not only the last finished one\n- Improved pictures Claude sends as BMP, HEIC, HEIF, AVIF or TIFF files: the Claude apps now show a preview where Claude Code can convert them\n- Improved subagents in auto mode: a subagent's run now ends as soon as it hands its report back to its caller, instead of taking extra turns that reach no one\n- Improved Bedrock and Vertex start-up model checks: models your account cannot use are now remembered for up to a day instead of being re-checked on every launch\n- Improved Artifact tool publish results to use fewer tokens: the note on updating an artifact is shorter, and where to find your artifacts is no longer repeated after every publish\n- Improved SDK liveness during a non-streaming fallback request: with partial messages on, a `ping` stream event is now sent every 30 seconds on the Anthropic API, Claude Platform on AWS and gateways\n- Improved `/resume` and `claude --resume` on a session that is running in the background: they now open that session instead of refusing, and a prompt given with `claude --resume <id> \"prompt\"` is sent to it as its next turn\n- Improved per-turn performance when many permission deny rules and MCP tools are configured\n- Improved responsiveness when leaving the ctrl+o transcript view in long sessions when fullscreen rendering is off\n- Improved Bedrock, Vertex and Mantle start-up model checks to send the same User-Agent, x-app and session ID headers as regular requests\n- Changed MCP tools so a tool that sets its own `_meta['anthropic/alwaysLoad']` to false stays deferred when its `--mcp-config`, Agent SDK or plugin server is set to `alwaysLoad`\n- Changed background Bash and PowerShell commands to stop after a time limit (their `timeout` with `run_in_background`, default 30 min, max 2 h); Claude is notified when one is stopped\n- Changed Code Review's pull request reviews and `/ultrareview` to run when `disableWorkflows` is on, unless the machine running the review has it set by its own administrator (MDM or the managed-settings file)\n- Changed sessions behind a custom `ANTHROPIC_BASE_URL` to use the 1M context window of models that have one (Opus 4.7+, Sonnet 5+, Fable); run `/autocompact 200k` if your gateway stops at 200K\n- Changed Team and Enterprise sessions, and sessions whose sign-in plan Claude Code can't determine, to withhold WebFetch until the organization policy loads if it couldn't be loaded at startup\n- Changed /memory so that Auto-memory can no longer be turned on from a background session or from a session one of Claude Code's own tools started; turning it off there still works\n- Changed the one-time offer to make auto mode your default permission mode to also show on third-party providers and with telemetry off, when your user settings default to another mode\n- Changed `claude -p` and Python Agent SDK sessions on third-party providers or with telemetry off to start in auto mode when no permission mode is configured, like interactive sessions; `--permission-mode` still overrides it\n- Changed Bedrock, Mantle and Claude Platform on AWS requests to a base URL with a non-default port to include the port in the SigV4-signed Host header\n- Changed the MCP server name `widgets` to be reserved in cloud sessions and on self-hosted runners: your own server under it, or a close spelling such as `widgets_`, no longer loads, so rename it\n- Changed `/ultrareview` on macOS and Linux to leave symbolic refs out when uploading a local checkout; a checkout whose current branch is a symbolic ref is now refused with an explanation\n- Windows: Changed project and local settings `env` to no longer set `ALLUSERSPROFILE`, `SystemDrive`, or the `CommonProgramFiles` variables; set them in user or managed settings instead\n- Changed `/tasks` to fold background work Claude Code runs for itself under one \"System tasks\" row; press Enter on it to show those tasks\n- Changed `/ultrareview` on macOS and Linux to require git 2.31 or newer to upload a local repository; checkouts made with `--separate-git-dir` are now refused instead of being uploaded with an older method\n- Changed `/ultrareview` uploads on macOS and Linux to send a partial clone as a working-tree snapshot on git 2.31 or newer, instead of falling back or refusing when git's version looked too old\n- Changed `/ultrareview` uploads on macOS and Linux to refuse, instead of fetching, a partial clone missing some of its working tree's files on older git versions; a clone made without `--filter` uploads\n- Changed Bedrock, Vertex and Mantle start-up model checks to identify themselves as Claude Code, like other Claude Code requests\n- Changed `claude mcp get` to hide the command, arguments, and environment values of stdio MCP servers provided by plugins; variable names are still shown\n- Changed `/claude-api` so it can no longer be run from Remote Control clients\n- Changed `/config chrome=true` to direct you to the /config panel instead of enabling Claude in Chrome by default; `/config chrome=false` still turns it off when it was on\n- Changed sandbox settings so project settings cannot widen or turn off an admin-required sandbox, replace the proxy behind a managed deny list, extend a strict allowlist, or reopen managed read-denies\n- [VSCode] Added a note under a restored tab's last message when a window reload interrupted it and no reply will follow\n- [VSCode] Added a plugin options form to Manage plugins: installing a plugin that has options asks for the unset ones, and a gear on its row changes them later\n- [VSCode] Added an on-demand diagnostics tool so Claude in the panel can read the Problems panel's current errors and warnings at any time, not only right after it edits a file\n- [VSCode] Fixed pressing Enter after typing a slash command running an unrelated menu item picked by fuzzy match, or doing nothing\n- [VSCode] Fixed an open agent transcript losing the agent's newer messages during a long session\n- [VSCode] Fixed a message that quotes a Claude Code or IDE tag losing the rest of its text in the chat\n- [VSCode] Fixed a message sent while Claude was working disappearing from the conversation after the session was reopened\n- [VSCode] Fixed the session list's Web tab showing the previous account's sessions after an account switch\n- [VSCode] Fixed restored tabs re-running an interrupted turn when VS Code was started with `CLAUDE_CODE_RESUME_INTERRUPTED_TURN` set, even with Continue After Reload off\n- [VSCode] Fixed Escape stopping the running turn instead of closing the command menu after clicking one of its rows\n- [VSCode] Fixed opening Past conversations replacing a live conversation with its saved copy\n- [VSCode] Fixed a Claude tab reloaded after an extension restart staying blank instead of saying how to recover\n- [VSCode] Fixed opening a conversation that is already open in another window or app starting a second copy of it without warning; it now asks first\n- [VSCode] Fixed a hook's reason for blocking or stopping a prompt disappearing after a window reload\n- [VSCode] Fixed tabs stuck on a conversation that can't be resumed: the error now says so and offers to start a new conversation\n- [VSCode] Fixed every file Read, Write and Edit stalling for ten minutes and then being skipped when the editor stops responding to the extension's automatic save before the tool runs\n- [VSCode] Fixed the agent map labeling a sub-agent with the session's model instead of the model it actually ran on (e.g. under `CLAUDE_CODE_SUBAGENT_MODEL_FORCE` or an agent's own `model`)\n- [VSCode] Fixed uninstalling a plugin from the Manage plugins dialog, which removed the wrong installation or failed for a plugin installed for the project\n- [VSCode] Fixed sign-in staying on the authorization-code step after going back and choosing the same sign-in method again\n- [VSCode] Fixed the chat panel stalling when a long session trims its oldest rows\n- [VSCode] Fixed the conversation disappearing from a session when many agents run\n- [VSCode] Fixed the editor tab keeping an old name after a session was renamed with /rename, by a SessionStart hook, or on claude.ai\n- [VSCode] Fixed the agent map's transcript view leaving out messages sent to a running agent\n- [VSCode] Improved the Manage plugins dialog: a failed plugin action now opens a popup that explains it and, where there is one, offers the fix\n- [VSCode] Changed the Manage plugins dialog to ask before removing a marketplace or turning off a plugin that your project's shared `.claude/settings.json` turns on\n- [Cloud sessions] Fixed Run now on a routine showing internal error text when the run is refused before it starts; it now shows the same explanation as the routine's failure notification\n- [Cloud sessions] Changed `MCP_DISCOVERY_CACHE=1`, when set in your cloud environment's variables rather than a settings file, to reuse your connectors' tool lists after a session restart; other MCP servers are no longer cached and connect at startup\n- [Claude Tag] Added direct messages with Claude for members on an Enterprise plan Standard or Usage-Based Chat seat who also have Cowork; a seat that includes Claude Code is no longer required\n- [Claude Tag] Fixed the Default model setting in admin settings and a channel's Configure page offering models your organization can't use, which made saves or new sessions fail\n- [Claude Tag] Fixed the note under Claude's Slack messages saying it answered on a fallback model, and why, disappearing when Claude later edited that message\n- [Code Review] Fixed the organization menu in Code Review's \"Add a repository\" dialog showing only a few of your GitHub organizations; it now loads more as you scroll\n- [Code Review] Improved the Code Review check run to say when your repository's REVIEW.md wasn't applied, for example on a very large pull request or when REVIEW.md is a symbolic link","body_html":null,"content_hash":"ea38024c5da879ded241a0d7884a31d803f7c25429a5283ecc723aacfa9f1c64","updated_at":"2026-10-05T19:07:21.945Z"},{"id":"b296c7d8-6608-4412-b77e-fb2e65656f8e","source_id":"codex","dedupe_key":"codex:rust-v0.159.0","version":"0.159.0","title":"0.159.0","url":"https://github.com/openai/codex/releases/tag/rust-v0.159.0","published_at":"2026-09-29T08:05:42Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:38:02.977Z","body_md":"## New Features\n\n- Opt-in `instant_interrupt` lets new input steer Codex during model responses or long-running code-mode calls. (#48135, #48141)\n- New sessions get a compact welcome screen and consistent headers, with occasional tips during and after turns. (#48513, #48562, #48352)\n- The warnings viewer dismisses reviewed warnings when closed; press `k` to keep one for later. (#48205, #48206)\n- You can scroll the transcript while deciding whether to implement a plan. (#48805)\n- Native Mermaid rendering supports more flowchart edges, labels, and node groups. (#48814, #48895)\n- App-server clients can paginate thread history from a specific item. (#48151)\n\n## Bug Fixes\n\n- Windows launches avoid stray console windows for MCP servers, code-mode hosts, and piped commands; restrictive launchers can fall back to embedded mode. (#48138, #48238, #48483, #48491)\n- Copying transcript selections preserves Markdown tables, formatting, and significant whitespace. More terminals now copy automatically on selection. (#48548, #48549, #48469)\n- Blank sessions retain drafts when switching tasks, and threads can be archived and listed before their first turn. (#48628, #48828, #48199)\n- Local ChatGPT sign-in opens the browser reliably; onboarding also provides a shortcut to copy the login link. (#48502, #48544)\n- Approved commands retain explicit filesystem denials, and `.aws` directories are protected by default under writable roots. (#48155, #48176)\n- Fixed macOS TLS access in network-enabled sandboxes and remote environments that require proxy access. (#48565, #48198)\n\n## Chores\n\n- Removed automatic follow-up prompt suggestions and the `tui.prompt_suggestions` setting. (#48621)\n- Removed the bundled `plugin-creator` skill. (#48604)\n\n## Changelog\n\nFull Changelog: https://github.com/openai/codex/compare/rust-v0.158.0...rust-v0.159.0\n\n- #48135 Add opt-in code-mode yielding on new user input @pakrym-oai\n- #48138 Suppress console windows when spawning the code-mode host on Windows @zm-oai\n- #48141 Preempt model responses when new user input arrives @pakrym-oai\n- #48143 Preserve executor MCP credential boundaries across reconnects @rreichel3-oai\n- #48151 Add item anchors to `thread/items/list` pagination @btraut-openai\n- #48155 Preserve filesystem denials when preparing approved commands @viyatb-oai\n- #48157 Allow Windows daemon launches with residual job membership @etraut-openai\n- #48158 Fix Guardian retained context spacing and empty assistant handling @olliem-oai\n- #48168 Generate unique exec-server process IDs for every request @sdcoffey\n- #48174 Preserve usage limit windows in turn and compaction analytics @rhan-oai\n- #48176 Protect `.aws` directories under sandbox writable roots @jackz100\n- #48187 Fix zsh alias quoting in sourced shell snapshots @jif-oai\n- #48190 Bound agent message board SSE frames before parsing @jif-oai\n- #48197 Optimize `blake3` in Bazel fastbuilds @jif-oai\n- #48198 Honor execution environment proxy requirements @seanh-oai\n- #48199 Keep archived threads with empty previews visible in listings @acrognale-oai\n- #48200 Extract Responses header conversion into a shared module @anp-oai\n- #48205 Dismiss viewed TUI warnings when closing the viewer @fcoury-oai\n- #48206 Add a keep-and-next action to the warnings viewer @fcoury-oai\n- #48207 Preserve queued output for observers during code-mode termination @pakrym-oai\n- #48211 Keep Codex visible during external editor handoff @etraut-openai\n- #48213 Isolate executable fixture copies in CLI tests on Linux @jif-oai\n- #48222 Preserve late result metadata for truncated code-mode calls @ningyi-oai\n- #48224 Preserve model and access program pairs during compaction @jamy-OAI\n- #48229 Extract Responses failure parsing into a dedicated module @anp-oai\n- #48238 Suppress console windows for local Windows MCP servers @malsamiri-oai\n- #48272 Prevent Windows daemon launches from retaining launcher stdio @zm-oai\n- #48318 Keep TUI reconnect attempts running until the shared deadline @etraut-openai\n- #48344 Preserve tool metadata for OpenAI provider endpoint overrides @peilin-openai\n- #48350 Display reconnect commands on a separate line @etraut-openai\n- #48352 Show turn tips while working and after completion in the TUI @fcoury-oai\n- #48353 Stabilize skill catalogs across executor availability changes @vkg-oai\n- #48469 Default to copying transcript selections in more terminals @fcoury-oai\n- #48483 Prevent console windows for piped Windows child processes @fcoury-oai\n- #48489 Fix Mermaid shape, relationship, and state description parsing @etraut-openai\n- #48491 Fall back to embedded mode under restrictive Windows launchers @fcoury-oai\n- #48502 Fix ChatGPT browser sign-in for local app servers @etraut-openai\n- #48508 Preserve WebSocket continuations when steering a turn @pakrym-oai\n- #48513 Refresh the TUI welcome screen for new sessions @fcoury-oai\n- #48531 Add context to Windows sandbox runtime registration errors @zm-oai\n- #48544 Make onboarding login links easier to copy @etraut-openai\n- #48547 Fade blossom replays back to the idle state @fcoury-oai\n- #48548 Preserve table cell source metadata through TUI rendering @fcoury-oai\n- #48549 Preserve Markdown tables and whitespace when copying TUI responses @fcoury-oai\n- #48551 Fix TUI math rendering for zero and big wedge expressions @etraut-openai\n- #48560 Keep working tips stable during transcript interaction @fcoury-oai\n- #48562 Use a consistent borderless session header in the TUI @fcoury-oai\n- #48565 Allow macOS TLS trust evaluation in network-enabled Seatbelt profiles @winston-openai\n- #48568 Allow exec-server to proxy permitted private IPs upstream @open-matt\n- #48574 Preserve deferred tool namespace names before descriptions @adaley-openai\n- #48575 Allow provisioned executors more time to come online @richardopenai\n- #48604 Remove the bundled `plugin-creator` skill @martinauyeung-oai\n- #48611 Centralize persistent mode enablement checks @alishobeiri-oai\n- #48621 Remove follow-up prompt suggestions from the TUI @etraut-openai\n- #48623 Preserve empty Markdown list markers in the TUI @etraut-openai\n- #48626 Stop showing previous-session summaries when switching TUI sessions @etraut-openai\n- #48628 Preserve blank TUI sessions when switching tasks @etraut-openai\n- #48643 Set the provisioned macOS CLI bundle name to ChatGPT @riley-oai\n- #48646 Fix the session-start helper call in the command center test @etraut-openai\n- #48686 Remove WebSocket headers and tool payloads from info logs @chess-oai\n- #48724 Prevent Linux ETXTBSY races in MCP stdio tests @jif-oai\n- #48725 Retain confirmed Code Mode messages for Guardian reviews @ankushg\n- #48727 Centralize executable fixture creation to avoid Linux ETXTBSY races @jif-oai\n- #48754 Render `/status` without borders and wrap long values @fcoury-oai\n- #48757 Match TUI status shimmer timing to desktop headers @fcoury-oai\n- #48761 Show hidden output line counts in compact terminal activity @fcoury-oai\n- #48764 Preserve MCP app resource URIs without defaulting display mode @victor-openai\n- #48772 Fix Unix socket connections through long symlink paths @etraut-openai\n- #48775 Match pinned transcript headers to the original prompt style @etraut-openai\n- #48776 Remove the `current` badge from TUI task rows @etraut-openai\n- #48779 Preserve independent Guardian history across parent compaction @felixxia-oai\n- #48783 Add single-server MCP status discovery with thread connection reuse @victor-openai\n- #48796 Add opt-in structured errors for Guardian circuit-breaker interruptions @won-openai\n- #48799 Fix SGR mouse reporting for Windows terminal capture @etraut-openai\n- #48800 Use the terminal palette for ordered Markdown list markers @etraut-openai\n- #48805 Allow transcript wheel scrolling while a modal is open @fcoury-oai\n- #48807 Show short turn durations in TUI completion footers @fcoury-oai\n- #48812 Add history-aware prewarming for idle threads @vkg-oai\n- #48814 Preserve punctuation and semicolons in Mermaid labels @etraut-openai\n- #48819 Use explicit histogram buckets for tool and skill context metrics @mzeng-openai\n- #48824 Keep voice RTP timestamps aligned to 20 ms packets @bc-openai\n- #48827 Show a hand pointer over transcript links in Ghostty and Kitty @bc-openai\n- #48828 Allow archiving threads before their first turn @bc-openai\n- #48829 Wait briefly for the Windows sandbox provisioning service to start @zm-oai\n- #48830 Show a short, neutral TUI interruption notice @fcoury-oai\n- #48895 Expand native Mermaid flowchart syntax support @etraut-openai\n- #48973 Isolate realtime auth fallback test from startup prewarm @jif-oai\n- #48982 Prevent message-board notifications from reopening final answers @eknight-oai\n\n\n","body_html":null,"content_hash":"438faf551d5b31db19fda1a909e7a4944b135a7ea27acd2788a069461f255426","updated_at":"2026-10-05T08:38:02.977Z"},{"id":"5e97c827-e154-4932-a75f-4c6d6636b79f","source_id":"claude-code","dedupe_key":"claude-code:2.1.284","version":"2.1.284","title":"claude code 2.1.284","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21284","published_at":"2026-09-28T17:11:59.750Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added Claude Sonnet 5.5 (`claude-sonnet-5-5`), now the default Sonnet model on the Anthropic API — 1M context, $2/$10 per Mtok with $0.20/Mtok cache reads\n- Added a \"Yes, but ask again next time\" answer to auto mode's prompt before a read outside the working directories, so you can allow that one read and still be asked about later ones\n- Added dollar amounts to the Claude apps gateway spend limit in `/usage` and the status line (for example \"$271.40 / $500.00 spent this month\") when the gateway runs this version or later; the status line's `rate_limits.spend_limit` also gains `used_usd`, `limit_usd` and `period`\n- Added `effortSlider:decreaseEffort`, `increaseEffort` and `toggleUltracode` keybinding actions, so the `/effort` slider's arrow and Tab keys can be rebound in `keybindings.json`\n- Added `/rate-limit-options` to `/help` and the command menu for claude.ai subscribers, so the usage-limit notices that mention it point to a command you can find\n- Added `/mcp reconnect all` in the interactive terminal to retry every MCP server that failed to connect or needs authentication at once\n- Added Claude apps gateway startup warnings when a managed policy's `availableModels` is empty, or leaves out the model Claude Code starts on without setting `model` or `enforceAvailableModels`\n- Added `auth: { google: {} }` for Claude apps gateway `telemetry.forward_to` destinations, so telemetry can be exported straight to Google Cloud's OTLP endpoint using the gateway's Google Cloud credentials\n- Added certificate client authentication (`private_key_jwt`) between the Claude apps gateway and its identity provider, for identity providers that issue certificate credentials instead of client secrets\n- Fixed a damaged response stream showing raw errors such as \"JSON Parse error\" or \"undefined is not an object\", or writing the word \"undefined\" into an answer, instead of being retried or reported as an interrupted response\n- Fixed an overloaded or server error arriving right after a thinking block ending the turn with an error instead of being retried\n- Fixed \"Prompt is too long\" errors that persisted after compacting: when the compacted request is still too long, Claude Code now compacts once more, keeping less of the recent conversation\n- Fixed a session whose model is unavailable, with no fallback model left, showing a bare \"is currently unavailable\" message (or \"Something went wrong\" in cloud sessions) instead of the model-unavailable notice and its Learn more link\n- Fixed Agent SDK sessions crashing when a user message contains an image with a malformed `source`, and failing on every later turn after a malformed document block; a malformed image is now replaced with an explanatory note\n- Fixed MCP tool calls in a resumed session failing with \"No such tool available\" while their server was still connecting; the call now waits up to 10 seconds for the server\n- Fixed repeated calls to the plan-usage endpoint after it rate-limits or rejects your login: `/usage`, `/extra-usage` and IDE usage views now back off instead of re-asking\n- Fixed `claude mcp add` reporting success when managed settings restrict MCP servers to plugins; it now refuses and says what to do, instead of saving a server that never loads\n- Fixed the `/plugin` configure screen: boolean options are now a true/false choice instead of free text, number options refuse invalid input, and ←/→ change an options field instead of switching tabs\n- Fixed `ANTHROPIC_FOUNDRY_RESOURCE` being interpolated into the Foundry endpoint host unvalidated; a value that is not a plain resource name is now refused\n- Fixed Claude Desktop behind a Claude apps gateway offering no 1M context option: the gateway now marks each 1M-capable model for Desktop automatically\n- Fixed ↓ in shell mode selecting a hidden background-tasks pill, which stopped Backspace and Ctrl+U from editing the prompt\n- Fixed Bash tool failing on Windows with many plugins enabled: plugin `bin/` directories that don't exist are no longer added to PATH, and inherited entries aren't added twice\n- Fixed `sparsePaths` plugin marketplaces cloning empty and replacing a working local copy on older git (before 2.39), which failed every refresh with \"marketplace.json file is no longer present\"\n- Fixed fullscreen rendering erasing the terminal output above the session when `[` in transcript mode writes the conversation to scrollback (macOS and Linux)\n- Fixed fullscreen scroll position jumping to the previous message or to the bottom when a reply finished streaming while scrolled up\n- Fixed tab bars in dialogs such as `/config` and `/plugin` breaking the title and tab labels mid-word in a narrow terminal; a tab that doesn't fit now moves to the next line whole\n- Fixed the `/model` picker showing \"+1 model\" below the list after scrolling to the last model; the count now covers only the models below the visible rows\n- Fixed `/keybindings` writing Backspace and Delete bindings for a footer action that does nothing into the generated `keybindings.json`\n- Fixed a rebound agent panel close key (`footer:close`) typing \"x\" instead of itself on the row of the agent you're viewing\n- Fixed vim mode `.` not repeating text typed very fast (for example over ssh or in tmux) or pasted without bracketed paste, and leaving the prompt in INSERT mode after repeating a change with nothing typed (such as `cw` then Esc)\n- Fixed vim mode leaving the cursor on an image placeholder's opening bracket after `dd` on the last line or `yy` at the end of the prompt, where `r` or `x` would break or delete the image\n- Fixed a key pressed the instant the terminal regained focus answering the Remote Control enable prompt before its short safety delay restarted\n- Fixed the workspace trust dialog appearing a second time after switching renderers or updating when Claude Code was started in the home directory\n- Fixed rules symlinked into `.claude/rules` from outside the project being skipped without ever showing the external-imports approval prompt; a `.claude` directory symlinked from outside the project now asks for the same approval\n- Fixed plugins from marketplaces, claude.ai and npm pre-approving their own tools via `allowed-tools` under managed `allowManagedPermissionRulesOnly`; only plugins from an official Anthropic source or a source that managed settings vouch for keep that pre-approval\n- Fixed a failed first `claude plugin install` leaving the plugin enabled and recorded when a dependency's version range could not be met\n- Fixed the debug log dropping a failed hook's stderr when the hook also wrote to stdout, and logging nothing for a failed hook with no output; failed hooks now also log their status code\n- Fixed `{\"decision\":\"block\"}` returned by Elicitation and ElicitationResult hooks being ignored; it now declines the MCP elicitation, as exit code 2 does\n- Fixed sessions launched without the `SendMessage` tool (such as by Claude Desktop) still being told to message other sessions with it\n- Fixed a photo sent from the Claude app over Remote Control being lost when its queued message was pulled back into the terminal prompt to edit, and the cursor moving one character for a photo with no caption\n- Fixed typing a message during an automatic usage-limit wait taking the wait out of the \"Continue automatically at usage limit\" setting's control when that turn hit the limit again\n- Fixed usage-limit warnings suggesting `/upgrade` to users already on the highest Max plan; the warnings and `/upgrade` itself now point at `/usage-credits` when it is available\n- Fixed the Explore subagent switching to Opus on the Claude API when the session runs a model ID Claude Code doesn't recognize, such as a custom model behind a proxy; Explore now inherits that model\n- Fixed `/loop` status updates in self-paced mode often not being shown because Claude wrote them only in its reasoning; Claude now writes each update, and the outcome when the loop stops, as visible text\n- Fixed `/ultrareview` failing to upload the working tree when started from a git worktree that the Claude desktop app created on macOS or Linux\n- Fixed sandboxed Bash commands failing to start on Linux when the working directory is write-denied and contains a read-denied directory\n- Fixed artifact database write results telling Claude that every viewer sees a write to a viewer's private `data/users/` subtree, and added a \"view\" level to `as_level`\n- Fixed the Claude apps gateway answering `431 Request Header Fields Too Large` to every request from a sign-in whose identity provider lists many groups; it now accepts request headers up to 256 KiB\n- Improved the usage-limit wait: the limit's state and the countdown with the usage-credits option now show as one block under the prompt, and limit messages no longer repeat the countdown\n- Improved the \"No such tool available\" error for Claude in Chrome tools called without their prefix: it now names the tool to call\n- Improved Monitor event rows to show what each event printed instead of repeating the description, and stopped repeating an unchanged \"Waiting for N … to finish\" line after every event\n- Improved Workflow tool sandbox hardening for errors thrown by async script hooks\n- Improved startup time and memory use by building only the parts of the settings schema that your settings files actually use\n- Improved `/claude-api`: `hillclimb` no longer spends rounds on prompt rewordings too small for the eval to measure, and an extra page you ask for beside `report.html` is built as one local file that loads nothing from the network\n- Improved lists such as `/tasks`, `/copy` and `/hooks`: the details after each name now line up in one column when they fit, and otherwise sit at the right edge\n- Improved `claude plugin marketplace add` to say when it replaces a marketplace already added under the same name from a different source, and how to undo it\n- Improved the startup refusal when managed settings require a sign-in (`forceLoginMethod` or `forceLoginOrgUUID`) and an API key, token or `apiKeyHelper` is configured: it now names the credential in use, where it is set, and how to remove it\n- Improved auto-memory loading: invisible characters and tags that imitate Claude Code's own markup are neutralized in `MEMORY.md` and recalled memory notes before they reach Claude\n- Improved `claude remote-control`: in a folder you haven't trusted yet, it now asks for workspace trust on the terminal instead of exiting\n- Improved artifact pages: Claude writes its design plan into the page instead of the reply, and uses the name you already gave something as the page title\n- Improved the Artifact tool so that when Claude is given a claude.ai chat or project link, an artifact from a chat, or an artifact id on its own, it asks for the right link or the content instead of stopping\n- Changed interactive terminal and VS Code sessions to start in auto mode when no permission mode is configured, on every plan and provider; `permissions.defaultMode` still overrides it\n- Changed Ultracode into its own toggle in `/effort` (Tab, or `/effort ultracode [on|off]`): it no longer forces xhigh effort and stays on at any effort level\n- Changed retries after a dropped connection mid-response to share one budget with the rest of the request's retries, so a failing request gives up sooner\n- Changed the notice shown when a Sonnet model's safeguards flag a message to explain why it happened and to offer editing and retrying\n- Changed safety-related model switches in sessions that pin an Opus model with `ANTHROPIC_DEFAULT_OPUS_MODEL` or `modelOverrides`: on the Anthropic API, the API now picks the model to switch to for each kind of flag, not the pinned model\n- Changed the non-interactive first turn to still wait up to 2s for connecting MCP servers named by `--allowedTools` or an `mcp_tool` hook, even when `CLAUDE_CODE_MCP_STARTUP_WAIT_MS` is `0`\n- Changed `/recap` to decline with a short notice when it arrives relayed from a chat thread (your own included) or from a routine or webhook; typed in the terminal, the Claude apps, Remote Control, `-p` or an SDK host, it runs as before\n- Changed `/artifacts` to show its filter tabs beside the title with one-word labels (All, Mine, Shared), using the same tab bar as `/config` and `/plugin`\n- Changed artifact publishing to refuse a file on a network share (a `\\\\host\\share` path or a `/net` automount) unless it is on a mapped network drive added with `--add-dir`\n- [VSCode] Added an optional time above each prompt and response, with a date line where the day changes (Claude Code: Show Message Timestamps setting, off by default)\n- [VSCode] Added plugin load errors and notes to the Manage plugins rows, with a popup to disable, uninstall or copy the error\n- [VSCode] Added an Ultracode on/off switch under the Effort slider, replacing the slider's Ultracode stop; the model pill shows \"· Ultracode\" at any effort level\n- [VSCode] Fixed Reload Claude from the Memory dialog restarting before an edited file was saved\n- [VSCode] Fixed a restored tab opening a conversation another Claude process still has open; it now asks first\n- [VSCode] Fixed Focus view sections you expanded closing on their own while a sub-agent is working or when the section's first step is trimmed from view\n- [VSCode] Fixed typing `/model` and Enter printing usage text into the chat instead of opening the model selector\n- [VSCode] Fixed `/feedback` on Vertex, Bedrock and Foundry being refused after you pressed Send; the report is now saved on this computer, as the terminal does\n- [VSCode] Fixed sign-in waiting up to a minute for the Python extension after a window reload\n- [VSCode] Fixed Claude Code tabs that stopped responding after Restart Extensions: they now reopen on their conversation\n- [VSCode] Fixed a message from another agent with no recorded sender showing as raw XML in the chat\n- [VSCode] Fixed messages from other agents, sessions or channels disappearing after a reload\n- [VSCode] Fixed a user's own `/mcp`, `/config` or `/settings` command being shadowed by the extension's dialog\n- [VSCode] Fixed Escape stopping every background agent when no turn was running\n- [VSCode] Fixed plugin install links replacing a marketplace you already have that uses the same name\n- [VSCode] Fixed \"Prompt is too long\" errors after compaction when a large text file is attached to a message\n- [VSCode] Fixed chat links to files with non-ASCII characters, spaces or brackets in their path not opening\n- [VSCode] Changed `CLAUDE_CONFIG_DIR` in the `claudeCode.environmentVariables` setting to apply only when it is an absolute path, and passed it to terminals that continue the chat\n- [Cloud sessions] Fixed a routine's Edit and Duplicate controls saying the routine was still loading while you were offline; they now tell you you're offline\n- [Claude Tag] Added model family choices such as \"Opus (latest)\" for a thread, a channel default or your DM, so the choice follows the newest model in that family\n- [Claude Tag] Added the spend that counts toward your organization-wide limit to the analytics spend projection chart, with how much of the limit is used\n- [Claude Tag] Fixed the earlier Claude in Slack app's progress card and link previews omitting the repository and Create PR button when a GitHub Enterprise host name contains an underscore\n- [Claude Tag] Fixed Claude staying silent in a channel whose environment declines to start it; it now posts one notice asking you to contact an admin, and retries when @-mentioned\n- [Claude Tag] Changed Claude to post its private sign-in notice at every @mention from someone who hasn't connected their Claude account, instead of going quiet after the first\n- [Claude Tag] Improved \"Notify members now\" in admin settings: one press reaches every workspace your organization claimed in an Enterprise Grid, and more members in large workspaces\n- [Claude Tag] Improved Claude's wait notice on self-hosted environments with on-demand runners: it now says whether a runner is starting, a start will be retried, or no runner will start\n- [Claude Tag] Improved the error shown when adding a channel manager fails because the channel's Slack workspace can't be confirmed as connected to your organization\n- [Claude Tag] Improved a channel's access lists in admin settings to show the connectors, repositories and plugins an auto-join pattern attaches, and where each comes from\n- [Claude Tag] Improved adding repositories as a channel manager: when your GitHub sign-in can't confirm you're a repository admin, the page asks you to sign in with GitHub\n- [Code Review] Fixed Code Review giving up without posting a finished review when an unsubmitted review under its GitHub App was open on the pull request; it now retries the post first","body_html":null,"content_hash":"268351f118a475a5608fade2ab69cec51bdad784711d041ca5ee0e157cf2144a","updated_at":"2026-10-05T19:07:21.945Z"},{"id":"dcf13fff-ab19-4500-baab-f8177f217052","source_id":"codex","dedupe_key":"codex:rust-v0.158.0","version":"0.158.0","title":"0.158.0","url":"https://github.com/openai/codex/releases/tag/rust-v0.158.0","published_at":"2026-09-28T05:07:23Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:38:02.977Z","body_md":"## New Features\r\n\r\n- Configure copy-on-select and right-click paste in the fullscreen TUI. Copied transcript selections now preserve Markdown formatting. (#47639, #47896, #48118)\r\n- Connect to MCP servers that require pre-registered OAuth client secrets, including through `codex mcp add --oauth-client-secret`. (#47891)\r\n- Secure direct exec-server WebSocket connections with bearer tokens, including connections configured through app-server. (#47601, #47648)\r\n- Image generation and editing can explicitly request transparent backgrounds, and edits now accept file-backed conversation images. (#47484, #47956)\r\n- Terminal input approval is enabled by default for commands running with elevated permissions; runtime-only grants no longer cause unnecessary reviews. (#47799, #48073)\r\n\r\n## Bug Fixes\r\n\r\n- Fixed Windows sandbox failures involving ordinary Windows 10 paths, rejected stored credentials, and large permission policies. (#47672, #47695, #47919)\r\n- Fixed Linux sandbox startup with nested writable roots and preserved Git metadata protections across writable roots on Linux and macOS. (#47623, #47974)\r\n- macOS patch operations now recognize system path aliases covered by existing permissions, avoiding unnecessary approval prompts. (#47879)\r\n- Approval reviews now retry when new user input arrives, so a status question does not automatically abort a pending action. (#47819)\r\n- Mermaid flowcharts now render quoted labels and ampersands; unsupported diagrams explain why they fall back to source. (#47572, #47678)\r\n- Command completion events now include early output and report process-launch failures to clients. (#47529, #47665)\r\n\r\n## Changelog\r\n\r\nFull Changelog: https://github.com/openai/codex/compare/rust-v0.157.0...rust-v0.158.0\r\n\r\n- #47441 Use secondary text styling for the transcript footer shortcut hint @etraut-openai\r\n- #47447 Extract WebSocket authentication into `codex-websocket-auth` @euroelessar\r\n- #47458 Parallelize instruction refresh and tool preparation @hlevy-openai\r\n- #47484 Add explicit background control to image generation @alicec-oai\r\n- #47520 Route session agent operations through `AgentControl` @jif-oai\r\n- #47529 Emit command lifecycle events for unified exec launch failures @steipete-oai\r\n- #47536 Route agent lookups and V2 context through `AgentControl` @jif-oai\r\n- #47539 Test interrupted one-shot command launch failure persistence @jif-oai\r\n- #47540 Add an option to disable multi-agent v2 direct messaging @jif-oai\r\n- #47565 Classify rollout read failures by reason and progress @jif-oai\r\n- #47568 Record sandbox backends in command execution analytics @iceweasel-oai\r\n- #47571 Wait for idle before injecting remote compaction test history @felixxia-oai\r\n- #47572 Explain Mermaid rendering fallbacks in the TUI @etraut-openai\r\n- #47582 Retain assistant context for Guardian authorization reviews @felixxia-oai\r\n- #47584 Preserve streamed assistant message order in retained context @felixxia-oai\r\n- #47585 Preserve delivered assistant messages in Guardian retained context @felixxia-oai\r\n- #47589 Keep unfinished link destinations out of rich streaming previews @etraut-openai\r\n- #47590 Serialize numeric custom reasoning effort as JSON numbers @dylan-hurd-oai\r\n- #47591 Stream daemon executable hashing off the async runtime @etraut-openai\r\n- #47596 Refresh realtime context for each model request @reia-oai\r\n- #47597 Guard prerelease channel and canary updates against older versions @imac-oai\r\n- #47601 Add opt-in WebSocket authentication to exec-server @euroelessar\r\n- #47603 Add a reap-only drop policy for child processes @charliemarsh-oai\r\n- #47604 Extend child commands with session and descriptor controls @charliemarsh-oai\r\n- #47605 Route pipe processes through the shared child launcher @charliemarsh-oai\r\n- #47610 Use native POSIX spawning for command hooks @charliemarsh-oai\r\n- #47611 Use the shared process launcher for Unix shell snapshots @charliemarsh-oai\r\n- #47612 Launch Linux pipe processes through a fresh setup helper @freeqaz-openai\r\n- #47613 Expand Linux spawn-helper lifecycle test coverage @charliemarsh-oai\r\n- #47617 Route Linux PTY launches through the process setup helper @charliemarsh-oai\r\n- #47618 Prefer Shift-arrow hints for queued messages and questions @imac-oai\r\n- #47619 Add bounded buffering for global operation metrics @celia-oai\r\n- #47620 Add portable project trust lookup APIs @seanh-oai\r\n- #47623 Fix read-only metadata mount ordering for nested writable roots @jif-oai\r\n- #47624 Recognize `user_message` tools in Guardian authorization context @ankushg\r\n- #47625 Allow history and notes without experimental context capability @pmccrary-oai\r\n- #47629 Route V2 child loading through `AgentControl` @jif-oai\r\n- #47630 Bind Guardian reviews to the action's target environment @jif-oai\r\n- #47633 Route message board agent resolution through the selected controller @jif-oai\r\n- #47635 Overlap startup WebSocket preconnect with tool discovery @bromano-oai\r\n- #47638 Classify retryable exec-server preparation errors by type @mtsui-oai\r\n- #47639 Add configurable copy-on-select for transcript selections @fcoury-oai\r\n- #47641 Honor Retry-After and preserve server retry deadlines @anp-oai\r\n- #47642 Add model-specific prefixes to indirect tool descriptions @rhan-oai\r\n- #47647 Apply Guardian computer-use review to the Browser connector @johnl-oai\r\n- #47648 Support bearer tokens for app-server executor connections @euroelessar\r\n- #47649 Add opt-in OTLP logging for final agent responses @xli-oai\r\n- #47653 Attach inherited rollout history to diagnostic reports @dkovalenko-oai\r\n- #47654 Make Linux descriptor cleanup fork-safe @yuzhu-oai\r\n- #47655 Bump the exec-server stable compatibility test to Codex 0.156.1 @imac-oai\r\n- #47657 Restrict the default Bedrock GovCloud model catalog @jackz100\r\n- #47662 Expose tool dispatch and timing observations to extensions @euroelessar\r\n- #47663 Preserve managed network policy in route-aware transports @jackz100\r\n- #47665 Preserve early unified exec output in completion events @sdcoffey\r\n- #47670 Support model-specific descriptions for agent message board tools @eknight-oai\r\n- #47672 Fix no-reparse directory opens on Windows 10 @zm-oai\r\n- #47673 Clarify registered Windows sandbox setup errors @zm-oai\r\n- #47677 Support model catalog overrides for MCP resource tool specs @rhan-oai\r\n- #47678 Support quoted labels and ampersands in Mermaid flowcharts @etraut-openai\r\n- #47679 Add extension hooks for model requests and response streams @euroelessar\r\n- #47680 Add exec-server RPC timing and process startup tracing @anp-oai\r\n- #47683 Add executor capability discovery V2 infrastructure @TAFOYA-OAI\r\n- #47686 Make thread-owned Guardian context always enabled @felixxia-oai\r\n- #47688 Remove legacy Guardian authorization evidence paths @felixxia-oai\r\n- #47689 Make Guardian thread context capture unconditional @felixxia-oai\r\n- #47690 Remove obsolete Guardian context capture mode branches @felixxia-oai\r\n- #47691 Materialize rollout persistence for pending inter-agent messages @dermanyang-oai\r\n- #47693 Configure curl retries for DotSlash installation in CI @anp-oai\r\n- #47695 Repair rejected Windows sandbox credentials during provisioning @zm-oai\r\n- #47696 Avoid the shutdown timeout in the lagged-event test @jgershen-oai\r\n- #47698 Allow WebSocket test server shutdown while waiting for requests @jgershen-oai\r\n- #47701 Allow idle threads to prewarm and repair WebSocket connections @vkg-oai\r\n- #47703 Preserve account network policy for ChatGPT backend requests @jackz100\r\n- #47704 Fix spawn flag typing and isolate project configuration tests @seanh-oai\r\n- #47709 Route resume prewarm through the cached WebSocket session @vkg-oai\r\n- #47712 Update unified exec output buffers atomically @sdcoffey\r\n- #47713 Reduce dependency coupling in shared configuration crates @aibrahim-oai\r\n- #47714 Preserve tool result metadata more selectively under size limits @ningyi-oai\r\n- #47717 Avoid recursive TUI event dispatch for model picker selections @etraut-openai\r\n- #47741 Attribute tool telemetry to the invoking turn's product SKU @rennie-openai\r\n- #47742 Honor network policy in history notes and image generation extensions @jackz100\r\n- #47745 Skip startup prewarm preparation when the WebSocket is ready @vkg-oai\r\n- #47748 Align Cargo and Bazel Rust debug information defaults @aibrahim-oai\r\n- #47751 Reduce generic code duplication in RPC and Markdown rendering @aibrahim-oai\r\n- #47755 Centralize typed app-server response decoding @aibrahim-oai\r\n- #47757 Refactor tool telemetry product SKU matching to use an allowlist @rennie-openai\r\n- #47758 Preserve more tool metadata within outgoing message budgets @ningyi-oai\r\n- #47773 Honor catalog schemas for asynchronous user input @rhan-oai\r\n- #47797 Support close-on-exec attachments without changing PTY semantics @jif-oai\r\n- #47799 Enable terminal input approval by default @jif-oai\r\n- #47808 Allow hosts to provide agent controllers through ThreadManager @jif-oai\r\n- #47811 Preserve explicit user goal updates in Guardian authorization @felixxia-oai\r\n- #47813 Fix sleep interruption test event handling and fixture lifetime @felixxia-oai\r\n- #47814 Fix a lost wakeup in the unified exec termination test @felixxia-oai\r\n- #47817 Stabilize thread resume and memory dual-write tests @jif-oai\r\n- #47819 Retry Guardian reviews when authorization changes @teddywyly-oai\r\n- #47820 Add integration coverage for host agent controllers @jif-oai\r\n- #47824 Allow four concurrent threads in the multi-agent resume test @felixxia-oai\r\n- #47828 Wait for login completion in recommended plugin tests @felixxia-oai\r\n- #47830 Bind Guardian async scores to target environment permissions @jif-oai\r\n- #47832 Stabilize Rosetta test timing and retry delay telemetry @jif-oai\r\n- #47847 Keep the TUI responsive during clipboard copies @fcoury-oai\r\n- #47851 Preserve human overrides across repeated heartbeat instructions @felixxia-oai\r\n- #47852 Avoid blocking async proxy resolution on the system proxy cache @jif-oai\r\n- #47856 Initialize media estimates outside the global cache lock @jif-oai\r\n- #47858 Validate loaded plugins outside the cache lock @jif-oai\r\n- #47861 Avoid nested read locking when rendering browser sign-in @jif-oai\r\n- #47867 Render remote permission paths using executor context @iceweasel-oai\r\n- #47870 Add opt-in OTLP logging for Guardian assessments @jif-oai\r\n- #47871 Fix PID reservation test race and update guardian heartbeat snapshot @jif-oai\r\n- #47873 Measure deferred tool namespace fragments before and after truncation @mzeng-openai\r\n- #47879 Fix macOS system-alias matching in patch permission checks @felixxia-oai\r\n- #47881 Use Tokio's clock for TUI paste timing @charliemarsh-oai\r\n- #47886 Preserve diagnostic logs when SQLite logging fails @dkovalenko-oai\r\n- #47887 Warn users when SQLite diagnostic log writes fail @dkovalenko-oai\r\n- #47889 Include TUI client logs in diagnostic uploads @etraut-openai\r\n- #47891 Support client secrets for pre-registered MCP OAuth clients @willwang-openai\r\n- #47894 Clean up temporary Codex homes after TUI tests @fcoury-oai\r\n- #47896 Preserve Markdown formatting when copying transcript selections @fcoury-oai\r\n- #47898 Preserve local-binding inheritance in environment network policies @seanh-oai\r\n- #47899 Add diagnostic reasons to MCP attribution errors @peilin-openai\r\n- #47900 Default local threads to paginated history @owenlin0\r\n- #47901 Add bounded credential-storage telemetry helpers @celia-oai\r\n- #47902 Avoid repeated table clones during config merging @imac-oai\r\n- #47903 Move config key alias normalization ahead of merging @imac-oai\r\n- #47904 Support nested canonical paths in config key aliases @imac-oai\r\n- #47908 Alias `tui.whimsy` to `tui.effects.starfield` @imac-oai\r\n- #47912 Fix attestation routing during thread startup @charliemarsh-oai\r\n- #47913 Add an opt-in flag to defer mailbox preemption @jif-oai\r\n- #47915 Reuse verified V8 checksum manifests from the artifact cache @aibrahim-oai\r\n- #47918 Parameterize the turn-start originator header test @aibrahim-oai\r\n- #47919 Transport large Windows sandbox launch payloads through the environment @malsamiri-oai\r\n- #47920 Allow directory moves under global Seatbelt basename denies @chess-oai\r\n- #47922 Allow full-access Windows setup to provision through registered Core @zm-oai\r\n- #47924 Make project trust lookup paths explicit and defer root resolution @seanh-oai\r\n- #47926 Retry file blob uploads on HTTP 502 and 504 @mtsui-oai\r\n- #47927 Use `127.0.0.1` for local login redirects @willwang-openai\r\n- #47932 Remove GPT-5.4 from bundled catalogs and preserve migration prompts @andrewgu-oai\r\n- #47934 Apply the unchanged-model compaction shortcut to all session sources @hlevy-openai\r\n- #47935 Allow cached catalogs to satisfy MCP startup readiness @hlevy-openai\r\n- #47936 Make MCP and Code Mode input schema budgets configurable @vivi\r\n- #47937 Add direct replies for thread settings updates @sayan-oai\r\n- #47939 Separate selected plugin identities from MCP contributions @sayan-oai\r\n- #47943 Remove unused Windows world-writable audit code @iceweasel-oai\r\n- #47945 Parameterize the thread initialization analytics test by originator @eddie-openai\r\n- #47946 Add an in-memory agent message board for ephemeral sessions @jif-oai\r\n- #47947 Expand root authorization context to 16 messages @felixxia-oai\r\n- #47951 Use prebuilt V8 archives for Bazel on macOS and GNU Linux @aibrahim-oai\r\n- #47952 Prune expired in-memory message board registry entries @jif-oai\r\n- #47954 Move fullscreen startup tips into the transcript @etraut-openai\r\n- #47956 Support file references in image edit requests @kchainani-oai\r\n- #47957 Bound tool-call observations to the outgoing Responses message budget @ningyi-oai\r\n- #47962 Request transparent huge pages for Cargo and eligible Bazel rustc jobs @aibrahim-oai\r\n- #47964 Preserve the client-agent header for Amazon Bedrock Runtime @celia-oai\r\n- #47967 Surface Flex capacity failures as a distinct terminal error @sdcoffey\r\n- #47968 Handle Btrfs device mismatches when masking daemon sockets @etraut-openai\r\n- #47970 Expose current environment selections for a running turn @sayan-oai\r\n- #47971 Add Pro Max plan support and update Pro display names @etraut-openai\r\n- #47974 Preserve Git directory protections across writable roots @aionescu-oai\r\n- #47975 Prevent stale voice answers from reappearing during speech recovery @etraut-openai\r\n- #47981 Prepare MCP calls directly from advertised tool identities @hlevy-openai\r\n- #47984 Add multi-agent spawn latency and failure metrics @owenlin0\r\n- #47988 Reuse MCP handlers across equivalent bindings @hlevy-openai\r\n- #47989 Add startup-only PID namespace inheritance to exec-server @open-matt\r\n- #48004 Respect configured authentication in the thread manager sample @celia-oai\r\n- #48015 Validate tool suggestion install URLs before showing the app link @aionescu-oai\r\n- #48017 Test same-cell permission grants and strict review in code mode @anp-oai\r\n- #48035 Remove plugin extension metadata from discovery and summaries @victor-openai\r\n- #48060 Deduplicate retained instructions across Guardian reviews @felixxia-oai\r\n- #48069 Handle early command yields in the Guardian network approval test @jif-oai\r\n- #48072 Skip message-board notification previews when there are no recipients @jif-oai\r\n- #48073 Avoid stdin approval for runtime-only permission grants @jif-oai\r\n- #48077 Add Serde support to agent message board request types @jif-oai\r\n- #48078 Replay exec-server shell snapshots through unnamed files @jif-oai\r\n- #48098 Preserve recent authorization context for Guardian reviews @felixxia-oai\r\n- #48099 Honor shell environment policy in legacy snapshots @jif-oai\r\n- #48100 Add an HTTP client for remote agent message boards @jif-oai\r\n- #48101 Show multiline command previews in `/ps` @etraut-openai\r\n- #48109 Deduplicate retained instructions against Guardian transcripts @felixxia-oai\r\n- #48110 Deduplicate retained instructions in async Guardian context @felixxia-oai\r\n- #48115 Preserve user text parts during local compaction @felixxia-oai\r\n- #48116 Allow reasoning shortcuts to reach Max @etraut-openai\r\n- #48118 Add configurable right-click paste to the fullscreen TUI @fcoury-oai\r\n- #48119 Prevent worker completion races in the guardian authorization test @felixxia-oai\r\n- #48121 Keep startup drafts visible during command center session handoff @etraut-openai\r\n- #48123 Add early yielding for code-mode observations @pakrym-oai\r\n- #48130 Use request notifications in the cloud config loader lifetime test @felixxia-oai\r\n- #48132 Allow Left to open the command center from read-only conversations @etraut-openai\r\n\r\n\r\n","body_html":null,"content_hash":"376f278e1f99c94c2f24741fc8f618e05bdc2857b34e5dca05306527cc2e452e","updated_at":"2026-10-05T08:38:02.977Z"},{"id":"caafe8d2-5a32-47a4-afcd-4c9a743b4da4","source_id":"codex","dedupe_key":"codex:rust-v0.157.1","version":"0.157.1","title":"0.157.1","url":"https://github.com/openai/codex/releases/tag/rust-v0.157.1","published_at":"2026-09-26T01:02:31Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:38:02.977Z","body_md":"## Chores\n\n- Release highlights could not be determined: the supplied PR index is empty, and the GitHub tag comparison returned 404.\n\n## Changelog\n\nFull Changelog: https://github.com/openai/codex/compare/rust-v0.157.0...rust-v0.157.1\n\n\n\n","body_html":null,"content_hash":"56a32564e76ab2d25fe33eb4e4311db1c9e4f2a443bbbdfca7619d94636f19b5","updated_at":"2026-10-05T08:38:02.977Z"},{"id":"7956aed6-589d-41da-a2c9-38eacdd01b09","source_id":"claude-code","dedupe_key":"claude-code:2.1.283","version":"2.1.283","title":"claude code 2.1.283","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21283","published_at":"2026-09-25T18:46:11.330Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added `x-claude-code-prompt-id` to the gateway hint headers so LLM gateways can group the requests that serve one user prompt; opt in with `CLAUDE_CODE_GATEWAY_HINT_HEADERS=1`\n- Added `availableModelsMatch` managed setting: with `\"exact\"`, an `availableModels` entry allows only the model version it names, so new releases stay blocked until listed\n- Added `deniedModels` managed setting to block specific models, even when `availableModels` allows them\n- Added MCP tool, WebFetch and WebSearch outputs to the `tool.output` OpenTelemetry span event when `OTEL_LOG_TOOL_CONTENT=1`\n- Added `/doctor prompt-audit` (also `/checkup prompt-audit`) to audit your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models\n- Added click-to-expand for truncated messages from your other sessions in fullscreen mode\n- Added `path` to `--plugin-dir` load-failure entries in the stream-json `system/init` `plugin_errors`, naming the directory that did not load\n- Added an opt-in `load_test_mode` block to the Claude apps gateway config: requests are built and signed but not sent upstream, and clients get a canned reply, so a deployment can be load tested\n- Added a `mantle` upstream provider to the Claude apps gateway for Amazon Bedrock's Mantle endpoint\n- Fixed SDK sessions losing a deferred tool call or finished tool result when a turn ended early, a held approval prompt after a worker restart, and a non-streaming fallback's `result.usage`\n- Fixed MCP progress notifications being discarded once a long-running tool call moved to the background; the background task now shows the latest progress\n- Fixed stdio MCP servers being left running when the session ended while they were still starting\n- Fixed a brief HTTP 404 from a stateless remote MCP server (for example a proxy mid-redeploy) leaving that server unusable for the rest of the session while still shown as connected\n- Fixed MCP sign-in for a server with no valid URL failing with an opaque SDK error; `/mcp` no longer offers Authenticate for such servers\n- Fixed the weekly Fable limit not appearing in `/usage` and the VS Code usage meters when telemetry is disabled\n- Fixed `/model` accepting Sonnet 4.6 or Sonnet 5 with `[1m]` when the id carried a date or `-v1:0` suffix, in the cases where the plain id was refused\n- Fixed `/model` picker showing a hardcoded Haiku version and price when `ANTHROPIC_DEFAULT_HAIKU_MODEL` pins a different model\n- Fixed dynamic workflows started during a model fallback running every agent on the fallback model instead of retrying the configured model\n- Fixed `DISABLE_PROMPT_CACHING_HAIKU` having no effect when Haiku is the session's main model\n- Fixed `claude plugin validate` saying Claude Code accepts a plugin or marketplace name it cannot install; such names in `marketplace.json` now fail validation\n- Fixed `claude plugin validate` passing plugins whose `outputStyles`, `themes`, `monitors`, or `lspServers` paths are missing or point outside the plugin directory\n- Fixed `claude plugin details` showing 0 MCP servers for plugins that declare their servers in `plugin.json`\n- Fixed `claude plugin marketplace remove` not saying which installed plugins it uninstalled with the marketplace; it now lists them\n- Fixed `claude plugin uninstall` removing the other of two installed plugins whose ids differ only in case, with its options and secrets, when the one named had no `enabledPlugins` entry at that scope\n- Fixed plugins that declare no version being silently restored at their source's newest commit, not the installed one, when their cached files were missing\n- Fixed user-installed plugins and marketplaces failing to load with \"cache-miss\" after the home or config directory was moved, for example in bind-mounted devcontainers\n- Fixed `installed_plugins.json` showing no plugins when it holds a record under an invalid plugin id; such a file loads again\n- Fixed `installed_plugins.json` being rewritten, losing records, when it holds a record this version cannot read; `claude plugin` commands now name the record and say how to recover\n- Fixed permission dialogs in screen-reader mode reading quoted commands and paths as if they were the dialog's own text\n- Fixed `/context` not counting MCP server instructions: they now appear as their own row and count toward the total\n- Fixed markdown links in the Warp terminal rendering as plain text instead of clickable hyperlinks\n- Fixed `claude mcp add`, `add-json`, and `remove` reporting success when the user or local config file could not be written, for example inside a sandbox\n- Fixed the first words of a reply in a cloud session sometimes appearing late instead of streaming as Claude writes them\n- Fixed Claude's built-in keybindings guide saying chords time out after 1 second instead of 3, and calling `cmd` an alias of `meta`, which could produce `cmd+` shortcuts most terminals never send\n- Fixed `keybindings.json` silently accepting a misspelled modifier such as `ctl+k`; it now warns in the debug log and suggests the fix\n- Fixed footer hints still saying \"Enter to view\" after `footer:openSelected` was rebound or unbound in `keybindings.json`\n- Fixed keys typed quickly together (type-ahead, key repeat, bursts over ssh or tmux) sometimes being handled against stale state\n- Fixed worktree checkouts failing certificate verification (for example on Git LFS downloads) when the CA certificate is passed to git as `GIT_CONFIG_COUNT` environment pairs\n- Fixed sandboxed `git` asking credential helpers to store the sandbox proxy's login, which printed \"failed to store\"\n- Fixed managed `sandbox` settings being ignored entirely when one nested value was invalid; the invalid value now fails closed and the rest of the block still applies\n- Fixed Claude's edits to its own auto-memory notes being blocked as sensitive-file writes when Claude Code was started in a subdirectory of a git repository\n- Fixed Remote Control being unavailable on paid plans when telemetry is turned off with `DISABLE_TELEMETRY` or `DO_NOT_TRACK`\n- Fixed the `/remote-control` menu cutting its QR-code hint mid-word in narrow terminals\n- Fixed vim mode `.` dropping a Shift+Enter newline, leaving the cursor inside an accented letter, and repeating an older change after `3J` or Visual-mode `J` on the last line\n- Fixed vim mode cursor placement: recalling a prompt over 10,000 characters in normal mode no longer leaves the cursor past the end, and `V` then `p` now lands on the first non-blank\n- Fixed vim mode `J` joining lines with different spacing than Vim (such as a space before `)` or after a tab), and `3J` or Visual-mode `J` on the last line not moving the cursor as Vim does\n- Windows: Fixed the PowerShell tool letting `cmd /c rd`, `rmdir`, `del` or `erase` delete drive roots, the home folder and other folders that `Remove-Item` refuses\n- Improved the `/mcp` tool list: it shows more tools at once, scrolls with the page keys and mouse, and marks tools your organization blocked with a warning icon\n- Improved MCP tool results: images returned by MCP tools are now also saved to a file, so Bash, Read and other tools can open them\n- Improved `/tasks`: rows show a status icon, the name and whole facts, the title and key hints stay on screen with many tasks, and the list gains paging keys, the mouse wheel and clicks\n- Improved lists in `/help`, `/hooks`, `/copy`, `/chrome`, `/memory`, `/ide`, `/release-notes`, `/rewind`, `/diff`, `/remote-env`, `/plugin` and other pickers with page keys, mouse wheel and clicks\n- Improved lists beside a search box, such as `/skills` and `/artifacts`, to draw their pointer dim while the search box has the keys, so only one pointer is highlighted\n- Improved the compaction spinner: its timer now starts when compaction begins and it counts the summary's tokens as they stream, replacing the percentage bar\n- Improved the browser page shown after signing in to an MCP server: centered layout, dark mode, and new artwork\n- Improved the Skill tool's reply when a skill belongs to a plugin that failed to load, so Claude tells you the plugin could not be loaded instead of calling the skill uninstalled\n- Improved `prompt-audit` on Claude Code configuration: stale paths, stale commands and contradicting instruction files now lead the report, and thinking keywords that Claude Code documents are kept\n- Improved recovery from an `installed_plugins.json` that cannot be read at all: its contents are kept in a file beside it before it is rebuilt, and `claude plugin list` names that file\n- Improved artifact database reads: an ordered query that returns a full page now says it is one page and how to read the rest\n- Improved first-reply latency: a pattern-compile step that ran at the end of a session's first reply now runs while the reply streams in\n- Improved first-request latency by reusing the preconnected API connection\n- Improved startup: `claude -p` and Claude Code Remote no longer load the interactive UI, and the auto-mode classifier's rules and the Artifact tool load on first use instead of at launch\n- Improved startup for claude.ai accounts whose Artifact tool features aren't known yet, as on a first run: the prompt no longer waits up to 1.5 s to check them; the first message waits if needed\n- Changed interactive sessions on third-party providers or with telemetry off to start in auto mode when no permission mode is configured; `permissions.defaultMode` still overrides it\n- Changed the `/ultrareview` launch dialog to say that reviewing a local branch may upload uncommitted changes to tracked files\n- Changed the `/model` picker's Opus row and the Default model's name to drop \"(1M context)\" where Opus already has a 1M context window; the window is unchanged\n- Changed prompt suggestions in the terminal to appear less often after 20 in a row go unused; using one brings them back\n- Changed `--system-prompt` and `--append-system-prompt` to accept their text and `-file` forms together; the file's text comes first\n- Changed `Skill(anthropic-skills:<name>)` deny rules to also block that skill when Claude Desktop delivers it as a plugin, and `Skill(skill:<name>)` denies to match the skill's alias and display name\n- Changed `/rewind` and `/diff` lists to move on the same keybinding actions as every other list (`select:*`); `messageSelector:*`/`diff:*` rebinds still work\n- Changed the `/workflows` run list to size itself like other lists: half the terminal inline, and it keeps its title on screen when the prompt shows below\n- Changed `claude plugin eval` to require git 2.31 or later when git is installed; a run on an older git is refused with a message naming the version\n- Changed artifact watching: a watch that was armed automatically (not one you asked for) now ends after 3.5 hours with no activity; publishing or watching the artifact again re-arms it\n- Self-hosted runner: Changed lifecycle hooks' git to skip a repository's Git LFS `pre-push` hook, ignore a writable system `core.hooksPath`, and not sign commits without `--configure-git`\n- Self-hosted runner: Changed `GIT_SSL_CAINFO` and `GIT_SSL_NO_VERIFY` under Anthropic-managed git: the runner's own git always verifies Anthropic's git route, and warning lines say what applies where\n- Reverted the 2.1.282 reservation of the `claude-ai` name: skills, commands, workflows and MCP servers' skills and prompts so named load again, and `Skill(claude-ai:*)` rules are ordinary prefix rules\n- [VSCode] Fixed the permission mode indicator showing Default while the session kept running in auto or bypass mode after an automatic switch out of it failed; the switch is now retried until it lands\n- [VSCode] Fixed a session teleported from the web dropping the messages sent while Claude was working\n- [VSCode] Fixed a Web session staying hidden from the session list, and an empty chat opening in its place, when an older version had saved an empty local copy of it\n- [VSCode] Fixed a reopened session splitting a turn at a message Claude received mid-turn, such as an automatic continuation\n- [VSCode] Fixed a reloaded session showing a rewound-away turn, or only the rows before a compaction\n- [VSCode] Fixed the footer's agents pill drawing its icon off-center, with the status dot against the edge, in narrow panels\n- [VSCode] Fixed the chat input showing its text slightly below the cursor and selection after pasting lines that end with a line break into a long prompt\n- [Cloud sessions] Improved adding a repository to a running cloud session: a private repository your GitHub account can read but not push to now attaches for reading\n- [Cloud sessions] Fixed cloud sessions occasionally redoing an already-finished step, such as posting a duplicate comment or push, after recovering from a server-side restart\n- [Cloud sessions] Changed new routine schedules to default to a few minutes past the hour, with a note that routines set exactly on the hour can start several minutes late\n- [Claude Tag] Added a \"Channels Claude can search\" admin setting that limits Claude's Slack search to public channels it has been added to, set per organization, workspace or channel\n- [Claude Tag] Added a Back to Slack button on the page shown after connecting your Claude account, returning you to the thread you started from\n- [Claude Tag] Fixed a channel's configure page listing no connectors or plugins when the channel gets its access bundle through an attach rule; rule-attached bundles are now shown\n- [Claude Tag] Fixed access-bundle repository search missing repositories on GitHub App installs that are limited to a large list of selected repositories\n- [Claude Tag] Fixed Claude occasionally posting the same reply twice when a new message interrupted it mid-reply\n- [Claude Tag] Fixed channel routines that stopped running in older private channels whose Slack channel ID changed, for example after a Slack Connect share\n- [Claude Tag] Fixed conversations in a channel set to \"Channel only\" all ending when a non-guest member joined and Slack was slow to confirm their membership\n- [Code Review] Fixed \"@claude review\" requests going silent when GitHub failed to return the pull request: the request is retried once, and a comment explains if it still fails\n- [Code Review] Fixed billing for a review that stopped at its time limit with nothing verified: it now shows as incomplete, isn't charged, and is retried once","body_html":null,"content_hash":"f28a94e62c8f9a4ae05f5c158974ed44cb98ce8741a1f8b38a5063cd529969d0","updated_at":"2026-10-05T19:07:21.945Z"},{"id":"a63c466b-125e-4254-87ee-018d3147324a","source_id":"codex","dedupe_key":"codex:rust-v0.157.0","version":"0.157.0","title":"0.157.0","url":"https://github.com/openai/codex/releases/tag/rust-v0.157.0","published_at":"2026-09-25T02:31:06Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:38:02.977Z","body_md":"## New Features\n\n- Added GPT-6 Sol and Luna, including Amazon Bedrock support and migration prompts for older models. (#47332, #47347)\n- Enabled fullscreen transcripts by default and added Shift-click to extend text selections. (#47178, #47414)\n- Enabled automatic background-server startup for eligible interactive sessions, with recovery choices when server settings are incompatible. (#47179, #47318)\n- Added an `f` shortcut to fork conversations open in another app, preserving drafts and queued prompts. (#47185)\n- Made `/import` available in remote sessions and local background-server sessions. (#47317)\n- Improved terminal rendering with Unicode bullets, checkboxes, aligned equations, and optimization notation. (#47191, #47322)\n\n## Bug Fixes\n\n- Preserved active voice conversations when switching threads. (#47381)\n- Recovered unsent question answers into the composer when turns end, without disrupting active history searches. (#47422, #47423)\n- Respected tmux mouse settings and restored native scrollback for Terminal.app over SSH in automatic screen mode. (#47399, #47417)\n- Fixed configured proxy routing for realtime connections and standalone web search, including search redirects. (#47101, #47142, #47204)\n- Added retries for transient file-upload failures and increased the upload timeout to five minutes. (#47122, #47393)\n- Enforced network restrictions across redirects and ongoing HTTP and WebSocket traffic, including cancellation when policy changes revoke access. (#47389, #47407)\n\n## Changelog\n\nFull Changelog: https://github.com/openai/codex/compare/rust-v0.156.0...rust-v0.157.0\n\n- #47063 Add a partial index for agent message board root posts @jif-oai\n- #47064 Stop redundant message-board reads when limits reach one @jif-oai\n- #47065 Deduplicate deprecation notices in the TUI transcript @etraut-openai\n- #47068 Highlight selected newlines in the transcript view @etraut-openai\n- #47073 Wait for thread idle in Guardian context budget tests @jif-oai\n- #47074 Refresh host-supplied cloud skills at turn startup @TAFOYA-OAI\n- #47075 Include attributed previews in agent message board notifications @jif-oai\n- #47077 Serialize environment updates and cancel removed pending attachments @sayan-oai\n- #47079 Mask daemon socket paths exposed through ancestor bind mounts @nicksteele-oai\n- #47081 Track cumulative MCP attribution across requests and thread history @peilin-openai\n- #47082 Show the voice toggle in the TUI shortcut overlay @etraut-openai\n- #47083 Extract per-thread enrichment into a dedicated async helper @aibrahim-oai\n- #47084 Avoid building a host SQLite driver for SQLx macros @aibrahim-oai\n- #47085 Update model catalog descriptions and GPT-5.6-Sol priority @andrewgu-oai\n- #47086 Format analytics credit usage with consistent decimal precision @fcoury-oai\n- #47088 Disable unused default dependency features @aibrahim-oai\n- #47089 Centralize JSON-RPC response serialization through payloads @aibrahim-oai\n- #47094 Restrict Unix local MCP servers to stdio descriptors @yuzhu-oai\n- #47095 Remove the `rust-release-prepare` workflow @andrewgu-oai\n- #47096 Keep TUI hints immediately above the composer @fcoury-oai\n- #47100 Preserve assistant answers in bounded TUI task responses @etraut-openai\n- #47101 Honor configured proxies for realtime WebSocket connections @celia-oai\n- #47106 Preserve originating turn metadata for yielded skill calls @eddie-openai\n- #47108 Preserve required Windows runtime variables for filesystem helpers @iceweasel-oai\n- #47112 Lowercase the retry hint for conversations open in another app @fcoury-oai\n- #47113 Persist thread creator identity in rollouts and SQLite @nornagon-openai\n- #47114 Preserve and expose thread item lifecycle timestamps @chiam-oai\n- #47116 Honor the configured product SKU in remote plugin requests @jessedu-oai\n- #47118 Support model-catalog overrides for Code Mode tool messages @rhan-oai\n- #47121 Pass thread IDs to attachment uploads @kchainani-oai\n- #47122 Increase OpenAI file blob upload timeout from 60 seconds to 5 minutes @wilkes-oai\n- #47125 Add extra policy configuration for Guardian reviews @won-openai\n- #47129 Preserve foreign working directories in extension tool environments @anp-oai\n- #47130 Remove the `ultrafast` service tier from `gpt-5.6-sol` @andrewgu-oai\n- #47132 Support caller-provided MITM CAs in the network proxy @viyatb-oai\n- #47137 Prevent horizontal transcript selection from triggering autoscroll @imac-oai\n- #47142 Honor system proxy settings for standalone web search @celia-oai\n- #47143 Extract exec-server CLI startup into a dedicated module @anp-oai\n- #47149 Update code mode catalog snapshot hashes @andrewgu-oai\n- #47155 Ignore stale thread-close notifications after resuming a thread @etraut-openai\n- #47158 Harden gateway OAuth credential persistence and error redaction @alexsong-oai\n- #47159 Expose HTTP origins in MCP server status @frantic-openai\n- #47162 Apply workspace routing to Guardian v2 classifier requests @acrognale-oai\n- #47170 Add explicit gateway login control and authentication status @alexsong-oai\n- #47174 Preserve empty cell metadata under pending tool-call pressure @ningyi-oai\n- #47178 Enable the fullscreen transcript by default @etraut-openai\n- #47179 Enable automatic daemon startup by default @etraut-openai\n- #47185 Allow forking conversations locked by another app in the TUI @fcoury-oai\n- #47191 Render aligned equations and optimization notation in TUI math @etraut-openai\n- #47199 Separate thread preparation from execution persistence @dermanyang-oai\n- #47204 Resolve proxy routes for standalone web search redirects @celia-oai\n- #47207 Add explicit gateway OAuth sign-in to app-server @alexsong-oai\n- #47212 Preserve MCP request trace context across transport workers @bromano-oai\n- #47235 Route multi-agent spawning through `SpawnRequest` @jif-oai\n- #47236 Suppress agent message board notifications to the post author @jif-oai\n- #47240 Prevent V2 agent eviction from racing with queued messages @jif-oai\n- #47244 Centralize agent resume handling in `LocalAgentControl` @jif-oai\n- #47248 Add explicit app and account targets to MCP resource reads @victor-openai\n- #47249 Drop descendant channel posts from retained remote compaction v2 history @jif-oai\n- #47252 Return agent snapshots from `close_agent` @jif-oai\n- #47257 Preserve explicit message-board unsubscribes when posting @jif-oai\n- #47258 Test spawn settings reporting after child removal @jif-oai\n- #47259 Subscribe authors to message-board channels created by posting @jif-oai\n- #47263 Expose hosted plugin extensions in app-server summaries @victor-openai\n- #47267 Stream agent snapshots from local status subscriptions @jif-oai\n- #47271 Implement `AgentControl` for `LocalAgentControl` @jif-oai\n- #47272 Allow Guardian sync review across compaction hash differences @felixxia-oai\n- #47275 Enable Guardian thread context by default @felixxia-oai\n- #47281 Add regression coverage for message board unsubscribe persistence @jif-oai\n- #47287 Update the Guardian extra-policy snapshot for retained instructions @felixxia-oai\n- #47292 Consolidate agent operations in the `AgentControl` implementation @jif-oai\n- #47301 Separate local agent runtime state from controller handles @jif-oai\n- #47302 Use compact display metadata for Guardian review threads @charliemarsh-oai\n- #47303 Clean up legacy Guardian thread metadata in SQLite @charliemarsh-oai\n- #47317 Enable `/import` in remote and local daemon sessions @etraut-openai\n- #47318 Offer explicit recovery for incompatible background servers @etraut-openai\n- #47319 Match agent status symbols to the selected row style @etraut-openai\n- #47320 Fix Escape navigation in read-only agent sessions @etraut-openai\n- #47321 Honor the system clock preference across more TUI timestamps @etraut-openai\n- #47322 Render TUI Markdown lists with Unicode bullets and checkboxes @etraut-openai\n- #47323 Persist resume metadata in compaction checkpoints @owenlin0\n- #47325 Keep report reason tags within Sentry limits @ningyi-oai\n- #47326 Restrict MCP OAuth authorization endpoints to HTTP(S) @viyatb-oai\n- #47327 Preserve image generation request IDs on failure @chrisdong-oai\n- #47329 Standardize TUI menu description wording and punctuation @etraut-openai\n- #47330 Identify failed SQLite databases in `codex doctor` output @dkovalenko-oai\n- #47331 Avoid redundant spacing above the transcript composer @fcoury-oai\n- #47332 Add GPT-6 Sol and Luna to the model catalog @andrewgu-oai\n- #47338 Move the activity inspection hint into keyboard shortcut help @fcoury-oai\n- #47340 Add conditional turn interruption that preserves pending input @pmccrary-oai\n- #47342 Skip stored title lookups for ephemeral forks @keyz\n- #47347 Add GPT-6 Sol and Luna to Amazon Bedrock catalogs @celia-oai\n- #47348 Overlap subagent spawn persistence and clean up cancelled children @owenlin0\n- #47349 Move plugin recommendations into developer context @adaley-openai\n- #47350 Reuse cloud skill catalogs across turns until invalidated @hlevy-openai\n- #47353 Preserve `invalid_prompt` as a distinct error classification @rennie-openai\n- #47355 Reserve spacing after recaps at the transcript tail @fcoury-oai\n- #47358 Color paths and URLs in `codex doctor` by check status @dkovalenko-oai\n- #47360 Preserve user prompt URL destinations across terminal widths @fcoury-oai\n- #47361 Restrict Windows sandbox default object access to the logon session @viyatb-oai\n- #47362 Bound inbound exec-server requests across client transports @viyatb-oai\n- #47365 Resume model context from the latest compaction boundary @owenlin0\n- #47369 Overlap agent metadata reads when resuming a V2 root @vkg-oai\n- #47375 Add an opt-in preference for the local MXC sandbox @iceweasel-oai\n- #47377 Add opt-in reasoning status for realtime V3 delegations @guinness-oai\n- #47380 Route TUI voice controls through the app @etraut-openai\n- #47381 Keep voice conversations running across TUI thread navigation @etraut-openai\n- #47382 Show a voice badge in the agents overview @etraut-openai\n- #47384 Restore composer hints after clearing selection at the transcript bottom @fcoury-oai\n- #47389 Enforce network policy throughout HTTP and WebSocket requests @acrognale-oai\n- #47393 Retry transient OpenAI file blob upload failures @mtsui-oai\n- #47397 Refresh bundled model metadata and instructions @andrewgu-oai\n- #47399 Respect tmux mouse settings in fullscreen and overlays @fcoury-oai\n- #47407 Enforce application network policy across app-server requests @acrognale-oai\n- #47408 Enforce application network policy for AWS auth and telemetry @acrognale-oai\n- #47410 Honor network policy in remote control and recover remote execution @acrognale-oai\n- #47411 Apply shared network policy throughout embedded Codex startup @acrognale-oai\n- #47413 Cache decrypted gateway OAuth secrets per backend @charliemarsh-oai\n- #47414 Support Shift-click to extend transcript selections @etraut-openai\n- #47417 Use native scrollback for Terminal.app over SSH in auto mode @fcoury-oai\n- #47422 Recover unsent question drafts when TUI turns end @imac-oai\n- #47423 Preserve history search during background draft recovery @imac-oai\n- #47424 Clear pending async question notifications when turns end @imac-oai\n- #47428 Apply inherited environment settings at turn boundaries @sayan-oai\n- #47435 Allow environment selection updates during an active turn @sayan-oai\n- #47437 Stabilize retry timing and WebSocket tests @anp-oai\n\n\n","body_html":null,"content_hash":"22355e1000af29e92865433512270995bb334e26c279c4b060c2856edc8dd2c2","updated_at":"2026-10-05T08:38:02.977Z"},{"id":"96cfa549-9a63-402f-9ad0-247e5859e3ae","source_id":"grok","dedupe_key":"grok:safety_identifier-request-field","version":"update","title":"safety_identifier request field","url":"https://docs.x.ai/developers/release-notes#safety_identifier-request-field","published_at":"2026-09-25T00:00:00.000Z","date_reconciled":1,"digest_import":1,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T18:08:02.751Z","body_md":"You can now send safety_identifier, an opaque end-user identifier assigned by your application, on Chat Completions, the Responses API, deferred chat completions, the Batch API, and the gRPC GetCompletionsRequest. It lets SpaceXAI attribute a policy violation to one of your end users rather than to your API key. The legacy user field is still accepted. See the Security FAQ.","body_html":"<p>You can now send <code>safety_identifier</code>, an opaque end-user identifier assigned by your application, on Chat Completions, the Responses API, deferred chat completions, the Batch API, and the <a href=\"https://docs.x.ai/developers/grpc-api-reference/chat\">gRPC <code>GetCompletionsRequest</code></a>. It lets SpaceXAI attribute a policy violation to one of your end users rather than to your API key. The legacy <code>user</code> field is still accepted. See the <a href=\"https://docs.x.ai/developers/faq/security#how-do-i-identify-which-of-my-end-users-caused-a-policy-violation\">Security FAQ</a>.</p>","content_hash":"3db9f5ec48f7b85e8d539bf574d926543d2e3155f06f60d66631ba753de2a3a5","updated_at":"2026-10-05T19:07:18.890Z"},{"id":"92b4639a-f3b7-49ba-affd-6ec4d8345f0b","source_id":"claude-code","dedupe_key":"claude-code:2.1.282","version":"2.1.282","title":"claude code 2.1.282","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21282","published_at":"2026-09-24T15:56:22.706Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added a `maxProseWidth` setting that caps the width of Claude's prose in wide terminals while tables and code blocks keep the full width\n- Added a startup notice, and `/status` and `claude doctor` entries, listing telemetry variables in a project's settings files that were ignored or that turned telemetry off\n- Added the `allowClaudeInChromeWithManagedMcp` managed setting to let `claude --chrome` run alongside an exclusive `managed-mcp.json`; the error shown when Chrome is blocked now names it\n- Added `store.readiness_grace_seconds` to the Claude apps gateway so `/readyz` can stay ready through a short Postgres outage such as a database failover\n- Added a scrollbar to the `/feedback` drafts list in fullscreen mode; it appears while the mouse is over the list\n- Fixed every request failing with a 400 error in conversations whose history holds web search results the API cannot decrypt (for example, from a turn answered through a third-party gateway)\n- Fixed more cases of continued or resumed sessions (`--continue`, `--resume`) re-sending earlier messages in a changed form, which could make the API drop Claude's earlier reasoning\n- Fixed earlier extended thinking being dropped when `/model`, `/rename`, `/artifacts` or another immediate slash command was used while Claude was working\n- Fixed continued or resumed conversations losing earlier extended thinking when relaunched with a `--tools` list that leaves out a built-in tool offered earlier in the conversation\n- Fixed sessions failing on every turn with an \"Invalid `data` in `redacted_thinking` block\" API error; Claude Code now drops the conversation's thinking blocks and retries once\n- Fixed compaction failing when the summarization request is refused; it now retries on a fallback model\n- Fixed a failed turn (\"Effort 'xhigh' isn't available with thinking turned off\") after a safety-related model switch in sessions with thinking off and effort above high\n- Fixed an unanswered Fable usage-credits prompt switching models in SDK-hosted sessions such as Claude Desktop; the turn now ends instead, and Remote Control clients now see the model-switch notice\n- Fixed `/model` with a full Fable model id stopping at an API error instead of opening the usage-credits prompt when the plan needs usage credits that aren't turned on yet\n- Fixed requests failing for up to a minute with an \"another Claude Code process is refreshing it\" login error after that other process was closed or killed mid-refresh\n- Fixed sessions started while another Claude Code window was refreshing the sign-in (common with several VS Code windows) not retrying their organization policy fetch\n- Fixed CLAUDE.md and rules being read at startup through a repository symlink reaching macOS's `/Network` via `..` or a `/.vol`-style kernel path, or a rules link to macOS's `/home` being listed\n- Fixed Bash permission rules with a mid-pattern `:*` being skipped in settings files while `--allowedTools` honored them; they now work from every source, with a startup warning on how they match\n- Fixed a command approved on a restored permission prompt running twice when a remote session's worker restarted\n- Fixed managed settings ignoring a mistyped value for boolean lock keys such as `disableClaudeAiConnectors` or `allowManagedPermissionRulesOnly`; the lock now applies and startup names the key\n- Fixed managed `permissions`, `autoMode`, `worktree` and `attribution` settings being ignored entirely when one nested value was invalid; the rest of the block now still applies\n- Fixed repository, user and `--add-dir` skills, commands and skills-directory plugin manifests pre-approving their own tools via `allowed-tools` under managed `allowManagedPermissionRulesOnly`\n- Fixed safeguard block messages on Amazon Bedrock and Bedrock Mantle not showing a request ID; block messages now also show the message ID\n- Vertex AI: Fixed web search not being offered for models Claude Code doesn't recognize yet, such as newly released ones\n- Fixed Bash and PowerShell hiding a full disk quota behind \"Exit code 1\" and leaving large output files in temp\n- Fixed tool input validation errors naming only an unknown, missing or mistyped parameter when other parameters in the same call were also invalid; those are now listed too\n- Fixed pasted multi-line text being submitted line by line after the terminal's bracketed paste mode was reset mid-session\n- Fixed the prompt's example text flashing and disappearing at startup in projects with a `SessionStart` hook\n- Fixed a blank screen flashing before the first frame when starting in fullscreen mode\n- Fixed garbled, misplaced rows in the non-fullscreen renderer after the screen got shorter while still taller than the terminal, e.g. deleting a prompt line while a shell command streams output\n- Fixed a stale character left in the last column of a diff when a redrawn line's CJK character or emoji wrapped to the next row\n- Fixed the cursor landing before the end of a prompt recalled from history when the prompt contains a tab\n- Fixed the send-now hint showing ctrl+enter on terminals that send it as a newline (Windows Terminal before 1.25); it now shows ctrl+x ctrl+s there\n- Fixed `claude remote-control --debug` failing with \"Unknown argument: --debug\", although Remote Control's own eligibility error says to run with `--debug`\n- Fixed `/install-github-app` saying \"cancelled\" and then still pushing the branch and saving the API key secret; leaving now stops the remaining steps and reports what was already done\n- Fixed /feedback, /bug and /share on Bedrock, Vertex and other third-party providers still saving the report file after you cancelled during the save\n- Fixed plugin uninstall reporting success and deleting the plugin's saved options when its settings file still enabled it or could not be read; it now stops and names the file\n- Fixed plugin uninstall deleting a plugin's saved options and secrets when the list of installed plugins could not be read after the removal; they are now kept and the uninstall says so\n- Fixed a key typed right after `/` in `/skills` moving the skill list instead of reaching the search box\n- Fixed the terminal cursor jumping from the `/skills` search box to the skill list while typing, which could hide the caret and put IME input in the wrong place\n- Fixed lists with a scrollbar, such as `/skills` and `/mcp`, being two columns narrower outside fullscreen mode, where the scrollbar can never appear\n- Fixed the agent panel footer wrapping onto two lines with long rebound keys, and its \"Esc to collapse\" hint ignoring a rebound collapse key\n- Fixed a doubled ` · ` separator in the `/tasks` dialog footer when the stop-all-agents shortcut is unbound in `keybindings.json`\n- Fixed artifact publishes failing when Claude gave the version a label longer than 60 characters; the label is now shortened\n- Fixed screen-reader mode, quoted lists and very long lists dropping the blank lines at the top of a code block that opens a list item, directly or inside a quote\n- Fixed PDF page-read error messages: paths with accented or non-Latin characters now appear readably, and a folder named like \"password\" or \"invalid\" can no longer make the error name the wrong cause\n- Fixed vim mode `>>` indenting empty lines, `r` with a count longer than the line changing text, `2J` joining one line too many, and a count on the last line (`2dd`, `2>>`) shifting or deleting it\n- Fixed vim mode cursor placement: after `dd`, `dj`, `dG` or a whole-line `p`/`P` it lands on the first non-blank, `yy` no longer moves it, and Esc after an emoji no longer leaves it inside the emoji\n- Fixed vim mode ignoring a count typed before `.` when repeating `x`, `s`, `p`, `d` or `c`, and whole-line `p`/`P`, `o`, `O`, `J`, `>>` and `<<` acting on the wrong line when a line above wraps\n- Fixed vim mode leaving the cursor past the end of a prompt recalled from history or pulled back from the queue in normal mode, so `x` did nothing\n- Improved the time to resume very large sessions, including ones that were never compacted\n- Improved the error shown on Windows when a session can't be resumed because its transcript file could not be read (EBADF): it now names possible causes and what to try\n- Improved the Claude Desktop unknown-model error to suggest switching to a different model\n- Improved rendering of unusual Unicode in permission prompts\n- Improved `/artifacts`: titles line up in one column, details are dropped whole instead of cut mid-word, and the list supports PgUp/PgDn, Home/End, the mouse wheel and clicks\n- Updated the `claude-api` skill: pre-output refusal billing now links to the How refusals are billed docs, mid-stream refusals bill at normal rates, and pre-output refusals count against rate limits\n- Updated the `claude-api` skill to recommend `ant apply` for keeping Managed Agents resources as version-controlled files\n- Changed auto mode to use the server-side classifier by default on a direct Anthropic API connection when telemetry is off (`CLAUDE_CODE_AUTO_MODE_SERVER=0` opts out)\n- Changed `sandbox.excludedCommands` to ignore project and local settings entries when managed settings or `--settings` set `allowUnsandboxedCommands: false`, or managed `allowManagedDomainsOnly: true`\n- Changed project and local settings to ignore OpenTelemetry variables that turn on export, set its endpoint, or capture content, like `CLAUDE_CODE_ENABLE_TELEMETRY` and `OTEL_LOG_*`\n- Changed Windows/WSL managed settings so an admin policy that is present but invalid or unreadable (HKLM, `managed-settings.json`) keeps user-writable HKCU and WSL `/etc/claude-code` from applying\n- Changed `Skill(anthropic-skills:*)` and `Skill(claude-ai:*)` allow rules to cover only skills synced from claude.ai, not plugins or other skills that merely use such a name\n- Changed skill folders, command files and workflow commands in the `anthropic-skills` or `claude-ai` namespace to no longer load; a plugin so named still loads but yields name ties to synced skills\n- Changed MCP servers configured under the name `anthropic-skills` or `claude-ai` to list no skills or prompts (their tools still work); rename the server in your MCP configuration to list them again\n- Changed the `ultracode` visuals in `/effort` and the prompt input to plain styling (no ripple, border flourish or keyword glimmer) and removed the dynamic-workflows spinner tip\n- Changed the Clawd mascot's feet in the start-up banner to sit under the corners of his body\n- [VSCode] Fixed long replies falling behind the stream: the panel no longer re-parses the whole reply on every update\n- [VSCode] Fixed the dictation mic button covering the message input's scrollbar when the input is tall enough to scroll\n- [VSCode] Fixed Remote Control sessions started on this computer not opening from their Web entry in the session list; they now open the local conversation unless it's running elsewhere\n- [VSCode] Fixed an editor tab's sign-in screen hanging silently after the extension host restarts; it now shows the \"stopped responding\" notice too\n- [Cloud sessions] Added Claude GitHub App status to Settings › Connectors › GitHub: whether the app is installed and reachable for your account, plus steps to connect, install or reconnect\n- [Cloud sessions] Added \"Open repository\" and \"Open compare page\" links to the repository menu of a cloud session whose repository is hosted on a Git server other than GitHub\n- [Cloud sessions] Added attaching a repository from a different GitHub owner, such as a fork's upstream, to a running cloud session that already has one, including sessions started from Slack\n- [Cloud sessions] Fixed the next run time shown for an hourly routine being 30 minutes off for people in half-hour-offset time zones such as India\n- [Cloud sessions] Improved how quickly the Routines page and the sidebar's Scheduled list load for accounts whose past sessions scheduled many check-in reminders\n- [Claude Tag] Fixed auto-join channel patterns saved for one workspace in Claude Tag admin settings being ignored on an Enterprise Grid org-wide install; Claude now joins matching new channels\n- [Claude Tag] Fixed Claude not responding in an Enterprise Grid channel shared between two workspaces of one organization when the channel's Claude Tag version was saved from the other workspace\n- [Claude Tag] Fixed the earlier Claude in Slack app's progress card for sessions on a GitHub Enterprise Server repository: it now names the repository and offers a working Create PR button\n- [Claude Tag] Fixed Slack threads whose model has been retired falling back to another model on every reply, slower and with a fallback note each time; the thread now moves to a working model\n- [Claude Tag] Fixed files Claude uploads to Slack not being able to carry a caption containing a table; captions now render with the same formatting as replies\n- [Claude Tag] Fixed Claude's threads in Slack's Agents & tools view sometimes being listed under their first message instead of their name; later renames now update the list too\n- [Claude Tag] Fixed removing a GitHub organization's grant from an access bundle's Repositories tab in Claude Tag admin settings failing to save after that GitHub organization was disconnected\n- [Claude Tag] Fixed Claude always replying \"Couldn't check this channel just now\" in a channel shared with a Grid workspace it isn't added to; the notice now says which workspace needs the app\n- [Claude Tag] Fixed the cost and token totals in Claude's reply footer reading many times too high after the session's cloud worker restarted\n- [Claude Tag] Changed the bordered cards Claude uses in Slack replies for plans, tables and details to render wide by default instead of a narrow width\n- [Claude Tag] Changed newly connected Slack workspaces to follow the current default model instead of keeping whichever model was the default when they were connected","body_html":null,"content_hash":"c603d10dce59a5e4febb782c95fd227888ec67610b2c8ba837dfa17852da9e8b","updated_at":"2026-10-05T19:07:21.945Z"},{"id":"83394a51-85a1-4c1a-bd6f-43aa1ec16519","source_id":"claude-code","dedupe_key":"claude-code:2.1.281","version":"2.1.281","title":"claude code 2.1.281","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21281","published_at":"2026-09-23T17:01:17.780Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added Claude apps gateway support for newer Claude Desktop keys in `desktop` policy blocks, including `blockReadsOutsideWorkingDirectories` and `disableBypassPermissionsMode`\n- Added `assume_role` on Claude apps gateway Bedrock upstreams: the gateway calls Bedrock as an IAM role it assumes through STS, in another AWS account if needed, optionally one session per developer\n- Added `guardrail: {id, version}` on Claude apps gateway Bedrock upstreams to apply an Amazon Bedrock guardrail to every request sent through them (set it on all Bedrock upstreams or none)\n- Added `telemetry.resource_attributes` to the Claude apps gateway config, to put fixed labels on the telemetry of Claude Desktop and `/login` sessions\n- Added `\"attribution\": false` in `settings.json` to hide all commit and PR attribution; older CLI versions skip a settings file that holds it, so keep the object form in files shared across versions\n- Added MCP URL-mode elicitation on 2026-07-28 protocol connections, so servers can ask Claude Code to open a browser-based flow; no waiting dialog is left on screen when the server has no way to confirm completion\n- Added MCP server checks to `claude plugin validate`: it reports `.mcp.json` entries that would be silently dropped at load, undeclared `${user_config.*}` references, and insecure URLs\n- Added an auto mode recommendation to `/insights` that estimates how many permission prompts auto mode could have handled in your recent sessions\n- Added a scrollbar to the `/skills`, `/mcp` and `/plugin` Installed lists in fullscreen mode, like the one `/workflows` now has: it appears while the mouse is over the list and can be clicked or dragged\n- Fixed a crash (\"unrecoverable interface error\") that could end a session while an API request was being retried\n- Fixed a turn that could retry indefinitely, ignoring `--max-turns`, when the model alternated unparseable tool calls and output-limit truncation\n- Fixed resumed sessions re-sending earlier turns in a changed form (a parallel tool-call turn, an MCP tool call's input or a tool-search result while its server was still reconnecting, or a tool-search result whose loading turn was interrupted), which could make the API drop the conversation's prior reasoning\n- Fixed resuming a very large session sometimes restoring only its last few messages\n- Fixed a session resumed after a restart during a pending permission prompt sending a different history than before, which broke the prompt cache from that point\n- Fixed resuming a session that ended during a tool call: Claude now sees the call and is told its outcome is unknown, and a manual resume no longer adds a hidden \"Continue\" message\n- Fixed sessions with an earlier advisor result the API could no longer read failing one request every turn and repeatedly losing earlier reasoning; the history is now repaired once\n- Fixed the prompt cache being lost when an MCP server disconnects mid-conversation, or is still connecting after a resume, while tool search is off (for example behind a proxy or gateway)\n- Fixed responses cut short by a proxy or gateway that closes the stream cleanly being shown as complete with no warning, and tool calls running twice on duplicated stream events\n- Fixed responses failing with \"Content block not found\" when a proxy drops a stream event mid-response; the partial response is now kept, and web search keeps results that already arrived\n- Fixed an empty completed response being requested twice when the connection dropped before the stream's final event\n- Fixed the stop reason being lost when a proxy sends a trailing usage-only frame\n- Fixed `CLAUDE_CODE_RETRY_WATCHDOG` sessions failing on the first 5xx or dropped connection after a run of 429/529 waits, and sleeping uncapped and silently on a long `Retry-After` from a 5xx\n- Fixed fast mode retrying rate-limited requests back to back when the server sent `Retry-After: 0`\n- Fixed a tool that returned an oversized image leaving sibling tool calls unanswered and still running, or ending the turn with no final message\n- Fixed conversations getting permanently stuck on \"tool_use.name: String should have at most 200 characters\" after the model called a tool by an overlong name\n- Fixed tool calls failing with \"Failed to get memory usage\", or being reported as failed after they ran, when Claude Code cannot read its own memory usage, for example when it has run out of file descriptors\n- Fixed `--input-format stream-json` sessions (Agent SDK, VS Code extension) and scheduled cloud sessions failing every turn with an error when an earlier assistant message had plain-string content\n- Fixed non-interactive sessions (`-p`, Agent SDK) failing on the next turn after the directory they were started in was deleted mid-session\n- Fixed headless sessions with host-side (SDK) MCP servers stalling on the first message when the host stops responding mid-handshake; remote sessions now wait a few seconds at most\n- Fixed interactive startup waiting on the managed-settings network request (about 80 ms, 17+ seconds when the network is unreachable) when no MCP servers or plugins are configured\n- Fixed a delay of up to two minutes before responding when reading or @-mentioning a PDF larger than 3 MB\n- Fixed an interrupted Read of specific PDF pages leaving its page render running for up to two minutes\n- Fixed permission dialogs and attachment checks reading a path under macOS's `/.vol`, `/.nofollow` or `/.resolve` (which can reach a network mount) before approval\n- Fixed a recursive `rm` whose target is only command-substitution output, such as `rm -rf \"$(pwd)\"`, running unprompted in auto and `--dangerously-skip-permissions` mode; it now asks even with a Bash allow rule, unless run with `CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT=1`\n- Fixed a permission rule containing a NUL byte being expanded into a wildcard match; such a rule now matches nothing\n- Fixed sandbox `excludedCommands` entries not matching `git rev-parse --git-dir`, programs named like shell builtins, and commit messages containing `[WIP]` or `#` lines\n- Fixed sandboxed Bash commands being unable to write to `$TMPDIR` when `CLAUDE_CODE_TMPDIR` is set\n- Fixed `claude --bg` starting a background session, and running its project hooks, in a directory that had not passed the workspace trust prompt; it now asks for trust first, or exits when not run interactively\n- Fixed `--setting-sources` (and SDK `settingSources`) not being forwarded to spawned sessions: teammates, `/bg`, `claude agents` sessions and `--worktree --tmux` now start with the parent's restriction\n- Fixed Read, Write, Edit and NotebookEdit: a file path containing a null byte now fails that tool call with a clear error instead of ending the whole turn\n- Fixed Write refusing a call that gives the file path or content twice under two parameter names with identical values\n- Fixed CLAUDE.md and rules files from an `--add-dir` directory inside the working directory being sent to the model twice in headless and SDK sessions\n- Fixed remote sessions staying on \"needs approval\" with a stale prompt after a permission prompt and a sandbox network-access prompt overlapped and both were answered\n- Fixed cloud sessions not telling Claude about background agents that finished just before a worker restart\n- Fixed scheduled routine and notification turns in remote sessions not receiving turn-start notices (newly available tools, MCP changes, date, todos) until after the first tool call\n- Fixed scheduled tasks and `/loop` wakeups being fired again every second when their delivery failed, which could make Claude Code exit at the end of a turn\n- Fixed Remote Control reporting \"disabled by your organization's policy\" when the org policy simply hadn't loaded yet; it now retries the fetch and says it couldn't verify\n- Fixed the Artifact tool missing from Remote Control sessions that `claude remote-control` starts for you to open from Claude Desktop, claude.ai or the mobile app\n- Fixed macOS credential writes dropping stored MCP OAuth tokens or deleting the keychain entry when the login keychain was locked (e.g. right after wake)\n- Fixed `gcpAuthRefresh`/`awsAuthRefresh` login processes being left running (and holding their localhost callback port on Windows) when Claude Code exits or the refresh times out\n- Fixed the \"Not logged in · Run /login\" footer and missing claude.ai connectors persisting in a session after logging in from another Claude Code process\n- Fixed `mcp_tool` hooks on blocking events (PreToolUse and similar) being skipped while their MCP server was still connecting; they now wait for it, up to the MCP connect timeout\n- Fixed the same MCP server being connected twice when a plugin or claude.ai connector and a configured server spell its URL differently (host letter case, default port, trailing slash)\n- Fixed `MCP_CONNECTION_NONBLOCKING=0` giving up on claude.ai connectors after 1s instead of honoring `MCP_CONNECT_TIMEOUT_MS`\n- Fixed `--channels` plugin entries being checked against the installed plugin's marketplace alone; the installed plugin's name must now match the entry as well\n- Fixed `--plugin-dir` on a folder of plugins that also has a `.claude-plugin/marketplace.json` loading one empty plugin instead of the plugins in it\n- Fixed `claude plugin uninstall` refusing to remove a project-scope plugin that isn't enabled, saying it is \"enabled at project scope\" while `claude plugin disable` says it is already disabled\n- Fixed `claude plugin update` failing for project-scoped plugins when `--scope` is omitted — it now resolves the scope the plugin is installed at instead of assuming user\n- Fixed `claude plugin validate` reporting `privacyPolicyUrl`, `supportUrl` and other listing metadata keys in plugin.json as unknown fields\n- Fixed `known_marketplaces.json` recording a marketplace as refreshed when its remote could not be reached and `CLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILURE` kept the existing clone\n- Fixed the `/plugin` Errors tab showing no confirmation after its last error is resolved\n- Fixed `/plugin` starting a second uninstall or update of the same plugin when Enter was pressed again while the first was still running\n- Fixed a `y` held while `/plugin` checks a marketplace source adding the marketplace the instant the \"Add marketplace?\" question appears, before it can be read\n- Fixed `1` answering Yes in `/permissions`' delete and remove-directory confirms while the pointer is on No, which let a held `1` remove one workspace directory after another\n- Fixed Alt+T and `/config` offering to turn thinking off on models that can't; thinking now stays on there, with a one-line reason in place of the switch\n- Fixed `/context` total leaving out messages added since the last response; it now matches its categories and can read higher than the status line\n- Fixed `/model` showing the raw API error JSON and request ID when the API refuses the picked model; it now shows the server's message and says the model was not changed\n- Fixed API errors from an HTML error page (such as a proxy's 429 or 502 page) printing the page's raw markup or leaving out the HTTP status, and error messages breaking onto a second line when the server's error text ended in a newline\n- Fixed /feedback, /bug and /share still sending your report after you cancelled it while it was being sent\n- Fixed /feedback, /bug and /share failing every send with \"Couldn't send feedback\" after a Remote Control Stop arrived while the dialog was open\n- Fixed `/ide` showing \"No available IDEs detected\" while also listing a running IDE\n- Fixed the terminal being left in a broken state (crash or garbled input) when `/setup-bedrock` or `/setup-vertex` restarts Claude Code to apply new settings\n- Fixed `/config` exiting when `respectGitignore` or `copyFullResponse` in `~/.claude.json` holds `null`\n- Fixed the session name from /rename disappearing while Claude asks a multiple-choice question, so side-by-side sessions stay identifiable\n- Fixed one-line pastes showing on their own lines in the sent message for prompts from VS Code or Remote Control and for expanded paste placeholders\n- Fixed a message queued while Claude is working losing or changing the IDE selection it was written with, and queued messages not showing their selection\n- Fixed pressing Shift+Tab twice quickly landing on the wrong permission mode\n- Fixed Ctrl+C or Ctrl+D pressed twice quitting Claude Code instead of closing the dialog in the remaining dialogs and pickers, such as `/memory`, `/hooks`, `/mcp` (including a server's sign-in screen), `/export`, `/copy`, `/theme`, and `/teleport`'s uncommitted-changes and login prompts (where Esc also quit)\n- Fixed keys that arrive in one burst of input (e.g. over Remote Control), such as an arrow key followed by Enter, `x` or `s`, acting on the previous selection: a stale effort level in `/effort` and the model picker, and the previously highlighted row in `/skills`, the background task rows under the prompt, MCP server prompts and `/install-github-app`\n- Fixed `/install-github-app` updating the workflow after \"Skip workflow update\" was chosen, running setup twice on a repeated Enter, and ↑ on the repository step blocking a typed repository name when no repository was detected\n- Fixed vim mode: `dj`/`dk`/`dG`/`dgg` and their `c`/`y` forms acting on part of a line; `1G` going to the last line; `d0`/`c0`/`y0` doing nothing; the cursor being off by one after `.` repeats an insert; and `o`/`p` on a `!`-prefixed line switching to shell mode\n- Fixed vim mode `cw` on a space, an empty line, a word's last letter or a one-letter word also changing the next word; word motions stopping inside words in Hindi, Bengali and other scripts; and `.`, `p` or `P` that inserts text starting with `!` switching to shell mode, losing text or editing the wrong character\n- Fixed the prompt cursor moving one character too far after an accent typed as its own key\n- Fixed an extra blank line above a list item whose text starts on the line after its bullet, in screen-reader mode, quoted lists and long lists\n- Fixed bulleted lists of plain numbers (like `- 316.`) showing as letters, roman numerals or the wrong numbers\n- Fixed the agent panel's footer hint ignoring keys rebound in `keybindings.json`, and showing a stray ` · ` when the stop-all-agents shortcut is unbound\n- Fixed the agent panel footer offering \"Enter to view\" and \"x to stop\" on the agent you are already viewing (where x types into its input), and \"Enter to view\" on the main row when main is already shown\n- Fixed a mouse click on an agent-panel row leaving the keyboard cursor on the previously selected row\n- Fixed Esc interrupting the running turn instead of deselecting the selected agent-panel row\n- Fixed PgUp and PgDn doing nothing in a dialog's list (for example `/skills`) in fullscreen mode\n- Fixed `/heapdump` summary saying most memory is native when it is in the JS heap snapshot\n- Fixed Bash edit-diff snapshot directories piling up in the temp folder: abandoned ones are now deleted right away and the rest when Claude Code exits\n- Fixed /workflows moving the pointer to a different run, and `x` stopping it, when a new run started while the list was open\n- Fixed the selected tab in tabbed dialogs (`/config`, `/plugin`, `/permissions`) showing no highlight while the tab bar has focus when color is off (`NO_COLOR`)\n- Fixed the mouse wheel over the `/plugin` Installed list scrolling the pane behind it instead of the list\n- Fixed the hover highlight lingering on a list row in fullscreen mode after scrolling or filtering moved it away from the mouse\n- Fixed long list rows, such as in the /remote-control menu, wrapping onto a second line in narrow terminals; they're now cut with …\n- Fixed `/hooks` and `/mcp` detail views printing a long value over the row below it in narrow terminals\n- Fixed lists such as a skill's state options in `/plugin` not being answerable by typing a number in screen-reader mode\n- Windows: Fixed Bash commands that write to `$TMPDIR/…` failing with \"Permission denied\"\n- Windows: Fixed a race in which Claude Code sessions updating at the same moment could delete each other's `claude.exe` backup, which could leave no `claude.exe` behind\n- Improved Claude Desktop sign-in and usage-limit error messages to point at the app instead of terminal commands\n- Improved startup: managed settings and policy fetches no longer retry requests that can never succeed\n- Improved interactive startup time: git reads, startup telemetry and the Bedrock/Vertex model-upgrade checks no longer run before the first frame\n- Improved the time to resume long sessions that read many files; the restored file cache now matches the files as they were read\n- Improved the time to resume very long sessions that have been compacted, most noticeably through the Agent SDK and Claude Desktop\n- Improved \"Prompt is too long\" recovery in sessions dominated by one very large first prompt: that prompt is now summarized on its own instead of being left out of the summary\n- Improved auto mode after resuming a session in a new process: the permission classifier can now reuse its earlier prompt cache instead of rewriting it\n- Improved the auto mode denial message so Claude treats a denial as covering the outcome, not only the exact command\n- Improved the dangerous-rm check to also flag a removal at a shell variable followed by a top-level directory name, at a variable derived from the working directory, or at a backslash-only target\n- Improved sandbox guidance on macOS: when a local dev server can't bind a port, Claude now points to `sandbox.network.allowLocalBinding`\n- Improved `--agents` to accept the path to a JSON file (with `-p`) as well as inline JSON, and to allow an empty `prompt`\n- Improved `/batch` to run where a WorktreeCreate hook provides the agent worktrees, not only inside a git repository\n- Improved plugin hook-failure errors to name the offending plugin, and added a `claude plugin validate` warning when a shell-form hook leaves `${CLAUDE_PLUGIN_ROOT}` unquoted (it breaks on plugin paths with spaces)\n- Improved the `/` menu, `/skills`, `/context` and the `/plugin` Installed list to show skills synced from claude.ai by their short name when no other command uses it, not `anthropic-skills:<name>`\n- Improved `/deep-research` reliability on long research briefs by removing unused required fields from the scope step's output\n- Improved the writing in published artifact pages: the bundled artifact-design skill now asks Claude for plain, direct prose\n- Improved artifact publishing on slow connections: large page uploads are now sent compressed\n- Improved the large CLAUDE.md startup notice to also count instruction files together, so many mid-sized files and @-imports are caught\n- Improved debug logs to name settings `env` variables ignored because the session's launch environment already sets them\n- Improved keyboard navigation in tabbed dialogs such as `/permissions` and `/usage`: ↑/↓ move focus between the tab row and the content, and a list responds to keys only while it has focus\n- Improved `/help` and `/sandbox`: ←/→ and Tab switch tabs from inside a tab's list, and ↓ on an empty Custom commands tab in `/help` no longer leaves the keys stuck until Esc\n- Improved `/install-github-app`, `/desktop`, the `/permissions` auto mode environment prompts, and the `/plugin` \"Add marketplace?\" and \"Run this command?\" prompts: they now use the standard dialog frame with key hints, and Ctrl+C or Ctrl+D cancels them on the second press like other dialogs\n- Improved the `/workflows` and `/mcp` lists: they page (PgUp/PgDn, Home/End) and take j/k and the mouse like other lists, their arrows follow `select:previous`/`select:next` rebinds, and `x` in `/workflows` stops the run the pointer is on\n- Improved the `/plugin` plugin and marketplace details menus and the `/remote-control` already-connected menu: they now support Home/End and clicking a row\n- Improved the background workflow row below the prompt: it now shows the name, a progress bar, the agent count on wide terminals, elapsed time, total tokens, and the large-workflow warning\n- Improved the /plugin Installed list: rows now line up in columns (status, name, type, details) across every section\n- Improved `/skills`: each row now leads with the skill's name, with ✔ or ◯ alone showing on or off, and stays on one line in narrow terminals\n- Improved narrow list rows (`/skills`, `/workflows`, `/feedback`): a name keeps 20 columns beside its first detail, and details are shown whole or not at all\n- Improved `/diff`: a scrollbar shows where you are in a long list of changed files, and long paths no longer wrap their rows\n- Improved `/hooks`: a hook's detail screen now says what kind of hook it is and where to change it, instead of always pointing at settings.json, and the hooks-disabled, safe mode and managed-hooks-only notices each say what is happening in one plain sentence\n- Improved screen-reader output in `/mcp`: a disabled server is read as \"off\" instead of \"pending\"\n- Improved the Remote Control confirmation: its options are briefly inactive again after the terminal window regains focus, so a key pressed while switching back cannot answer it\n- Changed send now (ctrl+enter or ctrl+x ctrl+s) to move running tools to the background instead of cancelling the turn\n- Changed auto mode so that, where its classifier review runs server-side, read-only and sandboxed shell commands also wait for that review and are blocked when it flags them\n- Changed `CLAUDE_CODE_AUTO_MODE_SERVER` to also apply on a direct Anthropic API connection: `0` opts out of the server-side auto mode classifier (the local classifier then counts toward usage), `1` opts in\n- Changed the dangerous `rm` prompt in `--dangerously-skip-permissions` and auto mode to wait 2 minutes for an answer, then deny the command with a rewrite hint so unattended sessions keep going (`CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT=1` turns this off)\n- Changed AGENTS.md support to also work on Amazon Bedrock, Google Vertex AI, Microsoft Foundry, LLM gateways, and sessions with telemetry disabled\n- Changed Claude apps gateway to refuse to start when a `managedMcpServers` entry's `envHelper` path starts with `\\??\\` or `/??/`, a path form current Claude Desktop refuses to run\n- Changed self-hosted runners to pass system prompts to Claude Code as private files instead of command-line text, so large prompts no longer fail the launch; a wrapper or `command` hook that appends `--system-prompt` or `--append-system-prompt` must switch to `--system-prompt-file` or `--append-system-prompt-file`\n- Changed queued messages to show in the conversation above the spinner instead of under it\n- Changed the session artifact links under the prompt into one footer pill (`⧉ name` or `⧉ N`) that opens `/artifacts`, which now lists this session's artifacts first\n- Changed the Artifact tool to let Claude load scripts from unpkg.com in artifact pages\n- Changed hovering a list row in fullscreen mode, including in `/config`, to tint the row instead of drawing a second ❯ pointer beside the focused row's\n- Changed /mcp: each server's row now starts with its status icon and name, says its state once, and in a narrow terminal drops trailing facts like \"managed\" before shortening the name\n- Changed /workflows: each run's row leads with its status icon and elapsed time, and a narrow terminal keeps the run's name and time, dropping the agent and token counts first\n- Changed Remote Control attachment downloads to reuse connections and to skip files already downloaded in the session\n- Changed MCP resource lists (the resource list tool and @-mention suggestions) to skip MCP Apps UI resources; reading one by URI still works\n- Changed `claude plugin uninstall --json` and the /plugin dialog to say a plugin's data was kept when its folder stays because another installed plugin uses it or install records cannot be read\n- Changed the background tasks list (`/tasks`): pressing `x` on a running `/ultrareview` now asks for confirmation before stopping the review\n- Removed the leftover \"(removed)\" `/agents` entry from the command menu and `/help`; typing `/agents` still explains where the wizard went\n- [VSCode] Added a Continue/Stop prompt in the VS Code and JetBrains panels when auto mode falls back to billed classifier requests, replacing the unanswerable warning line\n- [VSCode] Fixed opening a Web session with no messages saving an empty local copy that could not be resumed; an error now says where to continue it\n- [VSCode] Fixed a claude.ai/code session opening empty or with only part of its conversation, with no error, when the server failed to return its history, part of it failed to load, or a network sign-in page answered in its place; it now shows an error and can be opened again\n- [VSCode] Fixed conversations in editor tabs hanging silently after the extension host restarts; the tab now tells you to reopen it from the session list\n- [VSCode] Fixed Claude attaching option previews to multiple-choice questions in the chat panel, where the question card never shows them\n- [VSCode] Fixed the session manager's cost and usage block wrapping mid-text on a narrow side bar, and showing totals from a previous login after an account switch\n- [Claude Code on the web] Added a Fast mode switch to the composer's model menu in cloud sessions, shown when your plan includes fast mode and the selected model supports it\n- [Claude Code on the web] Added a settings shortcut on the GitHub setup tip and a \"Troubleshoot GitHub connection\" link in the repository pickers, both opening your GitHub connection page\n- [Claude Code on the web] Fixed routines with a GitHub trigger for a pull request being converted to draft never firing; they now start a run when the pull request is converted\n- [Claude Code on the web] Fixed cloud sessions on a repository that isn't hosted on GitHub showing a Create PR button that could never work; the button is now hidden there\n- [Claude Code on the web] Fixed the GitHub setup tip on claude.ai/code covering the repository picker's search box and rows while the picker is open; it now steps aside until the picker closes\n- [Claude Code on the web] Improved the file card shown when a cloud session can't open a file: it now says whether the file no longer exists or the session's permission settings block reading it\n- [Claude Tag] Added a short line in the Slack thread after someone presses Stop, naming who stopped Claude's response and saying to mention @Claude to continue\n- [Claude Tag] Fixed Slack channels where Claude could permanently stop responding to replies inside threads; affected channels now recover on their own with the next new message to Claude\n- [Claude Tag] Fixed Claude resuming a stopped request after you press Stop in Slack, for example when a check-in fired or a background task ended; messages sent mid-response are now read\n- [Claude Tag] Fixed Slack replies arriving many minutes late, or never, after Claude's session crashed mid-task, such as on a failed setup script; it now restarts on its own within minutes\n- [Claude Tag] Fixed Claude in Slack promising an automatic restart, then failing generically, when a session's configuration is too large to start; the thread now says why and how to retry\n- [Claude Tag] Fixed very long Slack threads: Claude could silently withhold a reply after judging it against weeks-old messages, and a restart deep into the thread could lose recent context\n- [Claude Tag] Fixed Claude answering every mention with \"Couldn't check this channel just now\" in a Slack channel moved from Enterprise Grid org-wide sharing into a single workspace\n- [Claude Tag] Fixed very large Enterprise Grid workspaces reached mostly through channels shared across workspaces getting \"Couldn't check this channel\" again after a quiet hour\n- [Claude Tag] Fixed a Slack request blocked by your organization's inference hook showing a generic retry notice; the thread now shows the hook's deny message and Claude doesn't retry\n- [Claude Tag] Fixed Claude in Slack offering to switch to models your organization can't use; it now lists and offers only models the switch will actually accept\n- [Claude Tag] Fixed requests to DynamoDB and Kinesis account-based endpoints failing to authenticate when sent through an AWS connection in Claude Tag\n- [Claude Tag] Fixed the Plugins sections in Claude Tag admin settings failing to load for organization admins and listing attached plugins as raw IDs; they now load and show each plugin's name\n- [Claude Tag] Changed the routine list Claude gives when asked in a Slack thread to show that thread's own scheduled tasks by default instead of every routine in the channel\n- [Code Review] Fixed a pull request getting no review when its reviewed commit was force-pushed away while a failed review was being retried in a repository not set to review every push","body_html":null,"content_hash":"697efce8a08a1db9d04b572e6a79e7df114e7c50757507c00963cf1d9ad9623e","updated_at":"2026-10-05T19:07:41.407Z"},{"id":"f629eb1d-ee67-47ce-8925-32e403a7fc77","source_id":"codex","dedupe_key":"codex:rust-v0.156.1","version":"0.156.1","title":"0.156.1","url":"https://github.com/openai/codex/releases/tag/rust-v0.156.1","published_at":"2026-09-23T02:41:36Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:38:02.977Z","body_md":"## New Features\n\n- Choose GPT-6 Sol or GPT-6 Luna from the model picker. The rate-limit switch prompt now recommends GPT-6 Luna. (#47405)\n\n## Changelog\n\nFull Changelog: https://github.com/openai/codex/compare/rust-v0.156.0...rust-v0.156.1\n\n- #47405 [hotfix 0.156.0] Add GPT-6 Sol and Luna to the model catalog (#47332) @imac-oai\n\n\n","body_html":null,"content_hash":"c1a7e758d6c8cc688b6446aab693b8abb188d9e0adbcdc7888459bcf46f0fa0f","updated_at":"2026-10-05T08:38:02.977Z"},{"id":"1db77838-d2df-4fda-baba-5595d424064d","source_id":"cursor","dedupe_key":"cursor:https://cursor.com/changelog/rollouts-and-security-reviewer","version":"Rollouts and Security Review","title":"Rollouts and Security Review","url":"https://cursor.com/changelog/rollouts-and-security-reviewer","published_at":"2026-09-23T00:00:00.000Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.651Z","body_md":null,"body_html":"<p><a href=\"/changelog/rollouts-and-security-reviewer\">Sep 23, 2026</a> · <a href=\"/changelog\">Changelog</a></p><h1><a href=\"/changelog/rollouts-and-security-reviewer\">Rollouts and Security Review</a></h1><p>Today we&#x27;re launching two Cursor bots for the last mile of shipping code. Rollouts watches every change as it deploys and reports its health per environment. Security Review reports exploitable bugs on every pull request.</p>\n<p>Both are available today on Teams and Enterprise plans.</p>\n<h2><a href=\"#rollouts\">#</a>Rollouts</h2>\n<p>Rollouts attaches a monitor to every pull request and watches the change as it deploys, reporting change health per environment: verified healthy, regression detected, or inconclusive. It&#x27;s the Cursor version of <a href=\"https://cursor.com/blog/firetiger\">Firetiger</a> Change Monitors, rebuilt with the Bot Development Kit.</p>\n\n<p>Enable it from the dashboard and connect source control, your deploy system, and your telemetry provider. Rollouts starts watching on the next pull request.</p>\n<h4><a href=\"#monitoring-plans\">#</a>Monitoring plans</h4>\n<p>When a pull request opens, Rollouts reads the diff and the systems it touches, then writes a monitoring plan as a PR comment. The plan lists the risks it identified, the effect the change is meant to have, the signals it will check, and any gaps in instrumentation that would make the change hard to verify. Edit the plan in the PR and Rollouts uses your version.</p>\n<h4><a href=\"#deploy-tracking\">#</a>Deploy tracking</h4>\n<p>Rollouts wakes on deploy events for the change&#x27;s commit and runs the plan against your logs, metrics, and traces. It tracks each environment separately, so a change can be verified in staging and still flagged in production. Rollouts checks the change&#x27;s intended effect alongside error and latency signals, and reports back on the PR when it reaches a verdict.</p>\n<h4><a href=\"#regressions\">#</a>Regressions</h4>\n<p>When Rollouts detects a regression, it names the change it suspects and notifies the author. Depending on configuration, it can also open a revert PR for review or hand the finding to a cloud agent for a fix. Rollouts does not merge or roll back on its own today.</p>\n<h4><a href=\"#integrations\">#</a>Integrations</h4>\n<p>Rollouts connects to Origin or GitHub for source control, to your continuous delivery system for deploy events, and to Datadog and other telemetry providers for signals. Feature flag integration is coming soon.</p>\n<h2><a href=\"#security-review\">#</a>Security Review</h2>\n<p>Security Review is available today. It reads every pull request in the context of the codebase and posts one review comment reporting exploitable bugs. Style and quality stay with Bugbot.</p>\n<img alt=\"Security Review comment on a pull request reporting an exploitable bug with a severity and proposed fix\" src=\"/marketing-static/_next/image?url=https%3A%2F%2Fptht05hbb1ssoooe.public.blob.vercel-storage.com%2Fassets%2Fchangelog%2Fsecurity-review-N8azgyLevr8FvNIRqJN6hk71os2Oxu.png&amp;w=1920&amp;q=70\">\n<p>Enable it from the dashboard for the repositories you want reviewed. Draft PRs are skipped.</p>\n<h4><a href=\"#what-it-reports\">#</a>What it reports</h4>\n<p>Security Review looks for injection across SQL, command, and template surfaces, along with authentication and authorization bypasses, including checks that a refactor stopped running. It also flags secrets and credentials committed to source, SSRF and unvalidated redirects, unsafe deserialization, and dependency changes that introduce known vulnerabilities. It traces where user input enters and what it passes through.</p>\n<h4><a href=\"#findings\">#</a>Findings</h4>\n<p>Each finding carries a severity, the attack path, and a proposed fix. Dismiss one with a reason and Security Review won&#x27;t raise it again on that PR.</p>\n<h4><a href=\"#team-rules\">#</a>Team rules</h4>\n<p>Add rules for your codebase, such as which client external calls must go through or which tables are never queried from a request handler, and Security Review enforces them on every PR.</p>\n<h2><a href=\"#get-started\">#</a>Get started</h2>\n<p>Rollouts and Security Reviewer are available today on Teams and Enterprise plans. Enable either bot from the <a href=\"https://cursor.com/automations\">automations</a> tab.</p>\n<p>For the next 10 days, we&#x27;re including usage credits so teams can try Rollouts on real changes. Teams and Enterprise customers receive credits for roughly 50 and 500 changes, respectively.</p>","content_hash":"23a86d2ea1f05817b52672361cfac6d319a3f8fcf30f15baa739b8a86caed443","updated_at":"2026-10-05T18:59:33.143Z"},{"id":"7e449298-ba50-42ac-bd49-dc84ee40b580","source_id":"codex","dedupe_key":"codex:rust-v0.156.0","version":"0.156.0","title":"0.156.0","url":"https://github.com/openai/codex/releases/tag/rust-v0.156.0","published_at":"2026-09-22T19:51:01Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:38:02.977Z","body_md":"## New Features\n\n- Choose an optional fullscreen UI with `/tui` for your next launch, including transcript search, mouse selection, and right-click copying. (#46732, #46734, #46883, #46895)\n- Voice conversations are enabled by default, with an F8 toggle, a `/voice settings` picker, and bundled audio runtimes for Linux and Windows. (#44921, #46071, #44622, #44714, #44922)\n- Explore account usage, token totals, and plugin and skill activity through the `/usage` analytics dashboard. (#45764, #45769)\n- Filter tasks by status and create worktree sessions from the agent command center; worktree support is now enabled by default. (#46839, #45276, #44870)\n- Customize the terminal with six new themes and view supported Mermaid diagrams and display equations directly in responses. (#46504, #46054, #45612)\n- Update the local background server through `/daemon`, or bypass it with `--no-daemon`. (#45854, #46088)\n\n## Bug Fixes\n\n- Preserve streamed answers and plans when turns fail, are interrupted, or receive subagent completion events. (#45549, #46867)\n- Fix clipboard forwarding in tmux and SSH sessions and preserve tab indentation when terminals send pasted text as individual keystrokes. (#45457, #45454)\n- Restore Plan mode when resuming sessions and preserve thread identity and settings when editing earlier prompts. (#45519, #45845)\n- Recover login through system proxies and refresh MCP credentials when OAuth discovery returns a 503 error. (#46562, #44636)\n- Prevent speech from being dropped during playback pauses or bursts of incoming audio. (#46880)\n- Close sandbox isolation gaps involving inbound Windows connections, privileged Linux/macOS sockets, and writes through read-only macOS file handles. (#44639, #45984, #46500)\n\n## Documentation\n\n- Clarify that deprecated `friendly` and `pragmatic` personality settings no longer select response styles. (#45809)\n- Explain how `?` matches a single character in network proxy allow and deny patterns. (#46027)\n\n## Chores\n\n- Update bundled TLS dependencies, including OpenSSL 3.6.4 for Linux musl builds. (#45149, #45489)\n\n## Changelog\n\nFull Changelog: https://github.com/openai/codex/compare/rust-v0.155.0...rust-v0.156.0\n\n- #44606 Preserve whole diagnostic attachments and report incomplete uploads @chess-oai\n- #44611 Preserve root turn attribution in turn-start events @owenlin0\n- #44613 Enable user verification for local Codex Desktop sessions @riley-oai\n- #44615 Treat non-interactive dumb terminals as warnings in `codex doctor` @etraut-openai\n- #44616 Simplify enterprise OAuth login helpers and expand callback tests @nicksteele-oai\n- #44617 Invalidate cached Guardian approvals for unscored permission widening @jif-oai\n- #44619 Allow discarded code mode tool responses to be garbage collected @jif-oai\n- #44620 Support temporary and minimal filesystem grants in MXC @iceweasel-oai\n- #44622 Add `/voice settings` to choose a voice for future conversations @bc-openai\n- #44626 Add bounded environment transport for MXC launch requests @iceweasel-oai\n- #44628 Expose session analytics state in Responses turn metadata @marksteinbrick-oai\n- #44629 Add manual callback input to MCP OAuth login @willwang-openai\n- #44631 Focus the task list when reopening the agent command center @etraut-openai\n- #44636 Recover OAuth metadata discovery from 503 responses via OIDC @malsamiri-oai\n- #44639 Block non-loopback inbound traffic for the Windows offline sandbox @viyatb-oai\n- #44646 Honor thread analytics opt-outs when using shared clients @priyanshusingh-de\n- #44650 Enforce managed model provider selection and definitions @alexsong-oai\n- #44651 Keep command center errors visible and preserve drafts @etraut-openai\n- #44654 Preserve missing environment variable diagnostics in Codex Doctor @etraut-openai\n- #44655 Honor thread-level plugin exclusions across runtime capabilities @mzeng-openai\n- #44656 Attribute turn metrics to the models used during the turn @eternal-openai\n- #44658 Keep Windows sandbox private desktops alive across helper exits @chess-oai\n- #44659 Preserve turn triggers across delegated agent work @joeytrasatti-openai\n- #44661 Trace tool call receipt, result readiness, and code-mode dispatch @anp-oai\n- #44666 Honor system reduced-motion preferences in the TUI @imac-oai\n- #44669 Resolve filesystem denials with explicit path context @seanh-oai\n- #44670 Restrict login setup redirects to known platform origins @hintz-openai\n- #44671 Keep voice sessions alive through mute and audio backlog @bc-openai\n- #44675 Refresh global instructions at model-request boundaries @vkg-oai\n- #44676 Resolve permission profiles with explicit execution-host path context @seanh-oai\n- #44691 Warn about ignored configuration settings @andrewgu-oai\n- #44693 Preserve selected profile settings over managed new-thread defaults @alexr-oai\n- #44694 Include the Windows sandbox service in release artifacts @johnl-oai\n- #44701 Add a provider for thread-scoped instructions @vkg-oai\n- #44711 Return to the command center after session cancellation or deletion @etraut-openai\n- #44714 Bundle Linux voice runtimes and improve audio reliability @bc-openai\n- #44732 Clarify folder trust prompts and add restricted widget support @etraut-openai\n- #44742 Preserve editor yanks across new sessions and thread switches @bc-openai\n- #44744 Make archive confirmation number shortcuts act immediately @etraut-openai\n- #44746 Check folder trust after resolving the startup destination @etraut-openai\n- #44747 Update `quinn-proto` and allow the pinned H3 Git source @richardopenai\n- #44749 Preserve voice caption order when replaying TUI history @bc-openai\n- #44752 Render Markdown in agent overview task details @etraut-openai\n- #44755 Check folder consent before creating or resuming TUI tasks @etraut-openai\n- #44814 Test approved command execution with managed unified exec disabled @jif-oai\n- #44826 Expose advertised MCP server capabilities in status responses @gpeal\n- #44832 Add trusted enterprise MCP auth configuration @nicksteele-oai\n- #44857 Add consistent theme-based thread colors across the TUI @etraut-openai\n- #44862 Preserve parent cache affinity for ephemeral forks @jif-oai\n- #44865 Scope code mode callback delegates to individual executions @abhinav-oai\n- #44866 Preserve originating context for yielded code-mode tool calls @abhinav-oai\n- #44867 Preserve originating budgets for code mode notifications @abhinav-oai\n- #44870 Enable worktrees by default and clarify local daemon errors @bc-openai\n- #44872 Add managed network policy support to the Windows MXC sandbox @iceweasel-oai\n- #44877 Return public key metadata from user verification enrollment @riley-oai\n- #44879 Fade Astra composer stars and stabilize cursor redraws @imac-oai\n- #44883 Reject token-budget history notes for unsupported starting models @jif-oai\n- #44893 Expose available access programs in model discovery @faizan-oai\n- #44903 Wire up the native Windows MXC helper entry point @iceweasel-oai\n- #44905 Expose disabled plugin settings in the app-server API @mzeng-openai\n- #44915 Remove the deprecated `thread/rollback` API @owenlin0\n- #44921 Enable TUI voice conversations by default @bc-openai\n- #44922 Bundle native voice runtimes in Windows releases @bc-openai\n- #44924 Refresh the speaker format when restarting voice output @bc-openai\n- #44925 Accept voice response audio before captions on quiet turns @bc-openai\n- #44928 Preserve voice meter history through quiet samples @bc-openai\n- #44930 Embed friendly instructions in bundled GPT-5.4 and GPT-5.5 @rhan-oai\n- #44931 Stop setting `YARN_NO_PROXY` in the managed proxy environment @viyatb-oai\n- #44932 Unify context snapshots and group requests into windows @pakrym-oai\n- #44933 Remove Windows world-writable scans and warnings from the TUI @etraut-openai\n- #44934 Add scenario snapshots for remote compaction and Code Mode tools @pakrym-oai\n- #44935 Remove personality selection from the TUI @rhan-oai\n- #44938 Add connector auth failure detection without an install URL @priyanshusingh-de\n- #44939 Respect execution hosts in Windows sandbox setup @etraut-openai\n- #44942 Clarify the Windows Visual C++ runtime notice for voice packages @bc-openai\n- #44944 Enforce managed provider requirements on existing app-server threads @alexsong-oai\n- #44945 Route TUI Windows sandbox setup through the app server @etraut-openai\n- #44946 Retire Friendly and Pragmatic personality selection @rhan-oai\n- #44948 Add context snapshots for async questions and plugin refresh @pakrym-oai\n- #44952 Keep voice captions visible across speaker updates and history handoff @bc-openai\n- #44957 Add model grouping to the agent command center @etraut-openai\n- #44969 Open tasks managed elsewhere as read-only history in the command center @etraut-openai\n- #44970 Show task tokens and usage estimates in the agent command center @etraut-openai\n- #44976 Make context snapshot text rendering consistent @pakrym-oai\n- #45035 Run DotSlash publishing directly on Ubuntu runners @charliemarsh-oai\n- #45039 Use gzip compression level 6 for Codex package archives @charliemarsh-oai\n- #45051 Consolidate Rust release artifact downloads @charliemarsh-oai\n- #45089 Delay automatic recaps and compact their TUI layout @fcoury-oai\n- #45090 Preserve conversation context and separate next actions in recaps @fcoury-oai\n- #45094 Estimate history tokens from content instead of serialized envelopes @won-openai\n- #45108 Cancel pending thread title generation after manual renames @fcoury-oai\n- #45112 Use blueberry in the realtime background-agent test fixture @anp-oai\n- #45116 Prevent multiline report notes from submitting early @etraut-openai\n- #45124 Add a feature flag for asynchronous user messages @alishobeiri-oai\n- #45135 Preview streaming prose before a newline arrives in the TUI @etraut-openai\n- #45137 Remove Astra sparkle animation from the TUI composer @fcoury-oai\n- #45149 Use OpenSSL 3.6.4 for musl builds @zm-oai\n- #45169 Extract Windows sandbox setup and installation storage into the library @zm-oai\n- #45176 Wire the Windows MXC sandbox into command execution @iceweasel-oai\n- #45178 Split Windows sandbox cleanup into preparation and completion phases @zm-oai\n- #45180 Extract shared network configuration and environment policy helpers @seanh-oai\n- #45182 Validate Windows sandbox token groups before copying SIDs @zm-oai\n- #45185 Bind direct tool-call metadata to invocation outputs @ningyi-oai\n- #45224 Register Windows desktop uninstall ownership before sandbox setup @chess-oai\n- #45248 Use captured step settings for request metadata and tool hooks @abhinav-oai\n- #45255 Open new sessions directly from the command center @etraut-openai\n- #45262 Route pastes into the active history search query @charliemarsh-oai\n- #45271 Preserve terminal scrollback when growing the TUI viewport @fcoury-oai\n- #45276 Add worktree session creation to the agents overview @etraut-openai\n- #45312 Extract Windows sandbox configuration preparation into a helper @seanh-oai\n- #45345 Publish opt-in provisioned macOS packages with Rust releases @riley-oai\n- #45399 Cancel code mode timer tasks when cleared or the cell finishes @jif-oai\n- #45409 Add session and originating window IDs to MCP request metadata @jif-oai\n- #45413 Invalidate Guardian review sessions after parent history resets @jif-oai\n- #45417 Extract guardian transcript selection into `guardian-context` @felixxia-oai\n- #45418 Extract Guardian conversation bookkeeping into the reviewer crate @felixxia-oai\n- #45420 Extract Guardian sampler execution into a dedicated module @felixxia-oai\n- #45428 Avoid cloning MCP server status snapshot data @charliemarsh-oai\n- #45439 Share tool output schemas and defer MCP envelope construction @charliemarsh-oai\n- #45440 Share Apps tool catalogs without retaining unused snapshots @charliemarsh-oai\n- #45441 Preserve Guardian parent response IDs across sampling requests @jif-oai\n- #45445 Attribute command and plugin analytics to the invoking model @jwang-openai\n- #45454 Preserve tabs in non-bracketed paste bursts @etraut-openai\n- #45455 Refactor Windows sandbox setup and service helpers @zm-oai\n- #45457 Fix clipboard routing for tmux and SSH sessions @fcoury-oai\n- #45459 Resolve enterprise-managed MCP registrations in the catalog @nicksteele-oai\n- #45461 Label rollout compression failures by stage and I/O error kind @jif-oai\n- #45463 Allow dedicated listeners for managed network proxies @iceweasel-oai\n- #45475 Fix fuzzy match scoring within Unicode lowercase expansions @etraut-openai\n- #45487 Retain thread persistence acquisition through session cancellation @jif-oai\n- #45489 Update `rustls` and AWS-LC dependencies in Cargo and Bazel lockfiles @zm-oai\n- #45491 Remove Guardian subagent-spawner plumbing @felixxia-oai\n- #45492 Split Guardian V2 async scoring into focused modules @felixxia-oai\n- #45493 Make the Guardian deadline cancellation helper crate-private @felixxia-oai\n- #45495 Expose effective login methods in config requirements @acrognale-oai\n- #45496 Trace global user instruction loading @vkg-oai\n- #45499 Send local TUI images as portable attachments to remote app servers @etraut-openai\n- #45501 Render inline TeX math as Unicode in the TUI @etraut-openai\n- #45502 Add managed thread lifetimes with cancellation-safe startup @jif-oai\n- #45503 Add revocable network policy primitives to the HTTP client @acrognale-oai\n- #45504 Allow ConPTY output to close after the last console client exits @iceweasel-oai\n- #45505 Add lifecycle tracing for unified exec @anp-oai\n- #45506 Allow background persistence for steered user input @bryanashley\n- #45509 Share MCP tool specs until search results are selected @owenlin0\n- #45513 Allow setting `daybreakEnabled` when starting a thread @faizan-oai\n- #45515 Filter plugin-install test analytics by event type @zm-oai\n- #45516 Allow configuring the Guardian prompt template @won-openai\n- #45517 Use a dedicated mock server in the provider enforcement test @zm-oai\n- #45518 Route Guardian reviewers through ThreadManager for inline parents @jif-oai\n- #45519 Restore collaboration mode when resuming threads @etraut-openai\n- #45520 Add dependencies to the Windows sandbox service @zm-oai\n- #45521 Move Guardian reviewer startup into the pool @jif-oai\n- #45524 Enable MXC TTY launches and managed networking in the exec server @iceweasel-oai\n- #45526 Stage Python runtime wheels directly from package directories @charliemarsh-oai\n- #45528 Compress larger Windows release artifacts first @charliemarsh-oai\n- #45529 Expose selected workspace routing in app-server account reads @acrognale-oai\n- #45533 Harden and share Windows sandbox identity helpers @zm-oai\n- #45534 Honor explicit Unix socket grants in the Linux managed sandbox @viyatb-oai\n- #45535 Classify tool analytics events by call origin @eddie-openai\n- #45537 Move Guardian reviewer lifecycle into the extension @jif-oai\n- #45542 Add service-managed package registration for Windows sandbox accounts @zm-oai\n- #45543 Refactor image content to use a shared `ImageReference` type @kchainani-oai\n- #45544 Discourage logging full image generation results @Gan-Tu\n- #45546 Move daemon packages out of the standalone CLI installation @etraut-openai\n- #45548 Honor prepared Unix socket permissions in Seatbelt @viyatb-oai\n- #45549 Preserve streamed answers and plans when turns terminate @etraut-openai\n- #45550 Add opt-in registered package execution to the Windows sandbox @zm-oai\n- #45554 Use shared Bazel cache preparation in SDK CI @charliemarsh-oai\n- #45556 Add attachment upload and resolution APIs and pass stores into sessions @kchainani-oai\n- #45558 Seed missing daemon installs from complete local CLI packages @etraut-openai\n- #45559 Resume Windows sandbox registration refresh after service restarts @zm-oai\n- #45579 Copy current thread attachments into non-ephemeral forks @joeytrasatti-openai\n- #45580 Add explicit daemon package replacement from the CLI @etraut-openai\n- #45602 Fix retry classification for throttling and quota errors @sdcoffey\n- #45612 Render standalone display math in the TUI @etraut-openai\n- #45649 Add elicitation classification support to app and MCP analytics @priyanshusingh-de\n- #45669 Centralize child agent configuration in the agent module @jif-oai\n- #45670 Move V2 agent message delivery into `AgentControl` @jif-oai\n- #45672 Consolidate Guardian reviewer lifecycle ownership @jif-oai\n- #45676 Move spawned-agent interruption rules into `AgentControl` @jif-oai\n- #45677 Move Guardian review reporting and denial accounting into the extension @jif-oai\n- #45679 Retire the unused Guardian extension prototype API @felixxia-oai\n- #45680 Restrict guardian assessment parsing and circuit breaker visibility @felixxia-oai\n- #45683 Consolidate guardian transcript tests in `guardian-context` @felixxia-oai\n- #45684 Pass `ReviewModel` through guardian review sessions @felixxia-oai\n- #45693 Move Guardian approval routing into the reviewer extension @jif-oai\n- #45711 Add startup tool allowlists for threads @jif-oai\n- #45716 Classify MCP auth and approval outcomes in analytics @priyanshusingh-de\n- #45729 Move Guardian reviewer configuration into the extension @jif-oai\n- #45730 Separate executor sandbox selection from Windows sandbox levels @iceweasel-oai\n- #45736 Route Guardian requests through `/responses` with identifying headers @jif-oai\n- #45737 Separate Windows sandbox implementations from legacy setup modes @iceweasel-oai\n- #45739 Add typed account analytics reports to the backend client @fcoury-oai\n- #45740 Add account analytics data normalization to the TUI @fcoury-oai\n- #45741 Add token history and credit formatting helpers for analytics @fcoury-oai\n- #45742 Add account-bound authentication for analytics requests @fcoury-oai\n- #45746 Explicitly gate DotSlash publishing on release success @chess-oai\n- #45749 Extract reusable Bash and Zsh startup scripts @jif-oai\n- #45755 Honor canonical plugin disables for shared connectors @mzeng-openai\n- #45757 Wire Windows sandbox selection into managed proxy routing @iceweasel-oai\n- #45760 Disable V8 optimization paths affected by array sort bugs @kliu128\n- #45762 Load analytics reports with server plans and account identity checks @fcoury-oai\n- #45763 Add stacked chart primitives for account analytics @fcoury-oai\n- #45764 Add an account analytics dashboard to `/usage` @fcoury-oai\n- #45765 Add Top chats to usage analytics @fcoury-oai\n- #45766 Add gated plan usage history to TUI analytics @fcoury-oai\n- #45768 Add consumer Top chats usage analytics @fcoury-oai\n- #45769 Add an account Summary tab to Analytics @fcoury-oai\n- #45770 Improve analytics chart readability and navigation @fcoury-oai\n- #45772 Expose experimental analytics plan history and improve navigation @fcoury-oai\n- #45779 Use native process identities for PID-managed daemons @etraut-openai\n- #45780 Allow daemon updates to restore pinned packages to latest stable @etraut-openai\n- #45781 Normalize bullet glyphs in the image preparation disconnect snapshot @jgershen-oai\n- #45782 Preserve Guardian authorization evidence across checkpoint migration @felixxia-oai\n- #45789 Preserve Guardian evidence during checkpoint migration @felixxia-oai\n- #45794 Support image references by file ID in inputs and tool outputs @kchainani-oai\n- #45796 Preserve `ImageUserInput` in the Python SDK @kchainani-oai\n- #45799 Complete Windows sandbox uninstall cleanup @chess-oai\n- #45805 Preserve MCP App UI metadata in tool-call events and history @victor-openai\n- #45806 Restrict plugin install requests to the root thread @rennie-openai\n- #45807 Record interrupted turns in managed daemon recovery snapshots @etraut-openai\n- #45809 Retire the personality feature flag and document deprecated settings @rhan-oai\n- #45811 Bound WSL terminal detection and handle inconclusive probes safely @etraut-openai\n- #45812 Add workspace routing support for Responses requests @acrognale-oai\n- #45813 Track Windows sandbox policy and per-thread executor hosts in the TUI @etraut-openai\n- #45817 Add a bounded Mermaid text renderer @etraut-openai\n- #45820 Continue interrupted work after managed daemon restarts @etraut-openai\n- #45821 Use app-server state for TUI Windows sandbox decisions @etraut-openai\n- #45822 Add opt-in response body limits to the HTTP transport @sergio-oai\n- #45823 Run R2 publishing when release dependencies succeed @dkumar-oai\n- #45825 Add opt-in nonfatal handling for clock read failures @vivi\n- #45830 Use app-server configuration for Windows sandbox state in the TUI @etraut-openai\n- #45831 Allow session-only model and reasoning selection in the TUI @etraut-openai\n- #45837 Hide WSLg's duplicate root in restricted Linux sandboxes @etraut-openai\n- #45845 Revert the current thread when editing an earlier TUI prompt @etraut-openai\n- #45849 Preserve the app-server shutdown signal future across loop iterations @jgershen-oai\n- #45852 Preserve executor path conventions in permission summaries @seanh-oai\n- #45854 Add `/daemon` menu for local background server updates @etraut-openai\n- #45863 Preserve executor path URIs in permission profile workspace roots @seanh-oai\n- #45865 Reject paths in project documentation fallback filenames @etraut-openai\n- #45900 Add a hidden HTTP/3 TCP tunnel command @richardopenai\n- #45915 Make Code Mode wrappers transparent to Guardian model policies @jif-oai\n- #45928 Bound model catalog decode errors and classify request timeouts @jif-oai\n- #45933 Avoid redundant model catalog lookups in reused Guardian reviewers @jif-oai\n- #45956 Record memory storage size after successful consolidation @jif-oai\n- #45957 Centralize Guardian policy resolution in config and protocol @jif-oai\n- #45960 Tag memory usage telemetry with the memory version @jif-oai\n- #45964 Expose partial completion in rollout compression metrics @jif-oai\n- #45966 Measure rollout read and materialization durations @jif-oai\n- #45978 Keep selection adjacent when hiding tasks in the agents overview @etraut-openai\n- #45980 Fall back to summary history for read-only conversations @etraut-openai\n- #45981 Preserve session config when switching thread permission profiles @etraut-openai\n- #45982 Use native DNS resolution for the network proxy on macOS @jdkula-openai\n- #45983 Show a loading message when opening tasks from the agents overview @etraut-openai\n- #45984 Isolate app-server Unix sockets from filesystem-restricted commands @etraut-openai\n- #45985 Replace guardian review result tuples with named structs @felixxia-oai\n- #45987 Centralize Guardian action preparation for review @felixxia-oai\n- #46002 Extract route-aware HTTP request execution into a separate module @acrognale-oai\n- #46004 Preserve attachment Unix socket grants when controller policy is omitted @open-matt\n- #46006 Report clock failures again after recovery @anp-oai\n- #46008 Route built-in permission selections through the app server @etraut-openai\n- #46009 Centralize compaction checkpoint selection and validation @felixxia-oai\n- #46010 Enable app tool result metadata with analytics controls @ningyi-oai\n- #46011 Enforce managed residency when constructing API providers @andrewgu-oai\n- #46013 Route permission shortcuts through the shared selection flow @etraut-openai\n- #46015 Allow callers to disable executor skills per environment @vkg-oai\n- #46019 Allow hosted Apps MCP contributions to override the protocol mode @teddywyly-oai\n- #46020 Add an experimental rollout compression endpoint @jif-oai\n- #46026 Centralize model-message resolution and rendering in `codex-prompts` @rhan-oai\n- #46027 Document and test `?` wildcards in network proxy domain patterns @viyatb-oai\n- #46029 Allow browser app cleanup hooks on interrupt @syuan-oai\n- #46031 Keep Noise relay streams alive after repeated handshake failures @viyatb-oai\n- #46032 Require forced macOS preferences for managed configuration @joeflorencio-openai\n- #46033 Preserve orchestrator skill caches across MCP runtime updates @hlevy-openai\n- #46035 Add per-app tool exposure configuration @ptiet-oai\n- #46036 Preserve config error causes when saving the approvals reviewer @darius-oai\n- #46038 Test Windows sandbox bin DACL modification permissions @zm-oai\n- #46040 Default TUI animations off when a screen reader is detected @etraut-openai\n- #46041 Tighten request handling in Guardian approval tests @jgershen-oai\n- #46042 Add read-only policy support to MCP tool requests @rennie-openai\n- #46043 Repair expired Windows sandbox account passwords during setup @zm-oai\n- #46044 Include Code Mode tool metadata in compaction prompts @ningyi-oai\n- #46047 Tag rollout compression metrics by trigger @jif-oai\n- #46051 Track WebSocket continuation modes and full-input send reasons @vkg-oai\n- #46054 Render Mermaid code blocks as diagrams in the TUI @etraut-openai\n- #46058 Attribute analytics events to realtime voice sessions @chrisdong-oai\n- #46063 Trim Guardian tests and tighten request layout assertions @felixxia-oai\n- #46064 Consolidate Guardian tests at shared policy and context boundaries @felixxia-oai\n- #46065 Route prepared images through the attachment store @kchainani-oai\n- #46066 Keep MCP user interaction on the root thread @rennie-openai\n- #46067 Remove the `done` prefix from TUI completion timestamps @etraut-openai\n- #46069 Use syntax theme colors for inline code and file paths @etraut-openai\n- #46070 Suppress warnings when skill descriptions are shortened @etraut-openai\n- #46071 Add a configurable F8 shortcut for voice conversations @etraut-openai\n- #46072 Account for file images in context budgets and Guardian reviews @kchainani-oai\n- #46073 Bound code-mode output previews across result blocks @etraut-openai\n- #46075 Use captured step settings when spawning subagents @rhan-oai\n- #46077 Keep the composer responsive during Command Center session creation @etraut-openai\n- #46081 Mark finished empty Code Mode tool inventories as complete @nf-openai\n- #46088 Add `--no-daemon` to bypass the shared background server @etraut-openai\n- #46096 Add a one-time composer starfield for new Astra tasks @imac-oai\n- #46104 Pause TUI events in the agents overview regression test @etraut-openai\n- #46107 Box app-server request handler futures to reduce stack usage @etraut-openai\n- #46108 Replace Sites migration state with a runtime compatibility guard @jiwon-oai\n- #46112 Preserve filesystem sandbox policy context when the cwd disappears @anp-oai\n- #46116 Make TUI web and image activity summaries compact and descriptive @etraut-openai\n- #46117 Add opt-in automatic background server startup @etraut-openai\n- #46122 Route filesystem reads and writes by their own sandbox permissions @anp-oai\n- #46123 Allow model catalogs to override the V2 `spawn_agent` description @rhan-oai\n- #46125 Fix daemon socket isolation checks for private tmp mounts @open-matt\n- #46126 Record daemon startup and update telemetry with consent handling @etraut-openai\n- #46179 Include sender user messages in Guardian delegation reviews @jif-oai\n- #46230 Preserve configured Flex tiers without catalog or fast-mode support @sdcoffey\n- #46237 Improve Windows sandbox error details and registry cleanup @chess-oai\n- #46239 Prefer the provisioning service for automatic Windows sandbox setup @zm-oai\n- #46241 Repair Windows sandbox access to existing runtime children @chess-oai\n- #46245 Publish Guardian cached scores and coverage atomically @felixxia-oai\n- #46258 Preserve uploaded image file IDs in user message display history @kchainani-oai\n- #46264 Relax delegation guidance in the v2 `spawn_agent` description @surajs-oai\n- #46266 Expand Unicode math rendering with accents, symbols, and delimiters @etraut-openai\n- #46268 Add filesystem accessors bound to environment permissions @anp-oai\n- #46271 Enable MXC selection through Windows sandbox configuration @iceweasel-oai\n- #46278 Reduce R2 release upload concurrency and enable standard retries @anp-oai\n- #46279 Preserve Guardian's reusable history prefix across approval requests @jif-oai\n- #46281 Connect app-server workspace discovery to model request routing @acrognale-oai\n- #46288 Add opt-in overhead timing to code-mode responses @cassirer-openai\n- #46291 Filter saved reasoning overrides from requests when disabled @felixxia-oai\n- #46292 Preserve selected reasoning effort for synchronous Guardian reviews @felixxia-oai\n- #46293 Route skill discovery and loading through `EnvironmentAccess` @anp-oai\n- #46294 Separate thread startup metadata from replay history @charliemarsh-oai\n- #46297 Support catalog descriptions for all multi-agent V2 tools @rhan-oai\n- #46300 Centralize OAuth login and refresh handling with safer diagnostics @alexsong-oai\n- #46302 Validate network socket policies using the executor OS @seanh-oai\n- #46303 Serialize release asset uploads to avoid secondary rate limits @imac-oai\n- #46305 Avoid cloning turn items for app-server active turn lookups @charliemarsh-oai\n- #46306 Preserve bio policy errors as a distinct non-retryable error @rennie-openai\n- #46309 Preserve plugin caches across display metadata refreshes @vkg-oai\n- #46310 Defer environment selection changes until the next turn @sayan-oai\n- #46318 Add OAuth credential management for model provider gateways @alexsong-oai\n- #46319 Preserve web search actions and results in exec JSON output @etraut-openai\n- #46322 Set the Windows sandbox type in the pending environment test @sayan-oai\n- #46323 Record active plugin inventory in turn analytics @marksteinbrick-oai\n- #46324 Broaden compaction fallback to the current model @aibrahim-oai\n- #46328 Avoid persisting project trust for projectless directories @viyatb-oai\n- #46330 Move retry backoff into `codex-async-utils` @bolinfest\n- #46331 Defer environment network policy validation until after composition @seanh-oai\n- #46332 Dim conversation recaps in the TUI @etraut-openai\n- #46333 Handle disabled Windows sandbox accounts during cleanup @chess-oai\n- #46334 Share platform identity across path, network, and sandbox configuration @seanh-oai\n- #46335 Keep MCP policy evaluation consistent with turn environments @sayan-oai\n- #46482 Handle unknown error classifications and configure gateway OAuth @etraut-openai\n- #46486 Make TUI async question replies compatible with desktop @etraut-openai\n- #46487 Keep TUI exploration grouped across reasoning and nonzero exits @etraut-openai\n- #46488 Split analytics tests into focused suites @rhan-oai\n- #46490 Compose gateway OAuth with primary provider authentication @alexsong-oai\n- #46492 Unify TUI tool output previews with a three-row limit @etraut-openai\n- #46493 Allow `/review` during MCP startup @etraut-openai\n- #46494 Keep remote workspace roots under server control @etraut-openai\n- #46495 Preserve the provisioned macOS CLI's code-signing identity @riley-oai\n- #46498 Allow worktree sessions to use an existing local daemon @etraut-openai\n- #46499 Allow approved escalation with environment-owned network policies @sayan-oai\n- #46500 Block mutating fcntls in restricted macOS Seatbelt policies @nornagon-openai\n- #46501 Add configuration and feature diagnostics to report metadata @pakrym-oai\n- #46503 Use catalog model display names throughout the TUI @etraut-openai\n- #46504 Add six bundled TUI themes and theme-aware accents @etraut-openai\n- #46505 Support catalog parameter schemas for Multi-Agent V2 tools @rhan-oai\n- #46506 Share ChatGPT cookies between HTTP and WebSocket transports @jif-oai\n- #46507 Run Windows sandbox tests exclusively when local @jif-oai\n- #46508 Refresh the model catalog before turns after auth changes @jif-oai\n- #46509 Flush completed Guardian reviews before delivering decisions @jif-oai\n- #46510 Avoid cloning active turn items for metadata-only thread resumes @charliemarsh-oai\n- #46511 Avoid cloning excluded turn items during thread resume @charliemarsh-oai\n- #46512 Capture Guardian review checkpoints from live context @jif-oai\n- #46513 Rename `AgentControl` to `LocalAgentControl` @jif-oai\n- #46514 Replay guardian checkpoints into a fresh session in tests @jif-oai\n- #46516 Handle completion timing in the multi-agent resume test @jif-oai\n- #46517 Stabilize the TUI exit interruption test @jif-oai\n- #46518 Handle delayed process startup in the Guardian network approval test @jif-oai\n- #46519 Use paused time in sampler and model catalog timeout tests @jif-oai\n- #46521 Use macOS member fallback in shared process-group termination helpers @jif-oai\n- #46522 Enable Guardian parent-compaction reuse by default @felixxia-oai\n- #46523 Default local binding to true for MXC managed networking @iceweasel-oai\n- #46524 Retry busy executable launches in packaged daemon tests @felixxia-oai\n- #46527 Pin WinGet publishing dependencies in the release workflow @imac-oai\n- #46528 Bind executor plugin measurements to the trusted plugin version @papayo-oai\n- #46529 Allow compatible feature overrides when starting the shared daemon @etraut-openai\n- #46530 Gate reasoning effort updates on explicit model support @felixxia-oai\n- #46531 Preserve request-level reasoning effort for memory and title workers @felixxia-oai\n- #46532 Remove `com.apple.runningboard` from Seatbelt platform defaults @nornagon-openai\n- #46533 Disable reasoning summaries by default for new TUI threads @celia-oai\n- #46534 Support `env_inherit` in `workspace_root_test` @bolinfest\n- #46535 Allow unrelated namespace mounts in Linux sandbox socket checks @pash-openai\n- #46539 Add a command-start callback for tool lifecycle extensions @papayo-oai\n- #46540 Centralize retry decisions and delays in `CodexErr` @anp-oai\n- #46541 Add opt-in compaction after final responses @hlevy-openai\n- #46542 Add authenticated remote plugin measurement references @papayo-oai\n- #46543 Add bounded filesystem path diagnostics to `codex doctor` @etraut-openai\n- #46544 Expose declared onboarding skills in plugin details @victor-openai\n- #46546 Skip skill discovery when injecting items into initialized threads @hlevy-openai\n- #46547 Expose a backend-independent agent control contract @jif-oai\n- #46548 Advertise the control socket's WebSocket message size limit @konsti-openai\n- #46551 Add a composite action to build and smoke-test Codex packages @anp-oai\n- #46552 Move child completion routing into the agent controller @jif-oai\n- #46553 Return `LiveAgent` records from agent listing @jif-oai\n- #46554 Always use private desktops for legacy Windows sandboxes @iceweasel-oai\n- #46555 Track executor registrations across connection refresh and recovery @viyatb-oai\n- #46556 Keep step settings and approval environments consistent @sayan-oai\n- #46557 Fix active-turn environment selection lookup @sayan-oai\n- #46558 Add shared plugin catalog discovery APIs @TAFOYA-OAI\n- #46559 Encapsulate rollout budget accounting in `LocalAgentControl` @jif-oai\n- #46560 Fix stale environment config in the network approval test @sayan-oai\n- #46561 Support explicit provider model catalog URLs @andrewgu-oai\n- #46562 Add system proxy fallback for login and startup requests @abhinav-oai\n- #46564 Rename plugin MCP and app extension APIs @TAFOYA-OAI\n- #46565 Preserve reasoning order in TUI activity groups @etraut-openai\n- #46566 Allow recovery commands when the current thread is unavailable @etraut-openai\n- #46567 Separate plugin catalog listing from package resolution @TAFOYA-OAI\n- #46568 Use captured environment state for permissions and daemon recovery @sayan-oai\n- #46569 Set explicit turn triggers for exec and TUI requests @eddie-openai\n- #46570 Tag remote model fetch duration by authentication mode @andrewgu-oai\n- #46571 Preserve macOS Seatbelt exclusions in scratch directories @nornagon-openai\n- #46572 Add turn-start cloud plugin discovery to the MCP extension @TAFOYA-OAI\n- #46573 Add a standalone network proxy binary with JSON configuration @viyatb-oai\n- #46574 Notify users when asynchronous questions arrive in the TUI @etraut-openai\n- #46575 Preserve Windows package identity for sandboxed descendants @zm-oai\n- #46577 Allow thread instruction providers to share updates with subagents @vinh-gpt\n- #46578 Fix standalone network proxy policy initialization @etraut-openai\n- #46579 Limit the agent command center to 10 recent sessions on startup @etraut-openai\n- #46580 Keep Guardian reviews on the applied instruction snapshot @jif-oai\n- #46583 Deny XPC service lookups in macOS Seatbelt profiles @nornagon-openai\n- #46659 Move local child-process spawning into `codex-utils-pty` @charliemarsh-oai\n- #46660 Make local child process launch settings explicit @charliemarsh-oai\n- #46661 Avoid fork when spawning macOS filesystem helpers @charliemarsh-oai\n- #46673 Extend server version notices to prerelease and local clients @etraut-openai\n- #46680 Improve TUI contrast, keyboard hints, and picker layouts @etraut-openai\n- #46691 Standardize TUI picker presentation and fix wrapping boundaries @etraut-openai\n- #46692 Unify TUI picker styling and improve compact layouts @etraut-openai\n- #46694 Unify TUI completion popup styling and preserve result identity @etraut-openai\n- #46695 Unify TUI prompts with shared picker styling and layouts @etraut-openai\n- #46697 Unify TUI picker styling and improve compact session layouts @etraut-openai\n- #46708 Preserve logical source text and styles across TUI wrapping @etraut-openai\n- #46709 Add compact activity rendering and preserve transcript source text @etraut-openai\n- #46710 Restore rich tool details in persisted TUI transcripts @etraut-openai\n- #46711 Align persisted TUI activity groups and reasoning with live output @etraut-openai\n- #46712 Recover executed tool call metadata under recorder capacity pressure @ningyi-oai\n- #46714 Skip polling delays in the external queue lifecycle test @charliemarsh-oai\n- #46715 Split shell snapshot credential tests into focused cases @charliemarsh-oai\n- #46719 Extract the TUI transcript overlay into its own module @etraut-openai\n- #46720 Cache transcript layouts across measurement and rendering @etraut-openai\n- #46721 Anchor transcript scrolling to entries and bound viewport rendering @etraut-openai\n- #46722 Cancel pending transcript Home jumps on subsequent navigation @etraut-openai\n- #46731 Render dynamic tool activity and preserve TUI history ordering @etraut-openai\n- #46732 Add selection and copying to the transcript viewer @etraut-openai\n- #46733 Integrate the interactive transcript into the alternate-screen TUI @etraut-openai\n- #46734 Add transcript search and per-activity detail controls @etraut-openai\n- #46739 Add compact transcript browsing and prompt navigation to the TUI @etraut-openai\n- #46749 Stabilize transcript and composer interactions in the TUI @etraut-openai\n- #46750 Preserve startup drafts and submit them when the session is ready @etraut-openai\n- #46751 Add a warning footer and dedicated warnings viewer to the TUI @etraut-openai\n- #46752 Add an animated Codex logo to fresh conversations and onboarding @etraut-openai\n- #46832 Add independent controls for TUI visual effects @etraut-openai\n- #46835 Respect reduced motion in the voice UI @etraut-openai\n- #46837 Improve agent command center rows and page navigation @etraut-openai\n- #46838 Refine the agent command center layout and metadata editing @etraut-openai\n- #46839 Add status filter tabs to the agent command center @etraut-openai\n- #46840 Simplify agent command center hints and back navigation @etraut-openai\n- #46844 Select read-only permissions for temporary structured threads @etraut-openai\n- #46845 Honor the system clock preference in TUI completion timestamps @etraut-openai\n- #46849 Move fullscreen transcript control to TUI configuration @etraut-openai\n- #46855 Increase the default terminal probe timeout from 100 ms to 250 ms @etraut-openai\n- #46856 Support stadium nodes in Mermaid terminal diagrams @etraut-openai\n- #46857 Extract shared text selection helpers for the TUI @etraut-openai\n- #46858 Add mouse selection and editing to the fullscreen composer @etraut-openai\n- #46859 Limit the welcome logo animation to onboarding @etraut-openai\n- #46861 Remove analytics TUI snapshots @etraut-openai\n- #46862 Refresh analytics on identity changes and compact usage menus @etraut-openai\n- #46863 Stabilize usage dashboard navigation and add keyboard help @etraut-openai\n- #46864 Improve usage report layouts and preserve reading positions @etraut-openai\n- #46866 Enable mouse navigation in the TUI usage view @etraut-openai\n- #46867 Preserve streamed answers when subagents finish @fcoury-oai\n- #46877 Allow subagents to request MCP elicitation input @rennie-openai\n- #46879 Count TUI launches by fullscreen transcript configuration @etraut-openai\n- #46880 Preserve voice playback across pauses and packet bursts @etraut-openai\n- #46882 Streamline agent command-center shortcuts and layout @etraut-openai\n- #46883 Add `/tui` to choose the terminal UI mode for the next launch @fcoury-oai\n- #46884 Enable plain clicks on transcript links and style bare URLs @etraut-openai\n- #46895 Add right-click copying for transcript and composer selections @fcoury-oai\n- #46897 Honor the effective terminal color level in activity charts @etraut-openai\n- #46899 Make transcript list spacing uniform after streaming @fcoury-oai\n- #46902 Hide Back to bottom when the current transcript tail is visible @fcoury-oai\n- #46905 Identify local background servers in `/status` @etraut-openai\n- #46910 Preserve transcript position when opening settings pickers @etraut-openai\n- #46912 Keep quota warnings visible in the TUI @fcoury-oai\n- #46917 Enforce current provider requirements for the model catalog @alexsong-oai\n- #46922 Fix realtime V3 transcript reconciliation for handoffs @etraut-openai\n- #46929 Remove the `Error` prefix from TUI `config.toml` load errors @etraut-openai\n- #46931 Use shared, keymap-aware tips in the fullscreen composer @etraut-openai\n- #46938 Add independent TUI rendering toggles for Mermaid, math, and tables @etraut-openai\n- #46946 Populate the agents overview from background tool responses @etraut-openai\n- #46952 Preserve metadata in native user verification requests @teddywyly-oai\n- #46959 Add shared agent message-board extension interfaces @jif-oai\n- #46962 Avoid exposing config values in `codex doctor` errors @jif-oai\n- #46966 Add SQLite storage for local agent message boards @jif-oai\n- #46978 Implement paginated queries for the local agent message board @jif-oai\n- #46979 Index channel posts by timestamp for latest-message lookups @jif-oai\n- #46981 Canonicalize the workspace trust key in the doctor config test @jif-oai\n- #46985 Add collaboration tools for the agent message board @jif-oai\n- #46989 Expand agent message board tool integration coverage @jif-oai\n- #46993 Clarify Bazel lockfile verification failures @jif-oai\n- #46994 Route agent delivery through captured send requests @jif-oai\n- #46999 Decouple tool restrictions from session identity with `ToolPolicy` @felixxia-oai\n- #47010 Add agent inspection without restoring unloaded runtimes @jif-oai\n- #47017 Wire agent message boards into persistent multi-agent runtimes @jif-oai\n- #47026 Add diagnostics for rollout compression metadata failures @jif-oai\n- #47028 Align message-board tools with the multi-agent namespace @jif-oai\n- #47029 Delete persisted message boards with their root threads @jif-oai\n- #47030 Preserve ordered assistant context in Guardian reviews @felixxia-oai\n- #47035 Defer extension tool history materialization until first access @charliemarsh-oai\n- #47036 Share stored JSON payloads across code mode cells with `Arc` @charliemarsh-oai\n- #47038 Cache OS discovery for user agents and telemetry @charliemarsh-oai\n- #47039 Preserve delivered messages through post-tool hook failures @felixxia-oai\n- #47042 Recover corrupt message-board storage during thread deletion @jif-oai\n- #47049 Share SQLite pools across local agent message-board handles @jif-oai\n- #47050 Batch message-board subscriber reads into one SQLite result @jif-oai\n- #47055 Fetch local message board thread summaries in one query @jif-oai\n\n\n","body_html":null,"content_hash":"24d8fc073db718efb80d493a5fa4f33cf6c398cf63a2cd1f734131463567761b","updated_at":"2026-10-05T08:38:02.977Z"},{"id":"58af523f-6ac9-43aa-bacd-c8c1665e6c2d","source_id":"claude-code","dedupe_key":"claude-code:2.1.280","version":"2.1.280","title":"claude code 2.1.280","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21280","published_at":"2026-09-22T15:44:39.443Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added Claude Opus 5.5 (`claude-opus-5-5`), now the default Opus model — 1M context, $4/$20 per Mtok with $0.20/Mtok cache reads\n- Added mouse support to more lists in fullscreen mode: the wheel scrolls the `/skills` list, and a skill's state options in `/plugin` can be clicked\n- Added `CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTH` to change the 2,048-character cap on MCP tool descriptions and server instructions for every MCP server in the session\n- Added hook output sizes and the number of oversized outputs saved to a file to the `hook_execution_complete` OpenTelemetry event\n- Fixed writes through a symlinked path being judged by their in-tree spelling: the prompt names where the write lands, and `acceptEdits`, allow rules and auto mode no longer approve one landing outside\n- Fixed auto mode retrying an action over and over when a safety check declined to review it; the action is now denied once, noting that retrying won't help\n- Fixed auto mode denying actions over and over without pause when a safety check gave no answer; retries now back off, and the turn stops with a message after ten in a row\n- Fixed Write calls failing validation when a model sends `path`, `file_text`, `file_content` or a stray `description` instead of `file_path` and `content`\n- Fixed Ctrl+C or Ctrl+D pressed twice in most dialogs (`/model`, `/effort`, `/config`, `/status`, `/usage`, `/plugin`, `/sandbox`, `/permissions`, `/artifacts`, `/mobile`, `/login`, `/upgrade`, `/usage-credits`, `/install-github-app`, `/setup-bedrock`, `/setup-vertex`) quitting Claude Code instead of closing the dialog\n- Fixed a click that only brought the terminal window to the front also triggering the item under the pointer — in search pickers, tab bars, agent/workflow rows, slash-command links and suggestion dropdowns\n- Fixed a stray `n` closing dialogs and a stray `y` confirming them; Enter and Esc accept and cancel (bind `y`/`n` to `confirm:yes`/`confirm:no` in `keybindings.json` to restore)\n- Fixed text fields in dialogs losing a typed letter, digit or Space to a keybinding on that key\n- Fixed the prompt line staying scrambled on Windows terminals after invisible characters were removed on Enter; the screen is now repainted so you review the exact text that will be sent\n- Fixed the invisible-character cleanup removing the zero-width non-joiner that Persian and Arabic text uses to attach a suffix to a Latin word or number, such as the plural of \"PDF\"\n- Fixed voice dictation not stopping on Ctrl+C (the prompt cleared but the microphone kept recording), Esc not cancelling while a transcript was processing, and held Space starting dictation from the transcript view and vim NORMAL mode\n- Fixed a model switch made from a host app (Claude Desktop, VS Code, SDK) while Claude is working causing a prompt-cache miss on the next prompt\n- Fixed resumed fork subagents rebuilding their tool list instead of re-sending the one they first used, which broke prompt caching for that agent\n- Fixed subagent hand-back messages showing an internal provenance preamble when expanded outside verbose mode\n- Fixed `installed_plugins.json` keeping the install-time commit after updating a plugin from a GitHub repository or git URL that tracks a branch or tag\n- Fixed skills in `~/.claude/skills/` being moved to `~/.claude/skills/.trash/` when a `manifest.json` in that folder listed their names\n- Fixed the session feedback survey showing no hover highlight on light and ANSI themes\n- Fixed `/workflows` briefly showing a one-row list before opening the only run\n- Fixed the mouse wheel not scrolling selection lists with hidden options (such as `/model` and `/permissions`) in fullscreen mode\n- Fixed a skill you switched off showing the same red ✘ as a plugin that failed to load in `/plugin` and `/skills`; off now shows a dim ◯\n- Fixed multi-select option descriptions being indented under the option number instead of under the label\n- Fixed the search box in `/plugin`, `/skills` and `/mcp` losing its right border in fullscreen mode\n- Fixed `/mcp` showing △ in the server list but ⚠ in the detail view for the same server; the list, detail views and `/plugin` now all show ⚠\n- Fixed Home and End doing nothing in the `/config` settings list and in selection lists such as `/model`, `/memory` and permission prompts\n- Fixed PgUp/PgDn in the `/skills` menu wrapping past the first or last skill instead of stopping there\n- Fixed Tab silently changing the selected setting's value in the `/config` list; it now does nothing there\n- Fixed conversations failing on every turn with a \"role 'system' must precede an 'assistant' message\" API error\n- Fixed conversations with the advisor on failing every turn with API Error 400 \"Input tag 'advisor_20260301'\" behind a proxy or gateway that doesn't support it; the request now retries without it\n- Fixed a session failing on every turn and `/compact` when its saved history held a malformed notice about MCP tools that could not be loaded\n- Fixed a crash when resuming a session whose saved transcript holds a malformed system message or a memory-saved notice without its file list\n- Fixed one cause of long-running fullscreen sessions exiting with \"Claude Code exited after an unrecoverable interface error\": a damaged cached message list is now rebuilt\n- Fixed Claude Code hanging when a settings file, or a file it re-reads after an edit, is replaced by a named pipe mid-read\n- Fixed `/config` crashing and some on/off preferences being misread when a preference that has moved to `settings.json` still holds a value like `null` or `\"false\"` in `~/.claude.json`\n- Fixed resuming a session with unfinished background agents, shells or workflows starting a model turn on its own before you typed anything\n- Fixed messages sent to a background subagent being silently lost in headless and SDK sessions when the subagent was finishing its turn\n- Fixed a finished subagent's report being lost when the conversation that launched it was compacted before the report was read\n- Fixed background subagents being unable to use the LSP tool when an LSP plugin is active\n- Fixed background shell tasks reporting benign non-zero exits (e.g. grep with no matches) as failures\n- Fixed background sessions (`claude --bg`) being unable to run git, hooks, plugins and other helper programs when an environment variable handed to the session contained a NUL character\n- Fixed Ctrl+C needing three or four presses to exit while background subagents are running; two presses now exit\n- Fixed IDE selection being dropped when a sent prompt comes back into the input, such as pressing Esc to edit it, rewinding to it, or pressing Esc while startup hooks run\n- Fixed a `!` shell-mode prompt stashed with Ctrl+S coming back as a plain prompt when restored, and `/` listing file paths right after stashing one\n- Fixed `claude agents` showing a blank, unresponsive screen instead of an error when the temp directory is full, not writable or owned by another user\n- Fixed an MCP server re-added under the same name after `claude mcp remove` still showing as needing authentication instead of reconnecting\n- Fixed background plugin marketplace auto-update ignoring git credential helpers, so private-repo marketplaces were re-cloned every run or never updated\n- Fixed `claude plugin update` clearing a plugin's recorded commit and moving it to version \"unknown\" when the official marketplace's snapshot file is a link or too large\n- Fixed the Artifact tool silently disappearing when your organization's policy can't be loaded (for example behind a web proxy); Claude now says what's blocking it\n- Fixed artifact republishes silently resetting stored database access rules or dropping the viewer profile scope when that capability was re-sent without them; they are now refused\n- Fixed `/ultrareview` reporting a stopped cloud review as completed or as an error to retry, and waiting out the full timeout when its session was deleted or the signed-in account changed\n- Fixed the Claude app showing a missing or stale context usage figure for Remote Control and cloud sessions right after /compact or /clear\n- Fixed the Claude app's diff view for Remote Control and cloud sessions dropping a branch's committed files whenever there are also uncommitted changes\n- Fixed cloud and self-hosted runner sessions failing with \"Authentication failed\" after waiting out a long overload during which the session's access token was rotated\n- Fixed memory write conflicts in Cowork sessions showing Claude only the start and end of a memory file over about 10,800 characters, so the retried write dropped the middle\n- Self-hosted runner: Fixed lifecycle-hook commits failing to sign under `--configure-git`\n- Windows: Fixed background cleanup deleting a directory symlink or junction used to relocate `~/.claude/session-env`, `image-cache` or another cleaned-up folder\n- Self-hosted runner: Fixed a turn that ended right at a `--retire-at` release losing its finished signal; the runner now briefly waits for the turn to be reported before stopping the session\n- Reverted `ctrl+l` / `cmd+k` in fullscreen mode clearing the transcript view (added in 2.1.260); they redraw the screen again\n- Improved `/permissions`: focus returns to the rule list after viewing, adding or deleting a rule, and the delete-rule and remove-directory confirmations now default to No\n- Improved `/permissions` tab navigation: ←/→ and Tab pressed in a rule list now switch tabs without moving focus to the tab bar\n- Improved `/cost` cache-miss causes to name thinking mode and thinking display changes\n- Improved the Artifact tool so that when Claude cannot read an artifact link it was given, it tells the user before continuing\n- Improved `/install-github-app`: the GitHub CLI check and repository selection steps now show \"Esc to cancel\"\n- Improved the `/artifacts` and `/workflows` lists: a scrollbar at the right edge shows how much of a long list is hidden and where you are in it\n- Improved the workflow progress tree: running agents and phases now show a dim dot instead of ⟳\n- Improved `/plugin`'s Add Marketplace form in fullscreen: it no longer draws a box inside the pane, and its text and key hints line up with the rest of `/plugin`\n- Improved the `/workflows` detail view in fullscreen: it no longer draws a second horizontal rule under the pane's divider\n- Improved code blocks that don't name a language: they are now colored like inline code, so commands stand out from the surrounding text\n- Improved `/btw` asked while a tool is still running: the side question now knows that call is in progress instead of reading it as a failed one\n- Improved the UserPromptSubmit hook timeout notice and the debug log to name which hook command timed out\n- Improved `@` file suggestions: a file whose name contains the query now ranks above one that only matches across its folder names\n- Improved artifact pages: no Print buttons, confirm dialogs or device features the viewer blocks, email and phone details shown as text, and dark mode that reaches form controls and scrollbars\n- Improved `/ultrareview` uploads: renamed copies of key files, such as `id_rsa copy` or `kubeconfig (1).yaml`, now also stay on your machine\n- Improved the cross-session messaging startup warning to explain that `--debug-file` writes a debug log to a path you choose\n- Changed the default model on Pro and Team Standard plans from Sonnet to Opus, matching Max, Team Premium, and Enterprise\n- Changed an effort level saved before `/effort` became per-model to no longer apply to newly released models such as Opus 5.5; they start at their default until you pick a level\n- Changed Opus 4.7, Opus 4.8 and Fable 5 to stop holding their launch-default effort over `/effort` in `-p` or the Agent SDK, a project, managed or `--settings` `effortLevel`, or a per-model level\n- Changed `/autocompact`'s footer hint to name ←/→, the keys that adjust other ordered values\n- Changed `/fast`'s footer to name Space as the toggle key\n- Self-hosted runner: Changed git in lifecycle hooks to ignore hook folders and programs named in the runner's shared git files; local-path and `git://` remotes there now need `GIT_ALLOW_PROTOCOL`\n- Changed plugin marketplaces whose name imitates a reserved marketplace name to be refused when added, and to stop loading if one was already added\n- Changed `PermissionRequest` hooks: an agent-type hook no longer runs there, since its answer could never allow or deny the request; it now shows an error pointing to command or http hooks\n- [VSCode] Added a Status dialog, with a typed `/status`, showing the session's version, account, model and server details\n- [VSCode] Added a Sandbox dialog for the sandbox mode, the unsandboxed fallback and excluded commands, opened from the panel menu or by typing `/sandbox`\n- [VSCode] Added a Claude in Chrome dialog (extension status, the install, reconnect and permissions pages, the enabled-by-default setting), opened from the panel menu or by typing `/chrome`\n- [VSCode] Added Export conversation, with a typed `/export`, to copy or save the conversation as plain text\n- [VSCode] Added each skill's source, token estimate and on/off state to the Slash commands dialog, with a click to change the state, and a typed `/skills` that opens it\n- [VSCode] Added a typed `/plan` that switches to plan mode, sends a first planning prompt, or shows the session's plan\n- [VSCode] Improved pasted-text handling in the chat box: a paste over 800 characters or over 2 line breaks is now marked so Claude can tell it from what you typed\n- [VSCode] Improved prompt handling in the chat box: invisible Unicode formatting and tag characters are removed from pasted text with a notice, and from anything else before it is sent\n- [VSCode] Changed \"Open in New Tab\" to open Claude beside the editor group you are working in rather than after the last group\n- [VSCode] Fixed the effort chip showing a stale saved effort level instead of the level the session runs at\n- [VSCode] Fixed Claude Code never starting when the Python extension hangs while activating; it now starts after 60 seconds without the Python environment\n- [VSCode] Fixed the plan approval card never offering auto mode: when auto mode is available, its first option is now \"Yes, and use auto mode\", as in the terminal\n- [VSCode] Fixed arrow-key navigation in the session list stopping after archiving or unarchiving a session from the keyboard\n- [VSCode] Fixed paste marker lines showing in your own messages after reopening a session\n- [Claude Code on the web] Changed the admin Routines on/off setting to live under Admin settings → Capabilities → Remote sessions; the Claude Code admin page now links to it\n- [Claude Code on the web] Fixed `gh` and GitHub API calls inside a cloud session on a GitHub Enterprise Server repository failing after about eight hours; the token now renews automatically\n- [Claude Code on the web] Fixed a routine that resumes an existing session running with its old prompt and name when it was edited moments before the scheduled run started\n- [Claude Code on the web] Fixed file links in a cloud session transcript that point outside the session's working directory opening a file card that never loads; they're now disabled and say why\n- [Claude Code on the web] Fixed auto mode refusing to retry a tool call because an approval prompt that expired unanswered, or was superseded by a newer message, had been recorded as your rejection\n- [Claude Code on the web] Improved cloud sessions viewed in the Claude app: Claude now saves files meant for you where the app can open them\n- [Claude Code on the web] Removed the empty repository picker shown when starting a session on a self-hosted environment in an organization where an admin has turned GitHub off\n- [Claude Tag] Added Slack's native Working indicator, Stop button and thread title to Claude's threads in channels; the indicator stays up until Claude finishes, and Stop interrupts the task\n- [Claude Tag] Added a short notice in the Slack channel when a guest joining, or the last guest leaving, changes how Claude responds there under a Restrict or Channel only guest setting\n- [Claude Tag] Fixed scheduled routines silently failing to run in Slack workspaces that were connected to Claude before the workspace joined its Enterprise Grid\n- [Claude Tag] Fixed Claude asking you to re-upload a Slack file when a brief file-scanning outage, not the file, was the problem; it now retries the scan and is told when the scanner is down\n- [Claude Tag] Fixed a bullet in Claude's Slack reply whose text starts with +, - or * rendering as an empty bullet with a stray nested item; it now shows as one bullet with the character kept\n- [Claude Tag] Fixed the Slack notice for a failed cloud environment setup script sometimes being a generic \"mention me to retry\"; it now names the setup script and says to fix it first\n- [Claude Tag] Improved the GitHub banner in Claude Tag admin settings to say why GitHub isn't connected: not signed in, app not linked or not installed, sign-in expired, or SSO not authorized\n- [Code Review] Improved the Code Review check run to say when REVIEW.md instructions were cut or left out of a review for exceeding a size limit, naming the file and the limit","body_html":null,"content_hash":"d59d50c64e194b652d68f067b3e1f25242178f8a6685e243f524bdb6963d159c","updated_at":"2026-10-05T19:07:41.407Z"},{"id":"0926b7de-2b21-490a-902d-86d2749ee238","source_id":"grok","dedupe_key":"grok:grok-47","version":"4.7","title":"Grok 4.7","url":"https://docs.x.ai/developers/release-notes#grok-47","published_at":"2026-09-21T00:00:00.000Z","date_reconciled":1,"digest_import":1,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T18:08:02.751Z","body_md":"Grok 4.7, SpaceXAI's frontier model for coding, agentic tasks, and knowledge work, is now available on the xAI API as grok-4.7. It has a 500k context window, text and image inputs with text-only output, and no text output limit. Pricing is $2 / $0.50 / $6 per 1M tokens (input / cached input / output) below 200k prompt tokens, and $4 / $1 / $12 above. Reasoning effort supports low, medium, high (default), and xhigh. On the Responses API, grok-4.7 always returns reasoning.encrypted_content, even when include does not list it. It is also served on the US regional endpoint. Grok 4.7 Fast is the same model and costs 2x the standard token rates, or 1.5x for long-context requests. It's available only in Cursor and Grok Build, not on the public xAI API, and is billed through your plan there. See the Grok 4.7 overview and the announcement.","body_html":"<p>Grok 4.7, SpaceXAI&#x27;s frontier model for coding, agentic tasks, and knowledge work, is now available on the xAI API as <code>grok-4.7</code>. It has a 500k context window, text and image inputs with text-only output, and no text output limit. Pricing is $2 / $0.50 / $6 per 1M tokens (input / cached input / output) below 200k prompt tokens, and $4 / $1 / $12 above. Reasoning effort supports low, medium, high (default), and xhigh. On the Responses API, <code>grok-4.7</code> always returns <code>reasoning.encrypted_content</code>, even when <code>include</code> does not list it. It is also served on the <a href=\"https://docs.x.ai/developers/advanced-api-usage/regions\">US regional endpoint</a>. Grok 4.7 Fast is the same model and costs 2x the standard token rates, or 1.5x for long-context requests. It&#x27;s available only in Cursor and Grok Build, not on the public xAI API, and is billed through your plan there. See the <a href=\"https://docs.x.ai/developers/grok-4-7\">Grok 4.7 overview</a> and the <a href=\"https://x.ai/news/grok-4-7\">announcement</a>.</p>","content_hash":"3b5d83ee100eaedba46f3aba37c2486aad71d13ec20934035b45c796a534f39a","updated_at":"2026-10-05T19:07:18.890Z"},{"id":"c092ff06-f17b-4194-917f-745b396c5188","source_id":"claude-code","dedupe_key":"claude-code:2.1.278","version":"2.1.278","title":"claude code 2.1.278","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21278","published_at":"2026-09-19T01:48:59.758Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Changed auto mode for Claude API and Enterprise users, and on Bedrock, Vertex, Foundry and gateways, to default to the server-side classifier, which does not charge for classifier overhead (`CLAUDE_CODE_AUTO_MODE_SERVER=0` opts out on Bedrock, Vertex, Foundry and gateways); warns on billed fallback. See https://code.claude.com/docs/en/auto-mode-classifier-billing\n- Added an `Auto mode server` row to `/status` showing whether this session's auto mode classifier runs on the server","body_html":null,"content_hash":"9cb8f8ba7f869c0975692151ef5742aea3cc921728e601440aa459af37a0591c","updated_at":"2026-10-05T19:07:41.407Z"},{"id":"9abf6e70-2cf6-4b76-a939-65e89b171c0e","source_id":"claude-code","dedupe_key":"claude-code:2.1.277","version":"2.1.277","title":"claude code 2.1.277","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21277","published_at":"2026-09-18T16:22:26.548Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added AGENTS.md support: in a project with no CLAUDE.md, Claude Code reads AGENTS.md instead; change it under \"Project instructions\" in `/config`\n- Added `CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY=1` for Claude apps gateways whose only egress is a forward proxy: every outbound request hands the proxy the hostname instead of resolving it locally\n- Added an optional `headers:` map on Claude apps gateway upstreams, to send static headers to a proxy you run in front of a provider\n- Added a line saying a background task's update is waiting when it finishes while a panel such as `/tasks` is open\n- Fixed `claude -p` and Agent SDK sessions that could hang with no result after an internal error; they now report the error and exit with code 1\n- Fixed conversations failing every request with \"text content blocks must be non-empty\" when an earlier assistant turn held an empty text block beside other content, including after `--resume`\n- Fixed being unexpectedly logged out when an older Claude Code build (for example an IDE extension's bundled CLI) runs on the same machine as the current one\n- Fixed interactive start-up hanging or showing an error for `ANTHROPIC_API_KEY` users when `~/.claude.json` holds a malformed `customApiKeyResponses` value\n- Fixed update checks erroring every 30 minutes, and `claude update` hanging when a minimum or maximum version is set, if a proxy returns an invalid version; a malformed `minimumVersion` is now ignored\n- Fixed `claude update` on winget- or apk-managed installs reporting \"up to date\" when the version lookup failed\n- Fixed `claude plugin install` sometimes failing and breaking the installed copy when reinstalling a plugin version that a session or another program was using; an unchanged copy is now left alone\n- Fixed Grep and Glob reporting no matches when the search could not start because the system was out of processes, memory or file handles; they now return an error saying so\n- Fixed the Write tool silently ending the turn as a declined permission when the target path is an existing directory; it now reports a clear error\n- Fixed the Edit tool treating an escaped backslash followed by `uXXXX` text as a `\\uXXXX` escape, which could make an edit of a non-ASCII character rewrite an escaped backslash sequence instead\n- Fixed the Edit tool reporting \"Invalid regular expression: regular expression too large\" instead of \"String not found in file\" when a very large edit containing non-ASCII text did not match the file\n- Fixed a turn ending early with \"Path contains null bytes\" when a tool call's file path contained `\\u0000` written as an escape sequence; escaped control characters now stay as literal text\n- Fixed background sessions (`claude --bg`) exiting when a plugin's LSP server exited or closed its stdin\n- Fixed a crash (\"Type error\") when opening `/mcp` or `/plugin manage` with a malformed `claudeAiMcpEverConnected` value in `~/.claude.json`\n- Fixed a crash at launch when `~/.claude.json` holds a malformed `theme` value\n- Fixed a crash (\"unrecoverable interface error\") when the prompt held text containing terminal color codes, for example a prompt recalled from history or text loaded from the external editor\n- Fixed a crash when resuming a session whose saved history holds an assistant message stored as a plain string\n- Fixed sessions on slow or heavily loaded machines sometimes exiting with \"Claude Code exited after an unrecoverable interface error\" when the first spinner appeared\n- Fixed a rare case where the screen could stop updating for the rest of the session after an internal rendering error\n- Fixed a rare case on Windows where a turn could stop with an error such as \"Out of memory\" right after Claude replied, so that reply's tool calls never ran\n- Fixed sessions continued after `/clear` (restart, `--continue`, `--resume`) missing part of their first message when a SessionStart hook printed output, causing a full prompt-cache miss\n- Fixed messages from other agents (such as a subagent's SendMessage) that arrived mid-turn showing up below the \"Ran N shell commands\" row instead of where they arrived\n- Fixed the \"copied\" notice not appearing after drag-selecting text in the fullscreen `/resume` picker and other panels that cover the prompt area\n- Fixed `$TMPDIR` expanding empty in Bash commands that run outside the sandbox while sandboxing is enabled\n- Fixed WebFetch and WebSearch in Cowork cloud sessions not telling Claude why a request was refused, such as a used-up fetch budget or an admin policy\n- Fixed the Claude apps gateway's telemetry relay ignoring a collector hostname or domain listed in `NO_PROXY` when a proxy is set\n- Fixed one malformed `strictKnownMarketplaces` or `blockedMarketplaces` entry silently disabling the whole enterprise marketplace policy\n- Fixed failed auto-updates leaving large staged downloads behind in `~/.cache/claude/staging`\n- Fixed `/plugin` not stripping terminal control characters from messages on the Installed tab, such as the error of a failed plugin update\n- Fixed `/plugin` → Installed and `/skills` crashing when a skill or legacy command is named like a built-in Object property such as `constructor` or `toString`\n- Fixed `/plugin` closing with no message when every install in a multi-select failed\n- Fixed uninstalled plugins reappearing as \"failed to load\" rows in `/plugin` Installed, and Remove not clearing such a row\n- Fixed plugins from the official marketplace being recorded without their commit in `installed_plugins.json`, and `installed_plugins.json` keeping the old commit after updating a pinned-commit plugin\n- Fixed plugin reload previews keeping every previewed copy of a plugin archive unpacked until exit, and overwriting the cached `--plugin-url` archive a reload falls back to when its download fails\n- Fixed Remote Control session bookkeeping failing when `~/.claude.json` holds a malformed placeholder record\n- Fixed the error after a revoked claude.ai login blaming an expired Anthropic profile; it now leads with `/login`\n- Fixed typed or pasted text occasionally coming out scrambled in the `claude agents` dispatch input during key repeat or very fast input\n- Fixed a crash (\"unrecoverable interface error\") when resuming a session whose saved transcript contains a stop hook summary without a well-formed hook list\n- Fixed Enter on a selected agent panel row doing nothing when `keybindings.json` rebinds Enter in the Chat context, for example to `chat:queueSubmit`\n- Fixed PDF page reads on Windows failing when the working folder's path is long (about 120 characters or more)\n- Fixed a headless resume (`claude -p --resume`, the SDK, a VS Code extension window reload) starting the session's cost and usage totals at zero; headless sessions now save their totals at exit\n- Fixed project skills from the main repository not loading in `--worktree` sessions when `.claude/skills` is untracked\n- Fixed a `sandbox.excludedCommands` glob exempting an entire compound Bash command from the sandbox when only one part matched; every part must now match\n- Fixed resumed subagents and teammates re-rendering the MCP tool definitions they had loaded, which broke prompt caching for that agent\n- Fixed rate-limited artifact publishes telling Claude to stop retrying; Claude is now told nothing was published and when to send the same publish again\n- Fixed attachments recorded earlier in a conversation being re-rendered after a resume or relaunch, which dropped extended thinking and missed the prompt cache\n- Fixed Console sign-in showing only \"Request failed with status code 400\" when the server refuses to create an API key; it now shows the server's message\n- Fixed messages typed while Claude is still working sometimes being ignored by the model\n- Improved session start-up for SDK and headless (`-p`) use: the first turn no longer waits on the per-directory CLAUDE.md lookup\n- Improved the Claude apps gateway's loopback error messages to name `CLAUDE_GATEWAY_ALLOW_LOOPBACK`\n- Improved `/plugin` Installed: an MCP server listed apart from its plugin now shows which plugin it belongs to\n- Improved `claude plugin install` on an already-installed plugin: it now says when the marketplace offers a newer version and names the `claude plugin update` command\n- Improved the startup notice overflow line under the logo: it now reads \"N more notices hidden\" instead of \"+N more · /status\"\n- Improved prompt handling: invisible Unicode formatting and tag characters in a prompt are removed and the cleaned prompt is shown for review before it is sent\n- Improved `/ultrareview` when there's nothing to review: messages say which case you're in, offer a command that reviews your latest commit, and a new repository's first commit is reviewed in full\n- Improved artifact link handling so Claude reads claude.ai artifact links with the Artifact tool instead of WebFetch when that tool is available\n- Improved the dangerous-rm permission prompt to name the flagged rm command and suggest a `${VAR:?}` guard, so headless runs can recover\n- Improved the Artifact tool's permission prompts: shorter sentences, pages and artifacts named by title or file name, and links listed after the text\n- Changed Fable to always appear in `/model` on the Anthropic API; it is greyed out only when your organization's settings disable it\n- Changed the Bash sandbox instructions on Bedrock, Vertex and Foundry to the first-party wording, which frames the sandbox as the boundary of what the task was given\n- Changed `/ultrareview` in non-interactive sessions to refuse when the repository has no base branch or shared history\n- Changed subagent results to reach the main agent under a header marking them as subagent output, with the result indented, so text in a subagent's result cannot pass as the session's own instructions\n- Changed workflow scripts' computed `agent()` prompts on Bedrock, Vertex and Foundry to reach the subagent framed as script-authored text, so the safety classifier does not read them as the user\n- Removed the background Haiku auto-title request from `claude -p` runs launched outside an SDK or IDE\n- Removed the deprecated TaskOutput tool; Claude reads a background task's output file with Read instead, and the `taskOutputMaxChars` setting and `TASK_MAX_OUTPUT_LENGTH` no longer have any effect\n- [VSCode] Added a Sign out row to the panel menu, with `/logout` in the typed command menu\n- [VSCode] Added background shells and other running tasks to the agent map, each with a Stop, and a typed `/tasks` that opens it\n- [VSCode] Added a Copy response button on responses and a typed `/copy`\n- [VSCode] Added a one-time notice when inactive sessions are archived automatically, and an \"Unarchive all\" action on the Archived sessions group\n- [VSCode] Added the session's cost and token usage to the Account & usage dialog and the session manager where plan limits do not apply (Vertex, Bedrock, Foundry, API key)\n- [VSCode] Fixed the \"General config\" menu row showing `/config` usage text instead of opening settings, and made typed `/mcp`, `/hooks`, `/memory`, `/rewind` and similar commands open their dialogs\n- [VSCode] Fixed the effort slider's level not persisting into later sessions on a model that already had a level saved with `/effort`\n- [VSCode] Fixed Auto missing from the mode picker for conversations opened in an already-used panel when the saved model setting is a differently-cased alias such as \"Sonnet\"\n- [VSCode] Fixed `/fast` not saving fast mode as the default, so it was lost when the extension relaunched Claude Code\n- [Claude Code on the web] Added Personal and Organization sections to the environment picker on Team and Enterprise plans, and admins can now share a personal environment with the organization\n- [Claude Code on the web] Changed organization environments to open as a read-only summary from the Code tab on Team and Enterprise plans, with editing under Admin settings → Cloud environments\n- [Claude Code on the web] Fixed a cloud environment saved with Custom network access and no domains silently reverting to Trusted; the dialog now asks for at least one domain\n- [Claude Code on the web] Changed the admin Claude Code setting labeled \"Web\" to \"Cloud sessions\" and removed the redundant read-only Mobile row beneath it\n- [Claude Tag] Fixed routines created in a Slack channel on an Enterprise Grid org-wide install failing to read other public channels in their workspace when they ran\n- [Claude Tag] Fixed the \"Learn more\" links on credential presets in Claude Tag access bundles to open each vendor's credential-setup page instead of a generic API reference\n- [Claude Tag] Changed the Pylon credential preset in Claude Tag access bundles so admins can point it at Pylon's EU host\n- [Claude Tag] Fixed Google Cloud credential forms in Claude Tag access bundles: a refused key file now says why, the website and scopes stay locked, and a rejected rotation keeps the pasted key\n- [Claude Tag] Fixed the network events log in Claude Tag admin settings showing no response status for requests through connections that use AWS signing, client certificates or a custom CA","body_html":null,"content_hash":"589eedd52b401e2ca12fb15ee6376360c905ada6b17bfd370a601d95604e1613","updated_at":"2026-10-05T19:07:41.407Z"},{"id":"7401583d-80e9-4825-b73b-e15ffc332095","source_id":"claude-code","dedupe_key":"claude-code:2.1.276","version":"2.1.276","title":"claude code 2.1.276","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21276","published_at":"2026-09-18T01:39:31.986Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Fixed every request failing with `400 … Input tag 'advisor_20260301'` when `ANTHROPIC_BASE_URL` points at a proxy or gateway (2.1.275 regression)","body_html":null,"content_hash":"30a9247333069f711780048e216ea90e8b8c6b6cca3550055640a04869306a28","updated_at":"2026-10-05T19:08:03.559Z"},{"id":"fb529cec-8291-4ca9-895c-b716dd438260","source_id":"claude-code","dedupe_key":"claude-code:2.1.275","version":"2.1.275","title":"claude code 2.1.275","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21275","published_at":"2026-09-17T20:20:31.805Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added the signed-in account to Claude apps gateway sign-in: when the gateway names it, you confirm it before the credential is saved, and `/status` shows it\n- Added a send-now key (ctrl+enter, or ctrl+x ctrl+s) that interrupts the current turn and sends all queued messages at once; sent and queued messages show in gray until the model receives them\n- Added a startup warning when a configured `otelHeadersHelper` fails, so sessions that silently export no telemetry are noticed\n- Added syncing of the skills and plugins enabled on your claude.ai account to terminal sessions signed in with it; opt out with `syncClaudeAiSkills: false` or `syncClaudeAiPlugins: false`\n- Added `/plugin install <plugin> --marketplace <source>`, which offers to add the marketplace before installing the plugin\n- Fixed a restored memory file's age note changing between requests after a compaction or resume, which caused prompt cache misses\n- Fixed `--forward-subagent-text` stream-json and SDK output dropping the messages of subagents spawned by a `context: fork` skill, and of forked skills invoked by a subagent or another forked skill\n- Fixed @-mention file suggestions being buried below MCP resources when using a custom `fileSuggestion` command or typing `@.`/`@./`\n- Fixed fullscreen mode placing background-task completion notices beneath a long turn's collapsed tool row instead of where they arrived; each notice now closes the open row\n- Fixed `claude plugin marketplace update` deleting a GitHub marketplace's local copy when the fetch failed and the marketplace was named after its repository\n- Fixed plugin and marketplace messages, logs and `claude plugin marketplace list` showing a password or token stored in a git, ssh or marketplace URL\n- Fixed a resumed cloud session leaving an unanswered question open in the transcript after a queued message superseded it\n- Fixed vim mode placing the cursor one character right after a dot-repeated \"!\" or a fast-typed \"i!\" switched a non-empty prompt into shell mode\n- Fixed fullscreen mode freezing or blanking for several seconds when scrolling up past a large file diff\n- Fixed a stray `</ccmemory>`-style closing tag occasionally appearing in responses\n- Fixed plugin messages, logs and the VS Code plugin dialog showing the wrong server for some git addresses\n- Fixed a terminal `API Error: 400` on every turn for users behind a network gateway that rewrites API error responses when a beta request header is rejected\n- Fixed sandboxed Bash commands on Linux reporting exit code 0 for failed commands when the shell is zsh\n- Fixed the Read tool hanging instead of reporting an error when part of a large file could not be decoded under memory pressure\n- Fixed `--resume`, the resume picker preview, resumed background agents and the transcript view failing on a session whose saved history contains a malformed task-reminder or @-file attachment entry\n- Fixed a crash when resuming a conversation whose transcript contains a malformed message entry, and a fullscreen crash when such a conversation received new messages while scrolled up\n- Fixed sessions failing to resume or start when their saved transcript contains a malformed message content block\n- Fixed Grep, Glob and @-file suggestions hanging or running out of memory on searches over the 20MB output cap, and system ripgrep reporting \"no matches\" instead of an error after a flood of warnings\n- Fixed `/rewind` in a forked or background session restoring a zero-filled or truncated file when the session's file-history backups could not be fully copied\n- Fixed fullscreen sessions sometimes exiting with \"Claude Code exited after an unrecoverable interface error\" when typing fast or holding a key with the slash-command dropdown open\n- Fixed background sessions crashing and restarting their worker when a command fed through stdin ran on a machine that had run out of file descriptors\n- Fixed a crash at launch when `~/.claude.json` holds a malformed `mcpNeedsAuthNoticed` value\n- Fixed `--resume` and `--continue` dropping a conversation's earlier thinking when a built-in tool it started with has since been switched off by a server-side flag\n- Fixed text selected with the mouse in the fullscreen `claude --resume` session picker never reaching the clipboard\n- Fixed plugin reload previews replacing a running session's extracted plugin files when the plugin was loaded from a `--plugin-dir` or `--plugin-url` archive\n- Fixed self-hosted runners with `--drain-wait-sec` losing the final result of a turn that finished during a SIGTERM drain; the runner now waits briefly for the turn to be reported\n- Fixed `SubagentStop` hooks with a specific `matcher` firing for every stopping subagent whose agent type was empty\n- Fixed sandboxed Bash commands being unable to write to project directories named `hooks/` or `config/`\n- Fixed Artifact updates failing with \"File not found\" after a session resumes on another machine or its scratchpad is cleared: the page's last published version is restored\n- Fixed `/update-config` writing `Write(path)` permission rules, which file permission checks don't match, instead of `Edit(path)` rules\n- Fixed four dead documentation URLs (Pricing, Computer Use, Skills, CLI) in the bundled claude-api skill's live-sources table\n- Improved prompt caching for a `--system-prompt` that contains a `__SYSTEM_PROMPT_DYNAMIC_BOUNDARY__` line: the text above it is now cached globally, as the SDK's array form already is\n- Improved the `/desktop` error when Claude Desktop does not open: it now says why and what to do next\n- Improved the Artifact tool's publish and read results: they now say who can open the page and what the owner's Share menu offers\n- Improved artifact publish results: they name the tab icon sent, warn when the page contains a NUL byte, and retry a flaky fetch of the newer page to merge after a stale publish\n- Improved pasted and attached images: they are now saved where Claude can open them as files without a permission prompt, including in Desktop and VS Code\n- Improved the Artifact tool's guidance so Claude updates a shared artifact in place when you were given edit access to it, instead of publishing a separate copy\n- Improved plan-usage reads: editor windows and non-interactive sessions on one machine now share a read made in the last minute instead of each calling the usage endpoint\n- Improved the `ListPlugins` tool description so Claude knows it lists plugins enabled on your claude.ai account, not plugins installed locally with `/plugin`\n- Improved responsiveness when the terminal is slow or paused: output no longer falls further behind while the terminal catches up\n- Improved Write and Edit results for files in the synced account-skills folder: they now say the change is not saved to your account and how to save it\n- Updated `/logout` for Claude apps gateway sign-ins to also end the session on gateways that advertise token revocation\n- Changed hosted sessions to keep an unanswered permission prompt up after a container restart, instead of asking again\n- Changed the Artifact tool to ask for a one-word tab icon on a first publish instead of an emoji favicon\n- Changed Claude in Chrome in auto mode to skip the extension's per-site check for classifier-approved calls, as bypass mode does, fixing `browser_batch` \"Permission denied\" after a redirect\n- Changed plugins installed from an npm source to be fetched with `npm pack --ignore-scripts` and integrity-verified, so a package's install scripts no longer run\n- Changed scheduled and Run now routine runs to save data to, and republish the page of, an artifact you can edit without asking; public artifacts, first publishes and deletes still ask\n- Removed the startup notice that told you a one-off scheduled routine had run since your last session\n- [VSCode] Added viewing, editing and deleting a saved memory inside the Memory dialog\n- [VSCode] Added sending an attached image without typing any text\n- [VSCode] Added a Retry link to the MCP servers dialog when the server list fails to load\n- [VSCode] Added accept and reject buttons under each change in the proposed-change diff tab, so an edit can be reviewed change by change\n- [VSCode] Fixed the transcript creeping toward the bottom in small steps while a permission card waits and content keeps arriving\n- [VSCode] Fixed rewound and forked conversations not keeping the permission mode you had picked for the original conversation\n- [VSCode] Fixed an empty `CLAUDE_CONFIG_DIR` entry in the `environmentVariables` setting making Claude Code keep its files in the workspace\n- [VSCode] Fixed plugin install links opening the Manage plugins dialog for plugin names and marketplace addresses that can't be used in a link\n- [VSCode] Fixed Remote Control staying shown as connected after a turn-off that Claude Code reported as failed; it now shows as off\n- [VSCode] Fixed the scroll to the bottom on send stopping short of the reply when the reply starts arriving during the scroll\n- [VSCode] Fixed the agent map showing agents a crash left unfinished as stopped instead of failed once the session is reopened\n- [VSCode] Fixed the \"Continuing the step\" notice not appearing, and the continue limit resetting, after a reload that follows a crash with background tasks still running\n- [VSCode] Fixed the session list showing when a session was last reopened, such as after a window reload, instead of when its last message was sent\n- [VSCode] Fixed \"Fork conversation from here\" failing on the message right after one sent while Claude was working\n- [VSCode] Fixed the prompt cache clock showing too few minutes after reopening a session with a message sent while Claude was working\n- [VSCode] Fixed a background agent that finished while Claude was running a tool losing its completion notice, and its result on the agent map, after a window reload\n- [VSCode] Fixed a rare case where text selected in a git-ignored file could be sent to Claude after the extension was unresponsive for several seconds\n- [VSCode] Fixed renaming a running session reverting to the generated name (regression in 2.1.269)\n- [VSCode] Fixed slash commands typed while Claude is responding being sent to the model as text instead of running once the response finishes\n- [VSCode] Fixed unreadable code in the plan preview and the Hooks and Permission rules dialogs with the High Contrast Light theme\n- [VSCode] Fixed `/remote-control` being ignored while Remote Control is still connecting: running it again now turns Remote Control off immediately\n- [VSCode] Fixed the conversation pulling you back to the bottom while a reply streams after you scroll up, and added a `claudeCode.scrollToBottomOnSend` setting to turn off the jump on send\n- [VSCode] Fixed the Manage plugins dialog showing a password or token that was typed into a marketplace URL\n- [VSCode] Improved the agent map: the pill counts running agents and turns red after a failure, the main agent stays in view while the map scrolls, and agents sort by state then end time\n- [VSCode] Changed New session in a Claude editor tab to open in the sidebar when Preferred Location is set to Sidebar, instead of always opening another tab\n- [VSCode] Changed a message sent while Claude is working to wait at the bottom of the conversation until Claude starts on it\n- [Claude Code on the web] Added a \"New routine\" button to the page shown when a routine link no longer resolves, next to the link back to your routines list\n- [Claude Code on the web] Fixed routine \"paused\" and \"on hold\" notifications being cut off mid-sentence; the paused-subscription notice now says to turn the routine back on yourself\n- [Claude Code on the web] Fixed cloud environments with a very long allowed-domains list saving fine and then failing every session start; saving now fails up front and says how much to trim\n- [Claude Code on the web] Fixed Claude's guidance when a cloud session on a personal account is denied GitHub access: it now links to claude.ai/connect-github instead of an admin settings page\n- [Claude Code on the web] Improved what Claude tells you when asked to edit, delete or run a routine it didn't create: it now links to the routine's page so you can do it yourself\n- [Claude Tag] Added attach conditions for access bundles in Claude Tag settings: an Owner can let a bundle also apply in channels with guests or Slack Connect channels, not just member-only\n- [Claude Tag] Added Amazon CloudWatch, CloudWatch Logs, Amazon SNS, Google Cloud Monitoring and Cloud Logging presets to an access bundle's Credentials tab in Claude Tag admin settings\n- [Claude Tag] Added Datadog presets for the US3, AP1, AP2 and US1-FED sites; new Datadog connections are now limited to Datadog's read and query API routes\n- [Claude Tag] Fixed S3 uploads from recent AWS CLI and SDK versions failing with a 502 error when sent through an AWS connection\n- [Claude Tag] Fixed Claude treating a channel as inactive, and skipping untagged messages there, while it was still posting in that channel from a routine or a thread\n- [Claude Tag] Fixed a thread's \"Claude [task]\" display name reverting to plain \"Claude\" after the session behind that thread was refreshed or restarted\n- [Claude Tag] Fixed the model you switched to in a Slack thread silently reverting to the channel's default after that thread's session was restarted or refreshed\n- [Claude Tag] Fixed Claude sometimes replying twice when another app or bot @mentioned it in a top-level channel message\n- [Claude Tag] Improved Claude's notices in Enterprise Grid channels shared across workspaces: they now say when no workspace is set up yet, or why only organization defaults apply\n- [Code Review] Fixed reviews occasionally dropping part of their analysis when one of the reviewing agents returned its findings in an unexpected format\n- [Code Review] Fixed pull requests with more than 100 Claude reviews getting a full re-review on every clean merge from the base branch instead of the lighter merge-focused review","body_html":null,"content_hash":"e8c74ab1565074e4553cb92bd4f6fa0bbda50ecbfee97bf895dc963e3d1b042b","updated_at":"2026-10-05T19:08:03.559Z"},{"id":"82a6dc23-2d5a-4bdb-9a48-ef9971f71995","source_id":"grok","dedupe_key":"grok:grok-voice-transcribe-20","version":"2.0","title":"Grok Voice Transcribe 2.0","url":"https://docs.x.ai/developers/release-notes#grok-voice-transcribe-20","published_at":"2026-09-17T00:00:00.000Z","date_reconciled":1,"digest_import":1,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T18:08:02.751Z","body_md":"grok-voice-transcribe-2.0 is now available. Use grok-voice-transcribe-1.0 or grok-voice-transcribe-2.0; the default is grok-voice-transcribe-2.0. See the Speech to Text docs.","body_html":"<p><code>grok-voice-transcribe-2.0</code> is now available. Use <code>grok-voice-transcribe-1.0</code> or <code>grok-voice-transcribe-2.0</code>; the default is <code>grok-voice-transcribe-2.0</code>. See the <a href=\"https://docs.x.ai/developers/model-capabilities/audio/speech-to-text\">Speech to Text docs</a>.</p>","content_hash":"6e9b0b6d6b593642ac58bae3293b8b066f7c19c04168390cf82b060090d64aaf","updated_at":"2026-10-05T19:07:18.890Z"},{"id":"29bb9288-a644-4b85-a37c-01da97eed423","source_id":"claude-code","dedupe_key":"claude-code:2.1.274","version":"2.1.274","title":"claude code 2.1.274","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21274","published_at":"2026-09-16T22:36:09.883Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added a visible warning when memory usage is critical, with steps to free memory or restart safely\n- Added `CLAUDE_CODE_MCP_STARTUP_WAIT_MS` to bound how long the first non-interactive turn waits for connecting MCP servers (`0` = don't wait)\n- Added `effort` attribute to the `claude_code.llm_request` OpenTelemetry trace span, matching the `api_request` event\n- Added `claude_code.managed_settings_resolved` OTel event: managed-settings sources and policy helper state; redacted settings and digests with `OTEL_LOG_MANAGED_SETTINGS=1`\n- Added `store.connect_timeout_seconds` to the Claude apps gateway config to lengthen the Postgres connect timeout (default 5 seconds), and improved the boot error when the database is unreachable to point to `store.postgres_url` and the configured timeout\n- Added `enduser.sub`, the IdP subject, to the telemetry Claude Desktop and Cowork send through a Claude apps gateway\n- Added a Claude apps gateway warning when a replica has more requests open than the 256 it sends upstream at once, and a startup log line showing that limit\n- Added click-to-expand for collapsed teammate and agent messages in fullscreen mode\n- Fixed sessions getting stuck endlessly retrying \"unexpected tool_use_id\" 400 errors: corrupted transcripts now self-heal where possible, and otherwise a clear error (with a `/rewind` hint) ends the loop\n- Fixed MCP servers configured as `http` that only speak legacy HTTP+SSE failing to connect when they answer the first request with 422 or another 4xx error\n- Fixed Streamable HTTP MCP tool calls timing out after about 5 minutes even when a longer per-server `timeout` was set\n- Fixed MCP prompts and resources not refreshing when a server sends list-changed notifications without declaring `listChanged`\n- Fixed MCP tool calls refused with 403 insufficient_scope being reported as an expired sign-in: the error now names the missing permissions and points to `/mcp` re-authentication\n- Fixed hook-driven sessions (such as an active `/goal`) ending with \"Prompt is too long\" instead of compacting when the context overflowed again after a reactive compaction\n- Fixed an active `/goal` being lost when resuming (`--continue` / `--resume`) a session that had compacted\n- Fixed `claude agents` losing `--model`, `--effort`, `--permission-mode`, `--allow-dangerously-skip-permissions` and `--agent` after an auto-update relaunch\n- Fixed a per-turn slowdown when a language server publishes project-wide diagnostics for thousands of files\n- Fixed subagents with `model: \"opus\"` on Bedrock, Vertex or Foundry leaving the session's model when its id has no recognizable model family (unless `ANTHROPIC_DEFAULT_OPUS_MODEL` is set)\n- Fixed self-hosted runner sessions failing every turn with a 401 after a few failed token refreshes, until the next scheduled refresh; the runner now keeps retrying, and fetches a new token after a 401\n- Fixed clickable links to local file paths doing nothing in VS Code and other terminals that require a `file://` URI\n- Fixed the transcript renumbering ordered lists in your own messages (typing \"3. 2. 1.\" displayed \"3. 4. 5.\"); numbers and \"N)\" markers now show as typed\n- Fixed AskUserQuestion preview notes being attached to a previously chosen option instead of the highlighted one\n- Fixed AskUserQuestion preview mode dropping the highlighted option when submitting a note with Enter\n- Fixed a resumed background agent keeping half of an interrupted tool batch when one of its calls was approved with a message\n- Fixed a local `claude -p --resume` started with `CLAUDE_CODE_RESUME_INTERRUPTED_TURN` not reporting background tasks the previous process left unfinished\n- Fixed the first turn of a cloud session sometimes starting without the tools of an SDK-hosted MCP server that was still connecting\n- Fixed background agent notifications claiming the agent had no live background work when it was still waiting on its own background task and would resume\n- Fixed error hints in Claude Desktop sessions to suggest slash commands like `/usage-credits` instead of CLI flags that cannot be used there\n- Fixed `/schedule` saving a routine's prompt without its message role when Claude writes the routine in the shape that listing routines returns\n- Fixed `/status` not showing the `apiKeyHelper` failure that its own error banner told you to check\n- Fixed `/fast on` in non-interactive sessions reporting on and then turning off under an organization's managed fast mode policy; it now says the organization has disabled it\n- Fixed the Artifact tool asking you to approve an update to an artifact that it then refused because the session had not read the latest version\n- Fixed Cowork and claude.ai cloud sessions with network access on treating reads of a teammate's artifact as if network access were off\n- Fixed a plugin or marketplace directory with no git repository of its own taking its version from an enclosing git repository, such as a git-managed `~/.claude`\n- Fixed `--strict-mcp-config` with an empty `--mcp-config` holding the first non-interactive turn for up to `MCP_TIMEOUT` on incidental MCP servers\n- Fixed Stop prompt hooks re-sending their whole prompt on every block in a conversation; repeat blocks now name the condition with a 500-character label\n- Fixed extra empty editor windows opening at startup on Linux under Wayland when running inside the Cursor or VS Code terminal\n- Fixed an unhandled promise rejection in the Claude apps gateway when Postgres drops a connection during a spend check\n- Fixed Claude apps gateway cutting every open stream on SIGTERM: it now lets in-flight requests finish for up to 25 seconds before exiting (`CLAUDE_GATEWAY_DRAIN_TIMEOUT_MS`)\n- Fixed `installed_plugins.json` being rewritten on nearly every start-up when plugin policy comes from remote managed settings, which made Claude Desktop reload every open session's plugins\n- Fixed headless and SDK sessions making a separate model call for every background task that finished; completions already queued are now answered by one call\n- Fixed the Bash tool re-sourcing the shell profile (a multi-second stall on the next command) after every plugin reload; it now does so only when the plugins' `bin/` directories changed\n- Fixed plugins with a top-level `$schema` in `hooks/hooks.json` showing an \"unknown key\" notice\n- Fixed MCP connection errors and the MCP login tool's description showing secrets resolved from `${VAR}` placeholders in MCP configs\n- Fixed Bash permission checks for commands that loop over or assign certain special shell variables; these commands now ask for permission\n- Fixed worktree-isolated sessions accepting Bash commands with certain nested shell expansions; these are now refused\n- Fixed the Edit permission prompt preview sometimes showing a different location than the approved edit in files with multi-byte characters\n- Fixed background commands being stopped after 30 idle minutes on machines under mild memory pressure; they're now stopped only when memory is critically low, and the debug log says why\n- Fixed a message a subagent sends to the main session disappearing from the Claude Desktop transcript after a relaunch\n- Fixed a plugin loaded from a `.zip` being served from a stale extraction after several overlapping reloads\n- Fixed a sub-agent's progress summary being replaced by a runaway multi-paragraph reply\n- Improved startup in `--input-format stream-json` sessions: the first turn no longer waits up to 2s for still-connecting MCP servers whose tools tool search defers; they arrive on a later turn\n- Improved Monitor tool notifications: a script's final output and its exit now arrive as one notification instead of two, saving a model turn\n- Improved Artifact tool errors: when you are not signed in to claude.ai the terminal now says so on the first attempt, and Claude is told to stop retrying a rejected call sooner\n- Improved artifact publishing: a publish built on an older version is stopped before it is sent, with the newer page to merge\n- Improved safety checks before removing an agent worktree that contains submodule checkouts\n- Improved `OTEL_LOG_RAW_API_BODIES=file:<dir>` output: a new `index.jsonl` and `request_body_id` / `message.id` event attributes link each response to its request file and transcript message\n- Improved Claude apps gateway boot: it now tries the first Postgres connection up to three times before exiting, so a database that is reachable a few seconds late no longer fails the boot\n- Improved the Claude apps gateway's spend-limit check under load: it now takes one database round trip instead of four, so fewer checks time out on a busy gateway\n- Improved Claude apps gateway sign-in rate limit errors: `/login` now explains the refusal, and the gateway log says which limit was hit and which setting to change\n- Changed Bedrock, Vertex, Foundry and telemetry-disabled installs to use the v2 MCP client and MCP 2026-07-28 negotiation with direct HTTP servers by default, as other installs already do (opt out: `MCP_SDK_GENERATION=v1` or `MCP_PROTOCOL_NEGOTIATION=legacy`)\n- Changed `/code-review` to use leaner inline review prompts for every model that has no tuned settings of its own, instead of spawning many review subagents\n- Changed `\"type\": \"sdk\"` MCP entries in `.mcp.json`, settings, plugins and agent files to be skipped with a warning: only an SDK host application can register in-process servers\n- Changed artifact watching in local sessions: a new version published elsewhere no longer starts a turn; Claude learns of it from a later Artifact tool result\n- Changed plugin and marketplace clones to leave Git LFS files as pointers instead of downloading them; `git lfs pull` in the checkout fetches them\n- Changed self-hosted runners to skip a read-only repository the git host refuses at the access check instead of failing the session start\n- Changed the `/status` GitHub line to read \"Cloud sessions\", and `/web-setup`, `/ultrareview`, and teleport messages to say \"cloud session\" instead of \"Claude Code on the web\"\n- [VSCode] Added continuation of the step a window reload interrupted, labeled in the chat, with a Claude Code: Continue After Reload setting to turn it off\n- [VSCode] Added Memory and Instructions entries to the Customize menu: Memory shows the auto-memory toggles, the saved memories and the memory folders, and Instructions edits the CLAUDE.md files\n- [VSCode] Added a `claudeCode.lockEditorGroups` setting to stop Claude from locking the editor groups it opens in\n- [VSCode] Fixed a `/btw` side question asked in a new conversation's first seconds occasionally showing another session's side-question history\n- [VSCode] Fixed a brief freeze when the extension first looks up your global gitignore file\n- [VSCode] Fixed a message sent while Claude was running a tool disappearing from the conversation after a window reload\n- [VSCode] Fixed the Manage Plugins enable toggle and MCP servers dialog rows being unreachable from the keyboard\n- [VSCode] Fixed sign-ins and sign-outs made in a terminal not showing until a reload after `CLAUDE_CONFIG_DIR` changed in the Environment Variables setting\n- [VSCode] Fixed Edit diffs in the chat being cut off at the bottom at some panel widths and for long wrapped lines; diff boxes now fit the rows shown\n- [VSCode] Fixed overlapping settings writes from the extension leaving `~/.claude/settings.json` unparseable or dropping a setting\n- [VSCode] Fixed Open in New Tab (Ctrl/Cmd+Shift+Esc) sometimes leaving the new tab's message box unfocused, so typing went nowhere until you clicked it\n- [VSCode] Fixed reopening a closed Claude tab splitting the editor layout when its locked group still holds another Claude tab and a file\n- [VSCode] Fixed New session opening another locked editor group whenever a file tab shared the group with your Claude tab\n- [VSCode] Fixed session names shifting sideways in the session picker while typing a search query\n- [VSCode] Fixed the plan review card cutting off its Send feedback button and reason field when a plan has several comments; the comment list now scrolls\n- [VSCode] Fixed inline code and code blocks in chat replies being unreadable under the High Contrast themes\n- [VSCode] Improved screen reader navigation of the conversation: each message is announced as \"You\" or \"Claude\", with the tool name for tool steps\n- [VSCode] Changed the default global gitignore file to `$XDG_CONFIG_HOME/git/ignore` when `XDG_CONFIG_HOME` is an absolute path\n- [Claude Code on the web] Added a \"Compare against\" branch picker to a cloud session's diff view, so you can diff its changes against any branch instead of only the base branch\n- [Claude Code on the web] Fixed git operations in cloud sessions failing with \"service unavailable\" when GitHub's token renewal briefly errors\n- [Claude Code on the web] Fixed editing a routine occasionally making it fire twice or re-enabling a routine that had just been paused\n- [Claude Code on the web] Fixed commits in cloud sessions occasionally failing with a signing error for a few minutes after the session's credentials refreshed\n- [Claude Code on the web] Fixed the toast after saving a routine whose GitHub trigger couldn't be linked to show the reason, such as a per-repository trigger limit, instead of only \"edit to retry\"\n- [Claude Code on the web] Fixed sessions sometimes flipping back to unread right after you mark them read\n- [Claude Code on the web] Changed routines to skip a run and retry for up to 72 hours when the owner's GitHub connection is missing, instead of switching the routine off at the first failed check\n- [Claude Code on the web] Changed a routine's on-hold notice: when your subscription is paused it now tells you to turn the routine back on yourself instead of promising an automatic resume\n- [Claude Tag] Added a Guests setting to the Add channel and Add workspace forms in Claude Tag admin settings, so owners can pick Inherit, Allow, Channel only or Restrict up front\n- [Claude Tag] Fixed Claude not answering when another Slack app or bot @mentions it; the tag now gets a reply and wakes Claude in a channel it had stopped following after days of inactivity\n- [Claude Tag] Fixed Claude missing another app's message that tagged @Claude right after a new Slack channel was created; it's now delivered once Claude has joined\n- [Claude Tag] Fixed Claude folding a follow-up sent minutes after its last Slack message into it as a silent edit; late updates such as blockers now post as a new reply that notifies\n- [Claude Tag] Fixed Claude's Slack search failing with an error whenever it searched within a single channel; it now returns that channel's matching messages\n- [Claude Tag] Fixed a safety-filter stop silently resetting a Slack thread's context when nobody was waiting; Claude now always says so and no longer cancels background work still running\n- [Claude Tag] Fixed email addresses in Claude's Slack replies rendering with a visible `mailto:` prefix; they now show as the plain, clickable address\n- [Claude Tag] Fixed Claude refusing to watch an Enterprise Grid channel shared with the whole organization when asked from another workspace in the grid\n- [Claude Tag] Fixed the Environment picker in Claude Tag admin settings showing a raw environment ID instead of the environment's name for archived or app-created environments\n- [Claude Tag] Improved Claude's live progress checklist in Slack: capped at 2,000 characters, reposted at most every 15 minutes in busy threads, with older \"Latest task list\" links updated\n- [Claude Tag] Removed the repeated guest-attribution note Claude appended to a Slack canvas each time it edited one in a channel using the \"Channel only\" guest setting\n- [Code Review] Fixed re-reviews occasionally leaving a fixed finding's thread open when the new review also filed a lower-severity note under it\n- [Code Review] Fixed rare reviews ending with \"Code review encountered an error\" when GitHub or an internal service failed transiently at launch; they now wait and retry\n- [Code Review] Improved how Code Review words each posted finding: short plain sentences that say who is affected, where the code goes wrong, and the fix up front\n- [Code Review] Improved the check-run card and PR comment when a review is skipped because of an organization limit: each cause now links the admin page that fixes it","body_html":null,"content_hash":"815d2b2d80ffc4503b231ba4de0d2e1304257793d4c8cb37feac4eddbb3d71dc","updated_at":"2026-10-05T19:08:03.559Z"},{"id":"86d31ec3-3cac-4953-8ed9-a6aa1b682aa1","source_id":"claude-code","dedupe_key":"claude-code:2.1.273","version":"2.1.273","title":"claude code 2.1.273","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21273","published_at":"2026-09-15T18:06:34.098Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added `x-claude-code-request-class`, `x-claude-code-agent-type`, `x-claude-code-prev-tool-durations`, `x-claude-code-compaction` and `x-claude-code-context-compacted` request headers for LLM gateways; opt in with `CLAUDE_CODE_GATEWAY_HINT_HEADERS=1`\n- Added a notification when an MCP server disconnects mid-session and automatic reconnection gives up, pointing at `/mcp`\n- Added forking a session started with `claude --remote-control` or `/remote-control` from the Claude app; the fork runs as a background session on your computer\n- Fixed Bash commands the permission checker cannot fully analyze skipping the prompt under `permissions.blockReadsOutsideWorkingDirectories`, and a subshell hiding a dangerous `rm` in bypass mode\n- Fixed skills synced from claude.ai staying available after your organization turns Skills off; they now move to the recoverable trash\n- Fixed `allowManagedMcpServersOnly`, `deniedMcpServers` and `disableClaudeAiConnectors` set via MDM or `managed-settings.json` being ignored when server-managed settings are also present\n- Fixed 401/403 errors on Bedrock, Vertex and Foundry, and Claude apps gateway 403s, telling you to run `/login`; the message now names the credential to refresh or points to your gateway administrator\n- Fixed `/login`, `/upgrade`, and `/extra-usage` discarding earlier thinking from the conversation, which forced a full prompt-cache rewrite on the next request\n- Fixed auto mode stopping for approval when the Artifact tool uploads a file you attached to the chat in a cloud or Remote Control session\n- Fixed a long-running session recreating a stub `.git/info/exclude` after the repository's `.git` directory was removed or moved away\n- Fixed the main prompt dropping a `!` typed at the start while already in shell mode, so negated commands like `! grep …` can be typed\n- Fixed Read on macOS refusing a dragged-in screenshot, or any file the system reports under a second path, with \"symlink resolution changed after permission was checked\"\n- Fixed `permissions.blockReadsOutsideWorkingDirectories`: a memory directory chosen by a repository's settings is no longer loaded into the prompt, recalled, indexed, or used by memory extraction\n- Fixed sub-agents and background agents being reported as failed, with their result never delivered, when the final streamed reply omitted token usage or carried no model id\n- Fixed the context meter and auto-compact counting advisor-tool turns at roughly twice their real context size, which made auto-compact fire at about half the real window\n- Fixed `/tui` refusing to restart because of an agent-team teammate that had already finished its work and was no longer shown in the agents panel\n- Fixed saved scheduled tasks running in the wrong session after `.claude/scheduled_tasks.json` was copied into another folder, such as a new worktree\n- Fixed SDK and `--output-format stream-json` output dropping a subagent's remaining messages and final report after it is moved to the background mid-run (e.g. by `CLAUDE_AUTO_BACKGROUND_TASKS`)\n- Fixed `/install-github-app` reporting a SAML single sign-on block as \"admin permissions required\"\n- Fixed Remote Control clients attached to a Claude Desktop, VS Code or JetBrains session being refused when they ask for the session's context window usage\n- Fixed the spinner showing a doubled ellipsis (\"……\") on compaction status lines such as \"Running PreCompact hooks…\"\n- Fixed a false-positive spinner tip suggesting the frontend-design plugin after reading or publishing Artifacts\n- Reverted a 2.1.268 change that checked Read and Edit deny rules on Bash lines the permission checker can't analyze (`eval`, `env -C`); commands like `time -p make build` prompt again instead of being denied\n- Improved responsiveness in long sessions: hook progress and sub-agent activity no longer re-process the whole conversation on every update\n- Improved the Artifact tool's error when a publish includes a file type artifacts don't serve: Claude is told which types are served and what to do instead, and the terminal shows one plain line\n- Improved the Artifact tool's page read to state the capabilities and database rules the artifact service holds for the page, for anyone who can publish to it\n- Improved artifact database writes: an update can now remove a single field instead of rewriting the whole document\n- Improved artifact publishing: a publish whose connection drops after reaching claude.ai is now re-sent safely instead of failing or creating a duplicate version\n- Improved the cloud-session GitHub error for an IP allow list, a suspended app installation or SAML single sign-on to show the cause instead of a generic install hint\n- Improved `/autofix-pr`: when `gh pr view` fails it now shows gh's own error (sign-in, SAML, rate limit) instead of a generic exit-code line\n- Improved `/autofix-pr` to say why GitHub webhook delivery couldn't be set up for the PR (for example, no linked GitHub account) instead of a generic warning\n- Improved `/web-setup` errors: a refused GitHub token now lists the likely reasons and the fix, and a connection failure names a configured proxy or TLS certificate problem\n- Improved the in-session SSL certificate and proxy connection errors to name the error code and what to fix, such as `NODE_EXTRA_CA_CERTS` for an untrusted corporate CA\n- Improved the error when a cloud session can't be created because your Claude login expired or was revoked: it now tells you to run `/login`\n- Improved the error shown when an MCP server's sign-in expires mid-session to say how to re-authenticate (`/mcp`)\n- Changed auto mode on Bedrock, Vertex and Foundry to use the local classifier by default for now; set `CLAUDE_CODE_AUTO_MODE_SERVER=1` to use the platform's server-side classifier\n- Changed `OTEL_LOG_TOOL_DETAILS=1` to also include real agent, skill, plugin and MCP server names on cost and token metrics\n- Changed sign-in with a Claude account to also request access to your claude.ai plugins\n- Changed `/bug` and `/feedback` reports to include only model-behavior params (model, system prompt, tools) from the last API request, omitting request metadata and `CLAUDE_CODE_EXTRA_BODY` fields\n- [VSCode] Fixed \"Report a problem\" still appearing, and `/bug` / `/feedback` opening a report form, for organizations that have product feedback disabled\n- [VSCode] Fixed a red \"Claude Code process exited with code 4294967295\" banner appearing after completed turns on Windows\n- Windows: Improved the network-path permission check for UNC paths when a mapped network drive was added with `--add-dir`\n- [Claude Code on the web] Fixed routines losing access to an organization connector, and still calling the old one, after an admin removed and re-added that connector\n- [Claude Code on the web] Fixed creating a self-hosted environment from organization settings occasionally failing with a server error and leaving a half-created environment behind\n- [Claude Code on the web] Changed the admin \"Share cloud sessions\" setting to live under Data and privacy instead of the Claude Code page, where Data and privacy admins can also manage it\n- [Claude Code on the web] Added a \"Discard unsaved changes?\" confirmation before the New routine page or the Edit routine dialog throws away a routine name, prompt or edit you typed\n- [Claude Code on the web] Removed the full-page desktop-app download screen that new users without a cloud environment saw on Mac and Windows; they now go straight to setup\n- [Claude Code on the web] Improved the routine detail page: menu and rename in the breadcrumb, the on/off switch and Run now at the top, and run history beside the routine's settings\n- [Claude Tag] Fixed Claude going silent minutes after reinstalling the app when an Enterprise Grid was disconnected but one of its workspaces stayed connected\n- [Claude Tag] Fixed scheduled tasks set up in an organization-shared private Slack channel silently never posting; they now keep running in the thread they were created in\n- [Claude Tag] Fixed replying in an older Slack thread while Claude is mid-task sometimes restarting it from scratch and losing work it had not pushed yet\n- [Claude Tag] Fixed Claude occasionally dropping a message with an incorrect \"couldn't find a Claude Code environment\" notice right after your account token refreshed\n- [Claude Tag] Fixed AWS connections refusing region-less endpoints such as Budgets, Savings Plans, WAF Classic and Import/Export; Global Accelerator requests now sign correctly\n- [Claude Tag] Improved AWS connection failures: when a request can't be signed, such as a hostname with no region, Claude is told why and how to fix it instead of a bare error\n- [Claude Tag] Fixed OAuth client-credentials and JWT-bearer connections failing with providers that return a lowercase token type; requests now send the standard Bearer scheme\n- [Claude Tag] Fixed adding a channel manager being refused on Enterprise Grid shared channels, on channels where Claude hasn't been used yet, and on legacy private channels\n- [Claude Tag] Changed Claude to start watching related public channels on its own, such as an incident channel a conversation depends on, instead of only when asked\n- [Claude Tag] Fixed the admin Memory page not listing Slack channels Claude set up on its own even when they had saved memory; admins can now open, edit and delete that memory\n- [Code Review] Fixed merging the base branch into a PR whose earlier review listed \"Additional findings\" triggering a full re-review; these pushes now get the lighter follow-up review\n- [Code Review] Fixed a whole REVIEW.md being ignored because of an @-mention, a code span wrapped across lines, or a backticked HTML tag; only lines linking to changed files are withheld\n- [Code Review] Improved suggested fixes to say what the fix must keep working when other code depends on the behavior being changed\n- [Code Review] Improved review comments that point to a second affected location to state that location's issue in a full sentence instead of a cut-off stub\n- [Code Review] Fixed `/ultrareview --post` so a retry after a GitHub error posts the findings comment exactly once instead of never or twice; the comment now names the reviewed commit\n- [Code Review] Fixed empty or content-identical pushes being re-reviewed on GitHub repositories whose owner or name contains a capital letter; these pushes are now skipped","body_html":null,"content_hash":"c94493a47d2059350d44ecd038c88f851cae3339af88394a60267379a05b473a","updated_at":"2026-10-05T19:08:03.559Z"},{"id":"4fe7373a-884c-4c6b-91f5-a865afe25fac","source_id":"claude-code","dedupe_key":"claude-code:2.1.272","version":"2.1.272","title":"claude code 2.1.272","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21272","published_at":"2026-09-14T23:34:13.565Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Bug fixes and reliability improvements","body_html":null,"content_hash":"be169a8b64a631155244b2255979fd3e6ec17125b8649159fc6fe2b8ab281d0b","updated_at":"2026-10-05T19:08:19.669Z"},{"id":"c7698ea3-06ef-4d7c-81c4-8ded7c1d25ed","source_id":"claude-code","dedupe_key":"claude-code:2.1.271","version":"2.1.271","title":"claude code 2.1.271","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21271","published_at":"2026-09-14T19:45:19.456Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added fast mode in Claude Code Remote sessions (cloud and self-hosted runners): the host's fast-mode setting or `/fast` typed in the session applies where your organization allows it\n- Added mouse support to the `/config` panel in fullscreen mode: the wheel scrolls the settings list, a click on a setting's value changes it, and the row under the pointer is highlighted\n- Added `claude self-hosted-runner --drain-marker-file <path>`: when that file exists at a SIGTERM drain, the runner reports its exit to the server as a host drain (telemetry only)\n- Added per-command `allowed_domains` to Bash, PowerShell and Monitor in auto mode with sandboxing: the hosts a command needs are reviewed with it and opened for it alone; other hosts are refused\n- Added `omitClaudeMd` to agent frontmatter and `--agents` JSON, letting custom and plugin subagents run without user, project and local CLAUDE.md files; managed policy files still load\n- Added `--accept-command <sha256>` to `claude plugin install` and `claude plugin update` to accept exactly the command a previous `--json` run displayed, instead of `-y`\n- Added support for a `multiplier` above 1, up to 10, in the `modelPricing` managed setting and the Claude apps gateway `pricing` block, for marked-up internal chargeback rates\n- Added a spinner tip pointing Bedrock, Vertex AI, Foundry and LLM gateway users to the Claude desktop app; the claude.ai desktop app tip now suggests `/desktop`, which offers to download the app\n- Fixed a cached organization policy being reused after switching accounts, organizations, or API keys, and the policy not refreshing until the hourly check when the credential changes mid-session\n- Fixed the tool and command lists not updating when the organization policy finishes loading after startup or changes mid-session\n- Fixed an enterprise `managed-mcp.json` that can't be read or parsed being ignored: it now keeps exclusive MCP control (user, project and plugin servers don't load) and warns at startup\n- Fixed org policy being fetched through, and rejected by, third-party local proxies set via `ANTHROPIC_UNIX_SOCKET`; they are again treated like other custom gateways, including for Remote Control\n- Fixed cloud sessions rejecting every subagent tool call (\"updatedInput … failed schema validation\") when a workflow or agent approval was applied after the session's worker restarted\n- Fixed `/fast off` answering \"Fast mode unavailable\" instead of turning fast mode off when the organization has fast mode disabled\n- Fixed sessions started with `CLAUDE_CODE_SKIP_FAST_MODE_ORG_CHECK` re-sending fast requests every turn after the API rejected fast mode; the rejection now stands and its reason is shown\n- Fixed fast mode under `CLAUDE_CODE_RETRY_WATCHDOG` failing the turn on a usage-credits limit, or retrying an overload at fast speed, instead of falling back to standard speed\n- Fixed Bash permission checks missing the file that `fmt`, `column` and similar commands read when it follows an option the checker doesn't recognize\n- Fixed Bash permission checks skipping files a wildcard expands to when the wildcard sits in a command's pattern or option value (for example `grep -v dir/* file`)\n- Fixed Bash permission checks so that shell variable declaration flags cannot misrepresent the command being run\n- Fixed Bash commands with two directory changes, a subshell, or a `cd`+`git` chain skipping the prompt under `permissions.blockReadsOutsideWorkingDirectories` in bypass and auto mode\n- Fixed a stale `.git/config.lock` breaking `git checkout -b`, `git push -u` and `git config` for the rest of a session after a sandboxed command failed to start (Linux)\n- Fixed settings file changes made outside the session going unnoticed on macOS machines whose system file-event service is saturated; the watcher now falls back to polling\n- Fixed resumed `claude -p` sessions whose tools all come from MCP servers failing with \"At least one tool must have defer_loading=false\"\n- Fixed turns failing with \"API returned an empty or malformed response\" when an LLM gateway returns the non-streaming reply as `text/plain`\n- Fixed sustained high CPU usage and repeated tool-list requests when an MCP server sends `list_changed` notifications in a tight loop\n- Fixed MCP OAuth mishandling client registrations: denying consent forced a new one, one for another redirect URI was reused, and a concurrent write could delete a valid one or keep a mismatched one\n- Fixed tool search returning no match when Claude selects an MCP tool by its bare name instead of its full `mcp__server__tool` name\n- Fixed Ctrl+O cancelling pending MCP server reconnects, and `/mcp` sent from Remote Control failing while the transcript view is open\n- Fixed the Claude in Chrome prompt telling the model to load tools through ToolSearch when ToolSearch is unavailable\n- Fixed cross-session messages held by the receiving session's permission-mode policy leaving no trace: headless senders now get a delivery notice, and `SendMessage` results no longer imply it was read\n- Fixed Claude starting a second copy of a background command (such as a watch task or dev server) that was still running after the conversation was compacted\n- Fixed `/model` warning about losing the conversation cache when switching back to the model the conversation actually ran on\n- Fixed `/reload-skills` reporting a skill count that disagreed with the slash menu after `/cd`\n- Fixed `/resume` and `/continue` showing only 1-2 sessions in fullscreen mode on short terminals\n- Fixed `/resume` and `/teleport` keeping the previous conversation's file-read tracking, so Claude could edit files the resumed conversation had never read\n- Fixed `--resume` dropping the 1M context window (`[1m]`) when the resumed session's model family differs from the configured default model\n- Fixed artifacts attached with `/artifacts` disappearing from the session after `--resume`\n- Fixed background sessions (`claude --bg`, `claude agents`) not watching the artifacts they publish for republishes made elsewhere\n- Fixed custom agents, slash commands and output styles beyond the first not loading from a virtual drive that reports inode 0, such as an encrypted vault mounted as a Windows drive\n- Fixed self-hosted runner sessions silently losing all host config (settings, skills, plugins, MCP servers) when the host config directory exceeds 64 MiB; added `--host-config-snapshot disk|memory`\n- Fixed skills synced from claude.ai staying on disk indefinitely after signing out; copies not refreshed within `cleanupPeriodDays` now move to the recoverable trash at the next launch\n- Fixed spinner tips suggesting commands that aren't available for your account type or are disabled in your session\n- Fixed the `/add-dir` path input: the left and right arrow keys now move the cursor, and Enter adds only the typed path instead of also adding the highlighted completion\n- Fixed text fields outside the main prompt moving a leading `!` to the end of what you typed (`!foo` came out as `foo!`)\n- Fixed the interactive `/hooks` menu crashing when a hook matcher is named after an inherited object property such as `__proto__` or `constructor`\n- Fixed a fullscreen rendering glitch where text kept a stale background color after the box around it lost its background\n- Fixed Delete in st and Alt+arrow keys in rxvt-unicode not working in attached background sessions\n- Fixed the terminal's replies to capability queries (`^[[?1;2c`) appearing at the shell prompt or in an editor when Claude Code exits, is suspended, or opens an editor right after starting\n- Improved terminal rendering performance: large diffs and long transcripts render faster, with fewer slow frames\n- Improved startup time slightly by skipping a redundant validation of built-in model data on every launch\n- Improved hook feedback: while a SessionStart, UserPromptSubmit, PreToolUse or SessionEnd hook runs, the spinner says so with elapsed time, and Esc cancels a prompt waiting on a SessionStart hook\n- Improved the spinner status during long thinking: it now reads \"deep in thought\" after 45s, and shows \"picking the thought back up\" while recovering from the output-token limit\n- Improved dynamic workflows to pause when you hit your usage limit and continue automatically when it resets, instead of dropping the affected agents\n- Improved Remote Control to leave fewer empty sessions on claude.ai when setup fails on a flaky network\n- Improved the Claude in Chrome message in cloud sessions when the browser can't be reached: it now says the computer may be asleep before it suggests an install\n- Improved `claude mcp serve`: a running tool call now sends a progress update every 30 seconds, so clients show it is still running and idle timeouts don't abort a long command that prints nothing\n- Improved Foundry and Claude Platform on AWS sessions: an `alwaysLoad` MCP server that finishes connecting mid-conversation is usable on the next turn without a tool-search round trip\n- Improved Markdown files published as artifacts: they now render as styled document pages (title header, document typography, syntax-highlighted code)\n- Improved Artifact tool publish errors: a publish with no file now says to write the page to a file first, and an unsupported file type is reported before a missing favicon\n- Improved the Artifact tool's error when a page declares a capability its contract version lacks: it now lists every supported capability and notes when a newer contract version has it\n- Improved artifact watching: a session can now watch up to 10 published artifacts at once for republishes made elsewhere, up from 5\n- Improved PDF @-mentions to say \"page count unknown\" instead of a page count guessed from the file size when pdfinfo cannot count the pages\n- Improved `/mobile` to show a single QR code for claude.ai/mobile, which opens the right app store for your phone\n- Changed auto mode so that a skill's or slash command's inline `!` shell commands follow default-mode permission rules instead of the classifier; a command no rule decides runs as a reviewed tool call\n- Changed auto mode so a subagent reports back to its caller through a dedicated hand-back call that the safety classifier reviews, instead of its last message being reviewed after the fact\n- Changed Monitor watches to always have a deadline (at most 30 minutes; 10 in single-prompt `-p` runs) and notify Claude to re-arm, replacing the no-timeout `persistent` option\n- Changed the IDE selection indicator in the prompt to a `[⧉ …]` pill that wraps with the text instead of squeezing multi-line prompts; delete it with Backspace to leave the selection out\n- Changed the default dynamic workflow size to small on Pro plans and lowered the medium size guideline from 15 to 10 agents\n- Changed Claude apps gateway, Bedrock, Vertex AI, and Foundry sessions so that they no longer refresh a leftover claude.ai login that the session does not use\n- Updated the bundled `claude-api` skill to enable `eager_input_streaming` on streaming custom tools, and to start deliverable-shaped Managed Agents work with `user.define_outcome`\n- [VSCode] Added an Attach Open File setting that, when turned off, stops the open file from being added to messages; selected text is still attached\n- [VSCode] Fixed the Hooks and Permission rules dialogs reporting a save that landed as failed, and the Hooks dialog going blank under a plugin-only policy lock or showing color codes in save errors\n- [VSCode] Fixed Hooks dialog saves: no duplicate hook on replace, a header name retyped in other capitals keeps its secret, and settings.local.json is gitignored before the save returns\n- [VSCode] Fixed session history showing only the current session when the workspace is on a Windows mapped network drive or SUBST drive\n- [VSCode] Fixed the session list's Active filter hiding open idle sessions when Open is also checked in the filter menu\n- [VSCode] Fixed a new chat switching back to the previous chat when the session list refreshed\n- [VSCode] Fixed open tabs and the side bar keeping the old config folder until a window reload after `CLAUDE_CONFIG_DIR` changed in the `environmentVariables` setting\n- [VSCode] Fixed console windows flashing on Windows when the extension runs background commands such as git, ripgrep, and the sign-in status check\n- [VSCode] Fixed the prompt cache clock's hover text appearing only after a delay, and the auto-compact icon showing the browser's own tooltip beside its popup\n- [VSCode] Improved the Hooks dialog: a save refused because of the settings file itself now opens a popup with an \"Open settings file\" button and the reason behind \"Copy error\"\n- [VSCode] Changed the on state of toggle switches from Claude orange to the editor theme's button color\n- [Claude Code on the web] Fixed a cloud session sometimes taking about ten minutes to respond after its process exited while the session still looked live; sending a message now restarts it right away\n- [Claude Code on the web] Changed the Routines page on claude.ai/code to a new layout with Yours and Templates tabs and two-column routine cards that show run status, and removed its calendar view\n- [Claude Code on the web] Added a Custom network access option to the Cloud environments editor in admin settings, with the same allowed-domains list the environment dialog on claude.ai/code offers\n- [Claude Code on the web] Improved the Cloud environments admin page: it shows the default environment for Claude Tag and Claude Code, with a link to change it, and marks the recommended kind to create\n- [Claude Tag] Fixed Claude in a channel where it stays active losing its working context about once an hour when the conversation is mostly in threads; thread activity now keeps it from being reset\n- [Claude Tag] Fixed a thread that asked Claude to watch a pull request no longer hearing about CI failures, comments and reviews after Claude was restarted in that thread\n- [Claude Tag] Fixed deleting the first message of a thread Claude had already replied in not ending Claude's work there; it now stops, as it did when a message with no replies was deleted\n- [Claude Tag] Fixed Claude holding back a post because of an earlier instruction addressed to a different bot or assistant; only instructions addressed to Claude bind it, and it asks when unsure\n- [Claude Tag] Fixed the reply-mode card Claude posts on joining a busy channel saying it \"sees a lot of automated posts\" when the channel is only chatty or large; the card now names the real reason\n- [Claude Tag] Improved the Environment picker in Claude Tag admin settings: options are labeled Anthropic-hosted or self-hosted, with links to edit that environment or create one\n- [Code Review] Fixed a pull request in a repository reviewed once per PR sometimes getting no review when a commit arrived while its review was waiting to start; it now reviews the requested commit\n- [Code Review] Fixed Code Review occasionally posting the same findings two or three times when GitHub reported an error for a review it had in fact created\n- [Code Review] Fixed follow-up reviews re-posting a security finding a person had already resolved when a later push moved the lines it was anchored to\n- [Code Review] Fixed reopening a finished /ultrareview cloud session in the Claude app starting the whole review over again unprompted\n- Windows: Fixed PowerShell commands failing with \"Exit code 1\" and no output when the session's temp output path reaches 260 characters","body_html":null,"content_hash":"f8f9b584a872ebdf1aee41efead0cf0b6307c80dedadc354799f8e64a1e8fdd0","updated_at":"2026-10-05T19:08:19.669Z"},{"id":"9acf3a18-f3d0-4a4a-a3fd-c5889cf5c238","source_id":"claude-code","dedupe_key":"claude-code:2.1.270","version":"2.1.270","title":"claude code 2.1.270","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21270","published_at":"2026-09-12T18:52:44.937Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Fixed read-only git commands in Bash unexpectedly asking for permission after a session had been running for a while (regression in 2.1.269)","body_html":null,"content_hash":"edff6d84472a4986383ab66482f5e7ce81bb8c886dcdde3c277fd1c95d076a62","updated_at":"2026-10-05T19:08:19.669Z"},{"id":"7f1494ad-9c28-4ba3-904d-983ec354c61d","source_id":"claude-code","dedupe_key":"claude-code:2.1.269","version":"2.1.269","title":"claude code 2.1.269","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21269","published_at":"2026-09-11T18:12:49.253Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added `claude plugin eval`: run a plugin's eval suite against Claude Code and get scored, reproducible results (JSON + HTML report); see `claude plugin eval --help`\n- Added `/output-style [name]` to list and switch output styles, including over Remote Control and in cloud and other headless sessions\n- Added a diff of the files a Bash command changed to the Bash tool result when the Bash tool handles file edits (setting `bashEditDiffEnabled`)\n- Added `OTEL_METRICS_INCLUDE_REPOSITORY` to tag OpenTelemetry metrics and events with `vcs.*` repository attributes; commit events get `vcs.ref.head.*` with `OTEL_LOG_TOOL_DETAILS`\n- Added `CLAUDE_CODE_GATEWAY_MODEL_DISCOVERY_TIMEOUT_MS` to extend the LLM gateway `/v1/models` discovery timeout (default 3s)\n- Added a spinner tip suggesting `/focus` for a view with just your prompt, a one-line work summary, and the response\n- Added `CLAUDE_CODE_WORKFLOW_MAX_CONCURRENT_AGENTS` (1–256) to raise the Workflow tool's per-run concurrent agent limit for inference-bound fan-outs\n- Fixed the prompt cache being partially invalidated on the turn after a response was cut off at the output-token limit and automatically resumed\n- Fixed a case where resuming a session after interrupting Claude mid-thought could change how earlier context was re-sent, hurting prompt-cache reuse\n- Fixed F1/F2/F4 not working in kitty-protocol terminals and Delete in st, Alt+arrows acting as Escape in rxvt-unicode, and Shift+punctuation typing the unshifted key in WezTerm (regression in 2.1.247)\n- Fixed remote and headless sessions reporting \"waiting for your input\" while background agents were still running (set `CLAUDE_CODE_BG_TASKS_REPORT_RUNNING=0` to restore the old behavior)\n- Fixed the terminal's replies to capability queries (`^[[?1;2c`) appearing as stray text at startup in some terminals\n- Fixed rows at the top or bottom of the transcript going blank in fullscreen after resizing the terminal\n- Fixed a deny or ask permission rule starting with `!` applying beyond the settings source that wrote it; such a rule now applies only within its own source, and a bare `!` negation is ignored\n- Fixed the git status Claude is told after a compaction: it is now the current status, not the one from the start of the session\n- Fixed synced plugin MCP servers not connecting when a remote session resumes\n- Fixed resumed headless sessions losing a turn's replies when the model was switched or a request was retried mid-turn\n- Fixed terminal escape codes, line breaks and oversized text from a background task's on-disk record reaching the task list and task notifications when work is resumed\n- Fixed CMYK JPEG images failing to attach with \"cannot decode\"; they are now converted and resized like other JPEGs\n- Fixed the managed settings approval dialog not naming the collector for a gRPC telemetry endpoint set without a scheme\n- Fixed plugin `headersHelper` consent prompts showing a URL path that could be misread as a different host\n- Fixed plugin errors showing `[redacted URL]` in place of a relative Windows path with a folder name that starts with `@`\n- Fixed missing cursor in the permission-rule, auto-mode-rule, add-directory, session-rename and feedback-review text fields when the terminal's native cursor is enabled\n- Fixed repeated clicks on a `/fork` receipt, each under a second apart, never backgrounding the session right away while it waited for the current tool to finish\n- Fixed plugin LSP servers that reject `shutdown` params (e.g. rust-analyzer) being left running at session end; `exit` is now sent even if `shutdown` fails\n- Fixed the attribution reminder overriding a CLAUDE.md or memory rule against commit and pull request attribution; lines set by managed settings still apply\n- Fixed prompt suggestions being dropped for text in Japanese, Chinese, Thai and other languages written without spaces between words\n- Fixed synchronized output being assumed from the terminal's name in GNOME Terminal and Konsole versions that do not support it\n- Fixed `permission_denials` in `--output-format stream-json` results omitting Read, Edit and Write calls blocked by a path-scoped deny rule\n- Fixed sessions run through the SDK or the desktop app showing an unknown status in other sessions' agent list\n- Fixed `/insights` failing on Bedrock, Vertex, Foundry, and gateway deployments whose account can't reach the default Opus model by using the session model there instead\n- Fixed organization policy limits not loading for the session when another Claude Code process refreshed the login at the same moment\n- Fixed Claude Desktop sessions using Bedrock, Vertex, or a gateway not getting the contextual \"what Claude needs\" turn-end notification text\n- Fixed MCP servers reconnecting when an updated config only changed the order of the server URL's query parameters\n- Fixed the prompt box's top border splitting into extra lines when viewing a background agent whose name or description has line breaks or is wider than the terminal\n- Fixed sessions getting permanently stuck on \"Prompt is too long\" when auto-compaction had no complete earlier exchange to summarize (mostly Agent SDK sessions with very large prompts)\n- Fixed `/goal` runs silently stalling after API errors, network drops, or token limits: the goal now retries with backoff, or pauses and says why, including until a usage limit resets\n- Fixed prompt cache misses in cloud sessions by waiting briefly for server configuration before the first request\n- Fixed `/btw` answers that contained made-up tool calls and output: the side question is now told not to write them, and any that appear are flagged as not executed\n- Fixed `CLAUDE_CODE_RESUME_INTERRUPTED_TURN` re-running a turn that had failed with an API error over 6 hours earlier, or longer ago than `CLAUDE_CODE_RESUME_INTERRUPTED_TURN_MAX_AGE_MS` when set\n- Fixed organization plugins enabled through managed settings not loading in headless sessions and on Claude Desktop (once Desktop bundles this CLI version); they load from the next session\n- Fixed plugin archives extracted for a session being readable by other local users, extracted files keeping world-writable bits from the archive, and stale files surviving re-extraction\n- Fixed `Edit()` deny rules and the write-path check not applying to the file a Bash `tee` command writes; a `Bash(tee:*)` allow rule no longer covers destinations outside the working directories\n- Fixed stray characters like `22c`, or a terminal's color or version reply, being typed into the prompt at startup over slow connections (ssh, browser terminals)\n- Fixed the terminal's block cursor showing under the interface in rxvt-unicode after leaving or re-entering fullscreen\n- Fixed the cursor block staying visible after returning from an external editor in fullscreen mode on rxvt-unicode\n- Fixed the interface being drawn twice after returning from an external editor (Ctrl+G) outside fullscreen mode\n- Fixed the interface being drawn twice in Konsole after returning from an external editor\n- Windows: Fixed PowerShell tool commands sent to the background stopping when Claude Code exits\n- Improved the `/diff` panel to open fully rendered in one step instead of showing a loading state first\n- Improved prompt suggestion filtering for Japanese, Chinese and Korean text: mixed-script and single-word suggestions are kept, and meta or evaluative text is dropped as it is for English\n- Improved the Skill tool's \"Unknown skill\" error to name the plugin skill's full name when a bare name matches exactly one plugin skill\n- Improved keyboard support over SSH and in unrecognized terminals: terminals that answer the kitty keyboard query (such as foot and Alacritty 0.16+) now get Shift+Enter and Ctrl+Shift shortcuts\n- Improved responsiveness in long sessions: transcript updates no longer re-process the whole conversation to build the collapsed tool-use summaries\n- Improved first-party sessions with telemetry disabled: an `alwaysLoad` MCP server that finishes connecting mid-conversation is usable on the next turn without a tool-search round trip\n- Changed `/ultrareview --post` to post the PR comment directly when the findings arrive and print the comment link, instead of starting a second cloud session to post it\n- Changed artifact database reads that save into the session scratchpad so they no longer stop for working-folder approval\n- Changed skills synced from claude.ai in cloud sessions to be named `anthropic-skills:<name>`, matching Claude Desktop; the bare name still works when nothing else uses it\n- [VSCode] Added an agent map: an \"N agents\" footer pill opens a map of the session's sub-agents with per-agent cards, Stop agent, and read-only transcripts\n- [VSCode] Added a Hooks dialog to the command menu for viewing hooks and adding, editing, or removing them in user, project, and local settings; managed, plugin, and session hooks stay read-only\n- [VSCode] Added live progress rows for running subagents under the tool-call groups in Focus view\n- [VSCode] Added a Permission rules dialog that lists permission rules and adds or removes them in user, project, and local settings; startup-option, session-only, and managed rules stay read-only\n- [VSCode] Added a Cancel button to the Switch account screen that returns to your session as the current account\n- [VSCode] Fixed Focus view showing a turn started by a delivered plain-text prompt, such as a scheduled task's, as part of the previous turn\n- [VSCode] Fixed the footer's prompt cache clock hiding its minutes when the panel is narrow\n- [VSCode] Fixed the session list keeping sessions from the default folder when `CLAUDE_CONFIG_DIR` is set in a settings file or the `environmentVariables` setting\n- [VSCode] Fixed a plan preview that finished loading late sometimes hiding its comment box or showing an older plan\n- [VSCode] Fixed a plan preview accepting comments that went nowhere after its Claude tab closed\n- [VSCode] Fixed the prompt cache clock and reopen notice for a session compacted after its last reply and then closed, which now reads as cold when reopened\n- [VSCode] Fixed a session renamed in the extension while Remote Control is on keeping its old name on claude.ai/code\n- [VSCode] Fixed the \"Enable Remote Control for all sessions\" toggle keeping its last position after the setting was reset to default from a terminal\n- [VSCode] Fixed restored Claude tabs not counting as open in the session list after a window reload until clicked, and their row opening a second tab\n- [VSCode] Fixed Switch account making a tab forget its dismissed usage-limit warnings when you sign back in as the same account\n- [VSCode] Fixed a session rename being replaced by the generated name after a window reload when the session was renamed during a long turn\n- [VSCode] Fixed the sidebar usage meter keeping a stale per-model weekly limit row after the account loses that limit\n- [VSCode] Fixed a rare case where an @-mention sent with the keyboard shortcut while a new chat view was still starting could be inserted into the input long after the keystroke\n- [VSCode] Fixed the session list jumping down when the Account & usage header appeared a moment after opening the Claude side bar\n- [VSCode] Improved documents and messages written for someone other than the user: Claude now writes them for that audience and names it at the top of its reply\n- [VSCode] Improved screen reader and keyboard accessibility in the slash-command menu, @-mention menu, output-style picker, Send/Stop button, permission and question cards, and onboarding checklist\n- [VSCode] Changed the current-file chip in the message box: an X now removes it, replacing the Hide toggle\n- [VSCode] Removed the Claude Code items from a session tab's right-click menu and the editor title bar's \"...\" menu; they could not act on the tab the menu was opened on\n- [Claude Code on the web] Added taking back a queued message in a cloud session before Claude reads it: remove it from the queue, or press Esc or Up, and the text returns to the message box\n- [Claude Code on the web] Fixed `/model default` in a cloud session leaving every later message failing in organizations that restrict which models Claude Code can use\n- [Claude Code on the web] Fixed one-off scheduled routines occasionally running a second time after a transient server error\n- [Claude Code on the web] Fixed routine runs that use subagents sometimes being treated as finished too early, which could skip the retry after a real failure or start a duplicate run\n- [Claude Code on the web] Fixed file links in cloud session transcripts opening a GitHub 404 when Claude was working from a subfolder of the repository\n- [Claude Code on the web] Changed the Cloud environments admin page to list every environment instead of capping each table at five rows behind a Show more control that could be unreachable\n- [Claude Code on the web] Changed claude.ai/code for Free-plan users to open the plans page with a path to upgrade, instead of a \"Disabled by org admin\" page with no way forward\n- [Claude Tag] Added a confirmation dialog before Connect all or Disconnect on a GitHub installation in admin settings, to guard against accidental organization-wide changes\n- [Claude Tag] Fixed threads occasionally going silent after a failed turn because the failure notice was dropped when Slack briefly rate-limited it; the notice is now retried\n- [Claude Tag] Fixed Claude accepting a switch to a model your organization hasn't enabled and then quietly answering with a fallback model; it now declines and says an admin can enable it\n- [Claude Tag] Fixed a table posting as raw pipe text when Claude attached files to the same message; the table now posts as a normal reply and the files follow with a plain caption\n- [Claude Tag] Fixed `@Claude !restart` at the top level of a channel where Claude isn't active starting an unrelated conversation; it now privately says there is nothing to restart\n- [Claude Tag] Fixed plugin rows in Slack access settings showing an unlabeled raw ID with no way to turn the plugin off; they now show its name and link to the bundle that manages it\n- [Claude Tag] Fixed the shared-session banner and Share dialog on sessions started from Slack claiming the whole organization could open the link; they now name the Slack channel's audience\n- [Claude Tag] Improved load time of the admin settings page and its Slack channel picker, most noticeably for organizations with many channels or several connected workspaces\n- [Claude Tag] Improved scheduled routines in Slack channels: a routine run can now reply in an existing thread instead of always posting a new top-level channel message\n- [Claude Tag] Improved the timestamp on Claude's live progress checklists to show each reader's local time and how long ago it was updated, instead of a fixed UTC time","body_html":null,"content_hash":"61d4fcfa099a89e08ac0b67ea0728b03248164a1fb2818ccd9bc482c48fb9646","updated_at":"2026-10-05T19:08:19.669Z"},{"id":"e49b3967-fab1-480f-8477-8474796fd4ce","source_id":"claude-code","dedupe_key":"claude-code:2.1.268","version":"2.1.268","title":"claude code 2.1.268","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21268","published_at":"2026-09-10T18:41:11.770Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added to the Claude apps gateway: with `pricing:` set in `gateway.yaml`, signed-in Claude Code clients receive the same rates through managed settings, so `/cost` and telemetry match the spend meter\n- Added a startup warning for gateways when `access_control.allow_cidrs` is empty, and a one-time warning the first time a request arrives from a public address\n- Added the `gatewayInternalNetworks` managed setting, letting administrators allow `/login` to a Claude apps gateway on their organization's own public IPv4 block\n- Added `claude self-hosted-runner --remove-session-state` (default off): delete each session's per-session directories under `<base-dir>/_sessions/` when the session ends\n- Added `configDirectory` to the output of `claude auth status --json`\n- Added `--json` to `claude plugin install`, `uninstall`, `update`, `enable` and `disable`, and `errorDetails`/`noteDetails` to each row of `claude plugin list --json`\n- Added browser-tab icons for published artifacts, chosen by Claude to match each page\n- Fixed every turn failing with HTTP 400 on third-party Anthropic-compatible endpoints (`ANTHROPIC_BASE_URL`) since 2.1.265: a regex in the Artifact tool's input schema that those endpoints reject\n- Fixed WebFetch hanging indefinitely on a server that keeps the response open without finishing; a fetch now fails after 300 seconds. Set `CLAUDE_CODE_WEBFETCH_DEADLINE_MS` to override the deadline (0 turns it off)\n- Fixed a respawned in-process teammate picking up tools or a system prompt from a same-named agent file in a folder you have not trusted\n- Fixed sustained high CPU usage: a busy loop in long-running idle sessions no longer pins a CPU core, and rapid terminal focus reports during a session recap no longer keep the CPU high\n- Fixed Claude sometimes replying \"your message came through empty\" after an MCP tool call\n- Fixed deny and ask permission rules on symlinked directories (`/etc`, `/tmp`, `/var` on macOS; `/bin` on Linux) not applying when a path was given by its real location, and Bash commands ignoring deny rules written on a symlinked path spelling\n- Fixed a case where a Read or Edit deny rule did not apply when an `env -C`, `eval` or similar command the permission checker cannot analyze was on the same line\n- Fixed plugin and marketplace errors showing a token or password from a git source URL\n- Fixed `/mcp` and `/plugin` server details, `claude mcp list`/`get`, and MCP login errors showing secrets resolved from `${VAR}` placeholders in MCP configs\n- Fixed prompt caching and extended thinking breaking mid-session for SDK sessions using `excludeDynamicSections`: the first message is no longer re-rendered each request\n- Fixed entitled users being told a model is restricted after restart or in the Desktop Code tab when a cached model-access denial was stale\n- Fixed a running session silently switching to the organization's default model when another Claude Code process refreshed a stale model-access entry\n- Fixed long-context 429s on Fable models showing the usage-credits consent prompt instead of the 1M-context message on Pro and Team plans\n- Fixed workload identity federation via a profile (as claude-code-action configures it): processes sharing the profile could fail mid-run with `401 … jti reused`\n- Fixed MCP server OAuth sign-in failing with \"No available ports for OAuth redirect\" when the local callback port range can't be bound\n- Fixed the conversation summary produced by `/compact` and auto-compact mangling text that contained `$` sequences\n- Fixed resuming a conversation that ended with `/compact`: its restored-file notes now load in the same order on every resume\n- Fixed SDK prompt suggestions, side questions and `/rename` sending the conversation from before a compaction\n- Fixed `@` file and `/` command suggestions not appearing after recalling a previous prompt with the up arrow and editing it\n- Fixed `claude agents`: pressing ← again at a natural pace to go back to the agent list no longer gets ignored until you pause for over a second\n- Fixed `claude agents` session delete getting stuck when a worktree can't be removed: the message names the cause and next step, and for a git worktree ctrl+x again deletes the directory anyway\n- Fixed background agent and workflow rows in the agents panel expanding to many lines when their text contained line breaks\n- Fixed Claude in Slack sessions losing their Slack tools when org managed settings set an MCP allowlist\n- Fixed Claude in Chrome asking to allow the host \"https\" when a navigation URL had a scheme but a host that could not be parsed\n- Fixed the spinner wrapping onto several lines when the current task's label is long; the label and the \"Next:\" task line now stay within one terminal row\n- Fixed the `/bug` and `/feedback` description field showing no cursor when the terminal's native cursor is enabled\n- Fixed Remote Control sessions served by `claude remote-control` showing a generated name instead of their session title in `ListAgents`\n- Fixed `claude plugin validate` rejecting plugin paths whose directory name begins with two dots, which the plugin loader accepts\n- Fixed plugins silently skipping a default monitors file or root SKILL.md that could not be checked\n- Fixed WebFetch's error for localhost and other dotless hostnames to explain why the URL is refused and suggest curl\n- Fixed PermissionRequest hooks not firing in `--print` mode\n- Fixed policy-helper warnings not printing on headless (`-p`) runs\n- Fixed `/resume` listing a `/fork` background session under its parent's name instead of its own `⑂` fork name\n- Fixed `/remote-control` and other claude.ai-gated commands to suggest `/login` when signed out instead of showing a Claude for Enterprise migration message\n- Fixed `CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS` not extending SessionEnd hooks that have no per-hook `timeout` (they were still cancelled after 1.5 seconds)\n- Fixed `/autofix-pr` and other cloud-session commands saying to retry or install the Claude GitHub App when no GitHub account is connected; they now point to `/web-setup` or the web connect page\n- Fixed cloud-session commands such as `/teleport` and `/remote-env` to explain when an organization policy turns them off, instead of answering \"Unknown command\"\n- Fixed Bash sandbox instructions over-stating confinement: no unenforced path lists when filesystem isolation is off, and strict mode no longer claims commands can never run unsandboxed\n- Improved fullscreen mode: adding or removing a prompt line (Shift+Enter) now repaints as fast as typing a character instead of re-rendering the visible transcript\n- Improved `--continue` / `--resume`: the conversation appears immediately instead of waiting for SessionStart hooks, and the first message no longer re-reads the whole transcript\n- Improved responsiveness during tool-heavy turns by no longer redrawing the transcript for a hidden per-tool-batch reminder\n- Improved startup time in projects with `.claude/workflows/` scripts: listing them no longer parses each script\n- Improved auto mode denials: the message Claude receives now names the rule that blocked the action and asks Claude to try a safer method and finish unrelated work before stopping to ask you\n- Improved Claude in Chrome: long page reads now stay inline instead of being saved to a file and read back\n- Improved the MEMORY.md truncation warning to say how many lines were cut and where the cut starts\n- Improved the terminal permission prompt for artifacts: it now leads with the ask's question\n- Improved the prompt footer: an editor or `/diff` selection now shows inside the prompt input, and fullscreen mode shows Remote Control status in the header instead of the footer\n- Improved the \"Usage credits required for 1M context\" message to say that usage credits turned on mid-session take effect after restarting Claude Code\n- Improved `/plugin`: installing, enabling or disabling a plugin now takes effect when you close the menu; `/reload-plugins` is no longer needed afterwards\n- Changed the system prompt on Bedrock, Vertex and Foundry to deliver environment, model and settings details as attachments, matching first-party sessions\n- Changed Bedrock, Vertex and Foundry sessions to keep the tool list byte-stable across a conversation (late-connecting tools load deferred instead of rewriting it), matching first-party sessions\n- Changed the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) to be offered only on Claude 3.x, Opus 4.0–4.7, Sonnet 4.0–4.6, Haiku 4.5; set `CLAUDE_CODE_ENABLE_TODO_TOOLS=1` elsewhere\n- Changed the artifact data-edit permission prompt in the terminal to a card that shows the document count and who can open the artifact\n- Changed local Cowork sessions set to skip all approvals: the Artifact tool now refuses a local file outside the session's folders, or behind a symlink, instead of reading it without asking\n- Changed plain `WebFetch` deny and ask rules to no longer apply to Artifact tool reads and updates; use an `Artifact` rule (or `WebFetch(domain:claude.ai)`) to block or gate them\n- Changed the \"N MCP servers need authentication\" startup notice to announce each server once instead of at every launch\n- [VSCode] Fixed the session list, settings toggles, and chat tabs when `CLAUDE_CONFIG_DIR` is set in a settings file or the `environmentVariables` setting\n- [VSCode] Fixed the model pill, model picker and command menu going blank in open tabs for a few seconds after a login, logout or account switch\n- [VSCode] Fixed Auto disappearing from the mode picker in new-tab or just-reloaded conversations when a project or local setting overrides the model named in `~/.claude/settings.json`\n- [VSCode] Fixed session names reverting to the last prompt after a window reload when a SessionStart hook is configured\n- [VSCode] Fixed the footer's model pill and Remote Control pill waiting for the new tab's Claude process to start when another tab in the window is already up\n- [VSCode] Fixed a second Claude process running through its full startup when a session tab's launch arrived more than half a second after its config read\n- [VSCode] Fixed resuming a session from the session list ignoring `claudeCode.preferredLocation: \"sidebar\"` (it always opened a panel), and programmatic opens resetting that setting to \"panel\"\n- [VSCode] Fixed Windows issues: the WSL install prompt no longer appears on machines without WSL installed, and IDE diagnostics are now returned correctly for Windows files when WSL is installed\n- [VSCode] Fixed the custom style builder saving a User level style in a folder the CLI does not read when `CLAUDE_CONFIG_DIR` is set through settings\n- [VSCode] Added Left and Right arrow keys to change where an always-allow permission rule is saved, for keyboard and screen reader users\n- [VSCode] Added a \"Claude Code: Focus last message\" command that moves keyboard focus to the newest message in the conversation, for keyboard and screen reader users\n- [VSCode] Changed the Manage plugins dialog to apply installs, enables, disables and uninstalls to open sessions without a restart\n- [VSCode] Changed some artifact permission prompts to omit the \"don't ask again\" choice, matching the terminal\n- [Claude Code on the web] Fixed cloud sessions running longer than about six hours silently losing files saved to persisted session folders; saves now persist for up to a day\n- [Claude Code on the web] Fixed \"Invalid effort level\" errors when a routine resumes a session, or a session starts with no set effort, in orgs where an admin caps a model's effort\n- [Claude Code on the web] Improved routine creation from a conversation: when the new routine has no connectors, Claude now says so and how to add them instead of only confirming it\n- [Claude Tag] Fixed the admin settings page hanging on a loading skeleton or going blank after a transient load failure; a section that fails to load now shows a Retry button\n- [Claude Tag] Added a link from a Slack channel's configure page back to the organization's Claude in Slack admin settings\n- [Claude Tag] Fixed a Slack Enterprise Grid channel losing its Claude settings (repository, environment, access) after a Slack admin moved it to another workspace\n- [Claude Tag] Improved how Claude explains a blocked action: it now says whether a permission check, its own decision to confirm first, or missing access stopped it\n- [Claude Tag] Improved reply speed: Claude now runs several read-only lookups (searching Slack, reading a thread, finding people) at once instead of one after another\n- [Claude Tag] Improved formatting of comparisons: sentence-length comparisons now come as lists instead of wide tables that scroll sideways, and long table cells wrap\n- [Claude Tag] Fixed `@Claude !restart` in a thread with its own session sometimes also posting a contradictory \"this thread is handled by the channel session\" notice\n- [Claude Tag] Improved the message shown when your Claude account is in a different organization than the Slack workspace: it now explains how to connect the workspace to your org\n- [Claude Tag] Fixed Markdown links whose URL is wrapped in angle brackets showing as literal bracket text in Slack instead of a clickable link\n- [Claude Tag] Fixed a workspace guest's top-level @mention in a channel where guests may use Claude sometimes getting a \"your Slack account isn't connected\" reply instead of an answer\n- [Claude Tag] Fixed a channel's long-running session being replaced with a fresh one mid-conversation; the scheduled refresh now waits until the channel and its threads are quiet\n- [Claude Tag] Fixed channel-settings cards clicked more than once telling the proposing session the change was refused after it had already applied; the outcome is now sent once\n- [Claude Tag] Changed memory in public channels: each channel now keeps its own notes, and Claude no longer recalls notes it saved in other public channels; workspace notes stay shared\n- [Code Review] Added a note under the still-open findings list in follow-up reviews: resolving a finding's thread, not just replying to it, stops later reviews from counting it as open\n- [Code Review] Fixed reviews sometimes ending as incomplete when one of the agents verifying a finding failed midway; the review now replaces that agent and reaches a verdict\n- [Code Review] Fixed a push-triggered review that was queued behind a running review still posting after the pull request had been converted to draft\n- [Code Review] Fixed reviews ignoring a directory's CLAUDE.md conventions when the PR edited a root file (e.g. README.md) that only shares a name with a file that CLAUDE.md lists","body_html":null,"content_hash":"07cfe1d2edb0f5e8edc2dd7a7b1a85b3e6a6aba652a30e63fae77c4fc2221bdf","updated_at":"2026-10-05T19:08:34.937Z"},{"id":"99c21431-871d-4cd9-883b-f6b02c042ab7","source_id":"cursor","dedupe_key":"cursor:https://cursor.com/changelog/projects","version":"Cursor Projects","title":"Cursor Projects","url":"https://cursor.com/changelog/projects","published_at":"2026-09-10T00:00:00.000Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.651Z","body_md":null,"body_html":"<p><a href=\"/changelog/projects\">Sep 10, 2026</a> · <a href=\"/changelog\">Changelog</a></p><h1><a href=\"/changelog/projects\">Cursor Projects</a></h1>\n<p>Today we&#x27;re launching Projects in Cursor. Projects lets you take on larger bodies of work, such as a feature, a migration, or a full app. It maintains context over months of work, delegates tasks to thousands of subagents, and performs recurring work without being prompted.</p>\n<p>Access Projects from the left-hand nav. The coordinator agent in a project doesn&#x27;t write code itself; it plans the work, delegates it to agents that implement it, and brings the finished work back to you to check. Coordinators create and manage agents on your behalf, running as many in parallel as the work needs.</p>\n\n<h2><a href=\"#powered-by-cloud-agents\">#</a>Powered by Cloud Agents</h2>\n<p>A Project runs on its own computer in the cloud, so closing your laptop doesn&#x27;t stop it. When something needs testing on your machine, the coordinator spins up a local agent to run it there.</p>\n<h2><a href=\"#shared-context\">#</a>Shared context</h2>\n\n<p>You shouldn&#x27;t have to onboard an agent every time you start a task. Each Project maintains a set of files that sync across every cloud and local machine its agents use. Agents add research and artifacts, along with what they learn about the codebase and how you prefer work to be done. If one agent figures out how to test a service, for example, every future agent can use those instructions. The shared context grows with the Project, making the coordinator more effective over time.</p>\n<h2><a href=\"#subscriptions\">#</a>Subscriptions</h2>\n\n<p>Tell the coordinator agent to watch a Slack channel, run on a schedule, or follow all your PRs. This way it can take action based on signals it detects, without waiting for your prompt.</p>\n<p>Connect Slack and point it at a bug-report channel, and it starts delegating each time a bug comes in.</p>\n<p>Projects are available in beta and rolling out to all users starting today.</p>","content_hash":"0ef53ad88da7b9164f5be37d91f38245d5039f28c6fab0917055eacfb8c840d9","updated_at":"2026-10-05T18:59:33.143Z"},{"id":"4a2e1c7c-2579-42cd-9d30-5f49ff6bb535","source_id":"claude-code","dedupe_key":"claude-code:2.1.267","version":"2.1.267","title":"claude code 2.1.267","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21267","published_at":"2026-09-09T18:25:42.820Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added `maxEffortLevel` setting (top-level or per model under `modelSettings`): caps the effort level on every provider, including Bedrock, Vertex and Foundry; users can still pick a lower level\n- Added `--system-prompt-snapshot off` to render the system prompt fresh on every request instead of reusing the conversation's recorded prompt (for iterating on prompt text)\n- Fixed Cowork scheduled tasks in the cloud failing at startup for organizations whose managed settings require sandboxing\n- Fixed `/context` and other local command output rendering blank on mobile clients\n- Fixed shift+enter and option+backspace not working after reconnecting to a tmux or ssh session inside an agent view\n- Fixed the dim last-prompt header not appearing at the top of the conversation when scrolling up in fullscreen mode\n- Fixed Workflow `agent()` calls with large output schemas being refused in auto mode instead of being checked by the safety classifier\n- Fixed a case where a marketplace entry path containing a backslash could bypass the containment check for fetched marketplaces on macOS and Linux\n- Fixed expired AWS or Google Cloud credentials under a host app such as Claude Desktop retrying ten times with a generic \"request failed\" before the re-authenticate error appeared\n- Fixed resuming a session after `/compact` or another slash command ran via `-p --resume`: a spurious \"Continue from where you left off.\" turn is no longer inserted\n- Fixed resuming a large session (transcript over 5 MB): parallel tool calls and their hook output are no longer dropped from the reloaded conversation\n- Fixed managed `allowedHttpHookUrls`, `httpHookAllowedEnvVars` and `allowedChannelPlugins` to admit nothing, not everything, when unreadable\n- Fixed `/login` on machines whose managed settings require Claude apps gateway sign-in: Esc now closes the dialog instead of doing nothing\n- Fixed artifact publishes cut off by a dropped connection mid-upload: they now retry once when Claude Code can tell the upload never completed, instead of reporting an unknown outcome\n- Fixed `effort:` frontmatter on custom commands, skills, and subagents being ignored on models whose default effort is still pinned (Opus 4.7, Opus 4.8, Fable 5)\n- Fixed artifact publish failing with an unhelpful error when the page file isn't valid UTF-8 or contains a replacement character (U+FFFD); the error now names the line and column to fix\n- Fixed `claude agents` `@` directory menu not listing repositories created after the session started\n- Fixed Remote Control clients that join a Claude Desktop or VS Code session showing a stale permission mode until it was changed again\n- Fixed `claude remote-control` exiting and dropping every attached session when its server credential expires (about 30 days after start); the host now re-registers and keeps going\n- Fixed the usage-limit warning flickering on and off during a session when requests for different models or modes report different limit windows\n- Fixed earlier reasoning being dropped when an MCP server re-sends, or a built-in tool re-renders, a tool the model already loaded\n- Fixed a tool that disappears mid-conversation, from a disconnected MCP server or an upgrade, rewriting the tool list and discarding earlier thinking\n- Fixed a background worker forked from a conversation adding EnterWorktree to the conversation's tool block mid-session, which broke prompt-cache reuse\n- Fixed mid-session MCP and plugin tools being added to the tool list in sessions without ToolSearch, which broke prompt-cache reuse; supported models now receive them as deferred definitions\n- Fixed switching models with /model re-sending every tool definition (a prompt-cache miss); commit and PR attribution text now arrives as a conversation note that updates on model changes\n- Fixed resumed sessions rewriting the inline tool set when an MCP connector reconnects at a different moment than before\n- Fixed resumed sessions re-rendering tool descriptions instead of replaying the recorded ones when the first turn ran a tool\n- Fixed prompt-cache misses and dropped extended thinking when a claude.ai connector's tools change between a session and its resume\n- Fixed resumed sessions rewriting earlier MCP tool announcements (and dropping extended thinking) before their connectors reconnect\n- Fixed a prompt-cache break when a print-mode (`-p`) conversation is resumed interactively: the system prompt prefix no longer changes\n- Improved the `/diff` panel: it no longer flashes \"0 files changed\" and a spinner before settling, and its empty state is centered in the panel\n- Improved the Bash tool's description guidance so Claude describes what a command does in plain words instead of echoing the command\n- Improved sandbox guidance so Claude suggests `/copy` when clipboard commands such as `pbcopy` fail inside the sandbox\n- Improved `--resume` first-render time for sessions with many Bash tool calls\n- Improved prompt input responsiveness: keystrokes no longer occasionally wait a frame behind spinner or streaming repaints\n- Improved prompt-cache stability: subagents and sessions started with `--system-prompt` or `--append-system-prompt` now record the system prompt and tool definitions once instead of re-rendering them\n- Improved Artifact tool publish errors: when a publish is refused, the message now says why and what to do about it\n- Self-hosted runner: Changed `--use-anthropic-git-proxy` to be reported to the server at registration and to print a warning for each session that still clones through the legacy git proxy\n- Gateway: Changed `forward_user_identity` upstreams to return a 429 as-is to a developer whose email was forwarded, instead of failing over to the next upstream, so the proxy's per-user limits hold\n- [VSCode] Fixed the extension host hanging at 100% CPU when forking, editing an earlier message, or rewinding in a conversation whose saved transcript contains a cyclic parent link\n- [VSCode] Fixed pasting a screenshot on WSL2/WSLg inserting raw image bytes into the chat input; the image is now attached when the clipboard provides it, otherwise the paste is ignored\n- [VSCode] Fixed chat diff blocks always rendering with a dark editor theme; they now follow the active VS Code color theme, including high contrast\n- [VSCode] Fixed mixed right-to-left and English text rendering in the wrong order while typing in the message input\n- [VSCode] Fixed accepting an edit in the diff view on a file with Windows (CRLF) line endings failing with \"String not found in file\"\n- [VSCode] Fixed @-mentions dropping files whose paths contain spaces\n- [VSCode] Fixed the sessions list view failing to load in windows connected over Remote-SSH when the workspace folder exists only on the remote host\n- [VSCode] Fixed runaway ripgrep processes when viewing files in large or symlink-heavy workspaces\n- [Claude Code on the web] Fixed GitHub Enterprise Server sessions showing your GitHub account as disconnected once its token expired; PR and issue operations now refresh it automatically\n- [Claude Code on the web] Fixed `gh` and GitHub API calls failing in organizations without the Claude GitHub App; they now use your connected GitHub account and say so when none is connected\n- [Claude Tag] Added a \"Use a custom connector\" link to the preset connection forms in Claude Tag admin settings, so you can switch to a custom connection without starting over\n- [Claude Tag] Fixed Claude replying \"The API rejected the request as invalid\" when the organization has run out of usage credits; the reply now says so and explains how to add more\n- [Claude Tag] Fixed thread requests to edit or delete a message Claude posted at the channel's top level being answered with a correction instead of reaching the session that posted it\n- [Claude Tag] Fixed **Connect** on Tool access requests under Admin settings > Review requests failing with \"Authorization failed\" or showing the requested access bundle as deleted","body_html":null,"content_hash":"0926675afa5971488e121957301a5ae49b87a82543a53e03e591e9dc0ef35bb4","updated_at":"2026-10-05T19:08:34.937Z"},{"id":"8edc3410-b855-44cf-b64c-7d229d082e72","source_id":"claude-code","dedupe_key":"claude-code:2.1.266","version":"2.1.266","title":"claude code 2.1.266","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21266","published_at":"2026-09-08T23:32:32.880Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Fixed a 2.1.265 regression affecting LLM-gateway and proxy setups: the undocumented `CLAUDE_CODE_USE_GATEWAY` environment variable, previously ignored unless `ANTHROPIC_BASE_URL` and `ANTHROPIC_AUTH_TOKEN` were both set, began forcing Cloud-gateway sign-in on its own in 2.1.265, so configurations that set it alongside an API key, `apiKeyHelper`, or custom auth headers failed every request with \"Not signed in to the Cloud gateway\". The variable on its own is ignored again; no configuration change is needed","body_html":null,"content_hash":"ce642ddc446b9f878a1d40482ba0c0c7da6b34898a1a4b0e3d4f84f77f05d0a5","updated_at":"2026-10-05T19:08:34.937Z"},{"id":"1d434789-8bc3-434f-957f-3ab69bb8ba84","source_id":"claude-code","dedupe_key":"claude-code:2.1.265","version":"2.1.265","title":"claude code 2.1.265","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21265","published_at":"2026-09-08T19:05:16.492Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added `user.email` and `user.groups` to the telemetry Claude Desktop and Cowork send through a Claude apps gateway, matching terminal sessions\n- Added support for pointing `--plugin-dir` at a folder of plugins: each child folder with a manifest loads, and children added or removed while running are picked up\n- Added a 1 GB cap on tool results saved to disk; the in-conversation preview says when a saved file was truncated\n- Fixed resuming a foreground-spawned subagent changing its tool list and system prompt prefix, which broke prompt-cache reuse for that agent\n- Fixed agent teammates and resumed subagents moving SubagentStart hook context and preloaded skills out of the prompt prefix on later turns, which broke prompt-cache reuse\n- Fixed resume after the previous process died while a tool was running: the last prompt is no longer rewritten, and the interrupted tool call is kept and marked interrupted\n- Fixed `/model opusplan[1m]` being rejected with \"Model not found\"\n- Fixed syntax-highlighted code in permission prompts and messages sometimes omitting a character after a Ruby `?`, Erlang `$`, or Perl `$` sigil\n- Fixed the fullscreen transcript jumping by one row whenever the slash-command or @-file suggestion list opened or closed\n- Fixed a plugin path containing a backslash bypassing the symlink containment check on macOS and Linux\n- Fixed plugin directories whose names begin with two dots being wrongly refused as outside the plugin root\n- Fixed VS Code and SDK sessions occasionally requiring re-login when a session was closed while refreshing its token\n- Fixed Remote Control sessions sending the end-of-turn signal before the reply's last message, which could show a reply as finished in the Claude app before its last part arrived\n- Fixed background (`--bg`) sessions occasionally being retired mid-turn when a message arrived just before the idle timeout\n- Fixed Claude Code's own git status and diff probes running clean filters configured by a nested repository inside the working tree\n- Fixed the advisor tool and its instructions being re-decided per request from the request's model; the decision is now made once and announced in the conversation when it changes\n- Fixed artifact publish accepting connector tool names the connector doesn't expose; the publish is now refused when none of the declared tools exist, and warned when only some don't\n- Fixed `/add-dir <subdirectory>` refusing to load a subdirectory's agents when managed settings lock only skills to plugins, and promising agents when only agents are locked\n- Fixed two-key keyboard shortcuts cancelling silently when the second key arrived more than a second later, as happens inside tmux; they now wait 3 seconds and show a notice when they time out\n- Fixed forked skills (`context: fork`) not streaming their kickoff prompt and, with `--forward-subagent-text`, their text turns as progress events in stream-json\n- Fixed a plugin's default component folder that the OS cannot check, such as a symlink loop, being silently skipped; it is now reported in `/plugin` with the error code\n- Fixed the Claude apps gateway's OTLP telemetry relay pausing all forwarding to a collector for 30 seconds after it rejected a few payloads as malformed or too large\n- Fixed `/plugin` Discover/Browse and `claude plugin list --json --available` showing no description or display name for marketplace plugins whose metadata lives only in their `plugin.json`\n- Fixed `/login` showing \"no gateway URL is configured\" when re-run in a session that signed in to a Claude apps gateway set by managed settings\n- Fixed `/model` claiming a model was \"saved as your default\" when the settings file couldn't be written; it now says the save failed and why\n- Fixed `/clear` from Remote Control waiting on SessionStart hooks and on open terminal dialogs before completing\n- Fixed the `/config` dialog changing height when switching between its tabs\n- Fixed resuming a workflow run after its container restarted; a resume whose run journal is missing now fails with a clear error instead of rerunning every agent\n- Fixed the `claude-api` skill's error-code reference: model access failures return 404 and unavailable beta headers return 400, not 403\n- Fixed non-interactive sessions (`-p` with stream-json input, Agent SDK, cloud sessions) resetting the shell working directory at each new user message; a `cd` now persists across turns\n- Fixed MCP servers configured as `http` that only speak the legacy HTTP+SSE transport never connecting; Claude Code now falls back to SSE as the MCP spec describes\n- Fixed some claude.ai connectors in cloud sessions showing as needing authentication even though they are connected in claude.ai (servers that answer an unsupported request with HTTP 401)\n- Fixed remote sessions keeping their sandbox container alive while a connector approval or sign-in link waits for you\n- Fixed resumed sessions showing long model-facing recovery instructions in \"background task didn't finish\" notices instead of a short status line\n- Windows: Fixed Read, Write and Edit refusing every file (\"symlink resolution changed after permission was checked\") when running inside an AppContainer or restricted-token sandbox\n- Improved `--worktree` startup on large repositories: the new worktree is now checked out in parallel (git 2.32+)\n- Improved `/workflows` agent detail: tool calls are marked running, failed or done, the subagent's task list is shown when it has one, and Enter unfolds the listed calls with their inputs and results\n- Improved slash commands typed mid-prompt: matches now show in a list (Tab opens it outside fullscreen) instead of a single suggestion, and a plugin skill is now found by its bare name\n- Improved remote MCP servers that need sign-in: Claude Code no longer registers an OAuth client with them until you actually authenticate\n- Improved the time to resume long sessions that read many files\n- Improved the error shown when an image over the size limits cannot be decoded: it now names the cause and how to fix it instead of only citing the limit\n- Improved the Artifact tool's read of an artifact someone else wrote: the summary now treats the page as untrusted content and flags embedded instructions rather than relaying them\n- Updated the `.claude` folder permission option to say what it actually allows: editing files in the project's `.claude` folder (or `~/.claude`) for the session\n- Changed machines with `forceLoginGatewayUrl` in managed settings to be Claude apps gateway sessions from startup, like `forceLoginMethod: \"gateway\"`; a leftover claude.ai login or API key is not used\n- Changed image processing to use the runtime's built-in image support; the CLI no longer extracts a native image module to the temp directory\n- Changed plugin display metadata to prefer the marketplace entry over `plugin.json` on the Installed tab and `claude plugin details`, filling gaps from `plugin.json`\n- Changed Claude apps gateway sessions to export OpenTelemetry directly to a collector the gateway's managed settings name in `OTEL_EXPORTER_OTLP_ENDPOINT`, instead of through the gateway's relay; sessions without a named collector still use the relay\n- [VSCode] Added automatic archiving of sessions inactive for a set period (new \"Archive inactive sessions\" setting, default 14 days)\n- [VSCode] Fixed the sidebar chat coming back blank after Reload Window or a restart when the conversation had been open for more than 10 minutes\n- [VSCode] Fixed the timeline dot sitting below the text on the \"Remote Control is active\" message","body_html":null,"content_hash":"5b090c8e69b394ac4776cdb81782a86e4acf11dbcf153df3a63efe20eeca2aa5","updated_at":"2026-10-05T19:08:34.937Z"},{"id":"87f5eaef-9caf-49d5-8a3f-82b9fa8a95b0","source_id":"claude-code","dedupe_key":"claude-code:2.1.263","version":"2.1.263","title":"claude code 2.1.263","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21263","published_at":"2026-09-06T02:07:58.391Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Bug fixes and reliability improvements","body_html":null,"content_hash":"8dd94cdbd47fca7a63c7953ef64ac0589757029c2ace7fcc6ab37062c6e35ba9","updated_at":"2026-10-05T19:08:46.471Z"},{"id":"b03d53a3-0343-45ff-a4f2-353c3a7a2ae1","source_id":"claude-code","dedupe_key":"claude-code:2.1.261","version":"2.1.261","title":"claude code 2.1.261","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21261","published_at":"2026-09-04T17:49:34.927Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added an \"Organization policy\" line to `/status` and `claude doctor` that says why your organization's policy could not be loaded, such as a proxy not passing the endpoint through\n- Added `bashOutputMaxChars` and `taskOutputMaxChars` settings to raise how much command and background-task output Claude receives inline before it is saved to a file, up to 128K characters\n- Added `--append-subagent-system-prompt-file` to read the subagent system prompt from a file, for prompts too large to pass on the command line\n- Added `/skill-doctor` to show which loaded skills go unused and what they cost in context, so you can prune them\n- Fixed typed or pasted characters occasionally landing out of order or being dropped during fast input or key repeat\n- Fixed `/add-dir <subdirectory>` printing a false \"couldn't be resolved\" error when the working directory is on a `/net` automount\n- Fixed the Bedrock setup wizard hanging when AWS or an AWS credential helper never responds (it now times out with a clear error), and its model checks failing behind a TLS-inspecting proxy\n- Fixed cloud sessions discarding a plugin synced from claude.ai when managed settings force-enable it in `enabledPlugins`, then falling back to a marketplace clone that could fail\n- Fixed being unable to delete the character immediately before an inline `[Image #N]` chip in the prompt input\n- Fixed resuming a session losing hook output and other context around parallel tool calls, which changed the resumed request\n- Fixed Remote Control showing a stale permission mode when a phone, browser, or claude.ai app attaches to a terminal session or after the mode changes in the terminal\n- Fixed Remote Control sessions showing as still working (stuck spinner and Stop button) after stopping a turn from a connected phone or browser, or after a local slash command like `/clear`\n- Fixed SDK and cloud sessions ignoring a Stop or interrupt sent just after the first prompt, before the turn had started; the turn now stops instead of running to completion\n- Fixed Remote Control uploading a session pulled with `/teleport` into the connected session, which appeared appended to the original on phone and web\n- Fixed Remote Control's inbound event stream failing behind TLS-inspecting corporate proxies on native Windows\n- Fixed Remote Control sessions showing the default effort level on claude.ai when the effort comes from settings\n- Fixed `gcpAuthRefresh` opening a browser at startup when the Google credential check was slow, even though the credential was still valid\n- Fixed claude.ai connectors staying absent for the whole session when the startup connector fetch timed out — the CLI now retries in the background\n- Fixed sustained high CPU usage when a background agent could not be resumed and its wake-up was retried in a tight loop\n- Fixed feature flags gated to a newer version occasionally applying to an older Claude Code version running on the same machine\n- Fixed `/usage` and the VS Code usage panel dropping a model-specific weekly limit row when the usage endpoint is rate limited or when opened right after startup\n- Fixed `claude -p --resume <file>` adopting a malformed session ID recorded in the transcript; it now resumes under a fresh session ID instead\n- Fixed the terminal progress indicator (iTerm2, Ghostty, ConEmu) showing the session as finished while a background workflow or agent was still running\n- Fixed a rare layout glitch where a box could render with the wrong height after its container switched between row and column direction\n- Fixed Claude apps gateway client IP when a trusted proxy appends a port to `X-Forwarded-For`; with an access list set, an unreadable entry now gets 403\n- Fixed Claude apps gateway telling Claude Desktop to export OpenTelemetry as JSON even when the terminal CLI uses protobuf, so protobuf-only collectors rejected Desktop's data\n- Fixed Desktop and web showing a session as busy while it only watches an artifact for updates\n- Fixed Claude in Chrome `file_upload` failing with \"paths: expected array, received undefined\" in local Cowork sessions run from the Claude Desktop app\n- Fixed `SendMessage` to an offline Remote Control session on another machine reading as delivered; the result now says delivery is queued until that machine reconnects\n- Fixed plugin install hints from CLIs run in background Bash commands: they are now detected, and the raw `<claude-code-hint>` tag no longer leaks into the conversation\n- Fixed in-process agent-team teammates re-sending their first-turn tool and skill announcements on the second turn, which changed the request prefix and missed the prompt cache\n- Improved the `/model` picker and the VS Code model pill to show a model's name instead of its raw Bedrock, Vertex AI, or LLM gateway ID when Claude Code recognizes it\n- Improved startup on Google Vertex AI when `GOOGLE_APPLICATION_CREDENTIALS` is set: API client creation no longer re-runs Google Cloud project discovery or spawns extra `gcloud` processes\n- Improved streaming performance: already-rendered blocks are no longer re-checked by layout on each update\n- Improved the dangerous-`rm` safety prompt to also catch `rm -rf` on positional parameters and inside double-quoted `sh -c` scripts\n- Improved handling when the API sends no response headers: the retry now waits up to `API_TIMEOUT_MS` (10 minutes by default) instead of another 3 minutes, and the messages say what to change\n- Changed a Claude apps gateway 403 on the managed settings load (at startup or after `/login`) to say Claude Code may not be enabled for the organization, instead of advising a new sign-in\n- Changed machines whose managed settings pin `forceLoginMethod: \"gateway\"` to ignore a leftover API key or claude.ai login and ask for `/login`; Bedrock, Vertex AI, and Foundry sessions are unaffected\n- Changed auto mode to treat a link that packs content into a public diagram renderer's URL as an upload to that site: no longer auto-approved unless you asked for it\n- Changed the prompt's word-editing keys to match Bash: Ctrl+W deletes back to whitespace, Alt+F and Alt+D stop at word end, punctuation separates words; `keybindingFlavor` no longer has any effect\n- Changed `/context` token counting to use a local estimate when the token-counting API is unavailable, instead of extra small-model requests\n- [VSCode] Added a \"Build a custom style\" walkthrough to the Output styles menu that writes a custom output style file and lists it right away\n- [VSCode] Added an Add server form and a Remove action to the MCP servers dialog, so MCP servers can be added and removed without leaving the IDE\n- [VSCode] Added a hollow ring in the session list for sessions open in a terminal, another VS Code window, or Claude Desktop, so they no longer look closed\n- [VSCode] Added a fold button to permission and question prompts so the conversation behind them can be read without dismissing them; the space beside the prompt now scrolls the conversation\n- [VSCode] Added \"Archive session\" to the session list's right-click menu and gave Unarchive its own icon\n- [VSCode] Fixed a session teleported from Claude Code on the web treating a question that was cut off when the cloud session shut down as declined\n- [VSCode] Fixed the session tab's Rename box opening empty for a tab restored with the window; it now starts with the current name\n- [VSCode] Fixed collapsed sections in the session list panel briefly showing expanded each time the panel loaded\n- [VSCode] Fixed Focus view showing a tool call as still running after Claude had moved on, such as while a question waited for your answer\n- [VSCode] Fixed the session list's active-row highlight going stale when an unfocused Claude tab's session ID is corrected\n- [VSCode] Fixed Cmd/Ctrl+Shift+T reopen and deep-link opens placing the Claude tab outside the Claude editor group when a Claude tab has focus\n- [VSCode] Fixed the session tab's \"Add to group\" putting a session opened from Claude Code on the Web in two groups; it now moves the entry the session list shows\n- [VSCode] Fixed the model picker showing models an organization has since disabled until the window was reloaded twice\n- [VSCode] Fixed a tab opened from the session list jumping back to that session, and a tab opened from a Web session restarting its teleport or staying empty, after VS Code reloads the tab's view\n- [VSCode] Fixed `/btw` side-question history from earlier sessions being overwritten when a question is asked right after a window reload or while a settings file has errors\n- [VSCode] Fixed the pending question card not reappearing after the Claude panel reloads when signed in with a Claude.ai or Console account\n- [VSCode] Fixed claude.ai-only features staying visible in a window's other Claude panels after one panel picked up a third-party provider from a settings file\n- [VSCode] Fixed the sign-in screen appearing despite the Disable Login Prompt setting when Claude Code reports no login or a request fails for lack of one\n- [VSCode] Fixed the next queued permission prompt keeping text typed on the previous prompt and accepting an immediate second click\n- [VSCode] Fixed install-plugin links opening the Claude sidebar without the install dialog in a window where only the session list had been shown\n- [VSCode] Fixed the sidebar usage meter staying empty on a new window until the Account & usage dialog was opened, and a 0% usage limit being left out of the meter\n- [VSCode] Fixed \"Start new session in this group\" losing the group after New conversation, and a missing unread dot for a session that finished before the sidebar's unread list loaded\n- [VSCode] Fixed the editor tab badge showing unread during a running turn or missing on a tab opened from the session list, and \"Add Session Tab to Group\" doing nothing for an archived session\n- [VSCode] Fixed \"Enable Remote Control for all sessions\" so flipping it also applies right away to sessions open in other VS Code windows\n- [VSCode] Fixed the session list's Open filter for sessions continued from claude.ai whose tab was still recorded under the web session, and labeled the filter menu's sections for screen readers\n- [VSCode] Changed the model picker to one flat list of every model, with rows kept for older model spellings listed last","body_html":null,"content_hash":"81aef91c212c3c09a4277256ff55ecb10023175269da3cd057675a318e4dc5cb","updated_at":"2026-10-05T19:08:46.471Z"},{"id":"de9b246d-81ed-48a9-8f03-e4c6245f328d","source_id":"claude-code","dedupe_key":"claude-code:2.1.260","version":"2.1.260","title":"claude code 2.1.260","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21260","published_at":"2026-09-03T22:32:02.087Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added a diff panel that opens beside the conversation in fullscreen mode and shows your uncommitted changes as Claude edits; toggle it with `/diff`\n- Added a likely cause for prompt-cache misses (e.g. tool definitions or system prompt changed, idle past the TTL) to `/cost` and the status line's `prompt_cache` field\n- Added `/reload-plugins` to headless sessions, so it appears in the Claude Code Desktop and SDK command lists\n- Added a text form of `/advisor` (`/advisor`, `/advisor <model>`, `/advisor off`) for the desktop app, Remote Control, and other headless (`-p`/Agent SDK) sessions\n- Added `oidc.scope_on_refresh` to the Claude apps gateway for IdPs that return an id_token on refresh only when asked for `openid` again\n- Added Claude apps gateway support for newer Claude Desktop keys in `desktop` policy blocks, including `userPluginMarketplacesEnabled` and `userPluginUploadsEnabled`\n- Fixed `Edit`/`Write`/`Read` permission rules whose path contains parentheses being dropped as invalid or ignored by the Bash sandbox, which left \"read-only\" folders writable\n- Fixed one file permission rule with an uncompilable pattern (e.g. an unclosed `[`) making every file edit fail with `Invalid regular expression`; such a deny rule now guards the literal path it spells\n- Fixed Bash permission checks auto-approving zsh commands that hide a command substitution in a REPORTTIME, REPORTMEMORY or DIRSTACKSIZE assignment; these now prompt for approval\n- Fixed Bedrock model discovery, token counting and AWS SSO/STS credential calls failing with \"unable to get local issuer certificate\" when the corporate root CA is only in the OS certificate store\n- Fixed `permissions.blockReadsOutsideWorkingDirectories` on macOS hiding the user's git config from sandboxed git and hiding a worktree-isolated sub-agent's own checkout\n- Fixed managed settings not loading for claude.ai Enterprise/Team users who also had a leftover API key from an earlier `/login`\n- Fixed `/status` listing a signed-in claude.ai account and a configured API key as if both were in effect; the credential not in use is now marked\n- Fixed managed `skillOverrides` entries keyed on a bundled skill's alias (e.g. `checkup` for `/doctor`) not applying, and `Skill(name)` deny rules not covering a nested skill listed as `<dir>:name`\n- Fixed `model: fable` agents ignoring the `[1m]` tag on an `ANTHROPIC_DEFAULT_FABLE_MODEL` pin and silently running with a 200K context window\n- Fixed the `/model` picker not showing Fable 5.1 for organizations that can use it, which was only accepted when typed as `/model claude-fable-5-1`\n- Fixed prompt caching on Claude Fable 5.1 not covering the context attached after tool results, so it was re-sent as uncached input on every tool-call turn\n- Fixed model switching staying blocked for the rest of the session after a plugin hook load failure; each switch now re-checks and the refusal names the cause\n- Fixed model switching being blocked for the session when an organization-managed plugin's marketplace could not be loaded\n- Fixed SDK-provided MCP servers (e.g. Desktop connectors) sometimes missing from the first turn and only appearing on the next one\n- Fixed Claude in Chrome tools failing with \"Not connected\" mid-task in cloud-hosted claude.ai sessions when a connector was added or removed\n- Fixed flags, joined emoji and accented letters splitting across wrapped lines, and stale text staying on screen when a flag or joined emoji falls in the terminal's last two columns (now shown as `…`)\n- Fixed Remote Control accepting a model pick that is not a valid model name; it is now refused with an error instead of failing on the next message\n- Fixed `/rewind` and `--rewind-files` reporting success when checkpoint backup files were missing and nothing was actually restored\n- Fixed `/rewind` leaving stale file-read tracking from the rewound-away turns, which caused \"File unchanged since last read\" stubs and full-file re-injection after external edits\n- Fixed `-p --resume`/`--continue` (as used by the desktop app) failing on every retry once a session's worktree directory lost its git metadata; it now fails once, then resumes without the worktree\n- Fixed a subagent that resumed another agent via SendMessage never being woken by that agent's completion (the notification went to the main conversation instead)\n- Fixed agent teams: an in-process teammate's transcript losing messages, or going blank, during long API retry waits (e.g. under `CLAUDE_CODE_RETRY_WATCHDOG`) as retry notices evicted real messages\n- Fixed a session that moved to the background appearing twice in ListAgents (once as a phantom \"interactive\" twin with the same name) and receiving SendMessage deliveries in the viewer\n- Fixed intermittent \"task output swap refused\" errors when many sessions share a project directory\n- Fixed Ctrl+Z in fullscreen leaving the shell on the alternate screen, drawn over the paused interface\n- Fixed Workflow tool subagents being restarted as stalled while a long context compaction was still in progress\n- Fixed plugins from a URL marketplace failing to install with \"marketplace entry path does not stay inside the marketplace directory\" when a host app (e.g. Claude Desktop) stores it as a directory\n- Fixed an extra browser tab opening when an artifact is published in a session you're driving from claude.ai, the desktop app, or mobile (Remote Control)\n- Fixed the Artifact tool's first call failing with an \"Invalid tool parameters\" validation error in some Cowork sessions\n- Fixed IDE line selections being dropped when running a skill or slash command (the \"N lines selected\" context now reaches Claude)\n- Fixed repository detection for GitLab projects in nested subgroups (e.g. `gitlab.com/group/subgroup/project`)\n- Fixed `owner/repo#123` issue references in rendered output linking to github.com when working in a GitLab repository; they now link to the gitlab.com issue\n- Glob/Grep: Fixed the search path being probed on disk before the permission check; a missing path is now reported after permission is decided, as Read does\n- Reverted the 2.1.259 change applying `Read()` deny rules to Bash arguments; it denied `npm run build` under a `Read(./**/build/**)` rule in every mode and made `cd … && grep` prompt even in auto mode\n- Improved structured output: Workflow `agent({schema})` rejects a JSON Schema that can never be satisfied up front, and retry-cap errors now include the last validation failure\n- Improved deleting a background session whose worktree has unpushed commits: the message now names the branch and commit count, and deleting again discards the worktree\n- Improved the Claude apps gateway's refresh-failure log to name the step that failed\n- Improved idle CPU usage of non-interactive (`-p` / SDK) sessions\n- Improved the Claude apps gateway on Amazon Bedrock: input tokens for an aborted request are now counted with AWS's free CountTokens API (grant `bedrock:CountTokens`) instead of a one-token request\n- Improved the settings error for rules such as `Edit(C:\\dir\\(name)\\**)`, where `\\(` is read as an escaped parenthesis rather than a path separator, to suggest an unambiguous spelling\n- Improved auto-compact for 1M-context models: Opus and Fable sessions now compact shortly before the 1M-token limit, and recovery compaction on very large contexts no longer times out at 10 minutes\n- Improved `/ultrareview` and `claude ultrareview` to wait up to 45 minutes (previously 30) for long-running cloud reviews\n- Improved `/effort` on Claude Fable 5.1 so changing effort mid-session no longer invalidates the prompt cache\n- Updated the bundled `claude-api` skill so its Go, Java, and C# samples use current-generation model IDs, and clarified that cheaper worker or sub-agent models should be current-generation too\n- Changed `ctrl+l` / `cmd+k` in fullscreen mode to clear the transcript view like a terminal `clear`; scroll up to see earlier messages\n- Changed permission rules with text after the closing parenthesis (e.g. `Bash(ls) x`), which never matched anything, to be reported as invalid settings instead of being silently ignored\n- Changed server-managed settings so a managed CLAUDE.md (`claudeMd`) no longer triggers the security approval dialog; hooks, shell-command, sandbox, and unsafe `env` settings still require approval\n- Changed Claude in Chrome to follow your organization's Claude in Chrome admin setting; when an admin turns it off, `--chrome`, `/chrome` and the browser tools are unavailable\n- Changed Claude apps gateway to send `orgPluginSettings` in the list form read by Claude Desktop 1.15200.0 and later; older desktops ignore it\n- Changed Claude apps gateway to also refuse to start, naming the field, when a `desktop` policy misspells a field in a nested object of a `managedMcpServers` or `orgPluginSettings` entry\n- Changed commands typed at the `!` bash-mode prompt to run outside the sandbox even when strict sandbox mode (`sandbox.allowUnsandboxedCommands: false`) is on, like typing into your own terminal\n- Changed self-hosted runner `--kill-session-after-min` to release a session that is only waiting on its user (paused, resumable on the next message) instead of killing it and reporting a failure\n- Removed the one-hour time limit on background commands started by subagents; they now run until they exit or are stopped, matching the main session\n- [VSCode] Added the selected effort level to the footer model pill, fixed a stale effort level after switching models, and returned the footer pills to their earlier compact size\n- [VSCode] Added Open and Closed to the session list's status filter menu\n- [VSCode] Fixed the welcome screen disappearing in a new session when Remote Control turns on automatically\n- [VSCode] Fixed the session history picker loading a session a second time when it is already open in another tab; it now switches to that tab\n- [VSCode] Fixed the session tab's Rename command silently doing nothing while the tab's view was reloading; it now always applies\n- [VSCode] Fixed a half-finished message, an empty tool card or an extra \"Thought for\" line staying on screen after Claude Code retried a dropped response\n- [VSCode] Fixed \"Enable Remote Control for all sessions\" not applying to a session tab that was still starting when the toggle was flipped","body_html":null,"content_hash":"9abfaa22e42375fac1646f2475a27e3ab9fc6dcaa010859a06515b6ddf460994","updated_at":"2026-10-05T19:08:46.471Z"},{"id":"91a6c7ce-bfed-4236-9e99-7aeb76b07ade","source_id":"claude-code","dedupe_key":"claude-code:2.1.259","version":"2.1.259","title":"claude code 2.1.259","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21259","published_at":"2026-09-02T21:21:42.115Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added `managedMcpServers` managed setting: organizations can provide HTTP/SSE MCP servers to every user (same entry shape as `.mcp.json`); entries that name a command to run are skipped\n- Added `--permission-prompts none` for unattended headless hosts: anything that would prompt is denied automatically while the active permission mode (including auto mode) keeps deciding\n- Added recognition of `glab mr create/merge/close/reopen/note/update` so GitLab merge requests show as `MR !N` in the collapsed tool summary and refresh the footer MR badge\n- Added `--json` to `claude plugin validate` for a machine-readable validation report\n- Fixed concurrent sessions silently reverting each other's `~/.claude.json` changes — workspace trust no longer resets and MCP/project state is no longer lost when running many sessions at once\n- Fixed a conversation whose thinking was rejected once being rejected again on every later turn\n- Fixed Bash `Read()` deny rules not covering files given as option values (`--ignore-revs-file=.env`, `-f.env`, `@file`), `git diff`/`git grep` file operands, or `cd DIR && cat FILE` compounds; `grep -r`/`cp -r` over a directory holding a denied file now asks\n- Fixed the prompt cache being invalidated when the OAuth token refreshed in sessions with telemetry disabled\n- Fixed fullscreen mode showing a blank conversation after a long turn with hundreds of tool calls\n- Fixed auto mode running a turn on a model it doesn't support when a command or skill's frontmatter `model:` named one; the turn now keeps the session model\n- Fixed `CLAUDE_CODE_MAX_CONTEXT_TOKENS` being ignored for Vertex-style model IDs (`@YYYYMMDD` suffix) of model versions Claude Code doesn't recognize\n- Fixed the live output preview of a running shell command hiding its newest lines when an earlier line wrapped\n- Fixed a background GitHub connection check that ran on every launch for claude.ai users; the result is now remembered across launches\n- Fixed `--resume` failing (and `--continue` opening an empty conversation) when a saved session contains an attachment entry with no payload\n- Fixed frontmatter `model:` on custom commands and skills being ignored in interactive sessions\n- Fixed Artifact publishing failing once with an \"unexpected parameter `note`\" error in conversations continued from an older version\n- Fixed managed `forceRemoteSettingsRefresh` being ignored at startup when a policy helper configured by MDM or the managed settings file had already run\n- Fixed worktree isolation refusing hook-created worktrees on machines where `git rev-parse` fails with a message other than \"not a git repository\"\n- Fixed OpenTelemetry metrics and events from cloud sessions missing the `user.email`, `organization.id`, and `user.account_uuid` attributes\n- Fixed MCP servers that disconnect while their tools are being listed at startup showing as connected with no tools instead of reporting the error\n- Fixed the file edit permission dialog sometimes showing a changed line cut short with no indication\n- Fixed repository detection dropping a known repo identity after a transient git probe failure\n- Fixed managed settings silently going unenforced when the managed-settings file, a drop-in, the MDM plist, or the HKLM value cannot be parsed: Claude Code now refuses to start and names the source\n- Fixed Stop not actually stopping background agents and workflows in remote-control sessions: killed tasks now stay visible and re-stoppable until their processes exit\n- Fixed resuming a workflow run while its previous stopped run was still exiting, which could run duplicate copies of its agents\n- Fixed marketplace repo URLs on github.com with a trailing slash or dangling `?`/`#` producing an unusable `.git` clone URL\n- Fixed blocking Stop hooks causing the turn after a block to lose the model's reasoning from that turn and, on some models, miss the prompt cache\n- Fixed remote (claude.ai) sessions taking 60 seconds to start a turn after a browser-hosted MCP server's page had gone away\n- Fixed worktree-isolated sessions refusing common Bash loops, xargs pipelines and launcher-wrapped commands that cannot reach the main checkout\n- Improved terminal resize and first-render performance for long responses by reusing text measurements\n- Improved `/workflows` agent detail: JSON outcomes are pretty-printed with syntax colors and real line breaks, and long outcomes fold behind an expand toggle\n- Improved headless/SDK session start: the first turn begins up to 50 ms sooner when MCP servers finish connecting\n- Improved `/install-github-app` to explain it is GitHub-only and point to the GitLab CI/CD docs when run inside a GitLab repository\n- Improved nested background subagent results to be saved in the parent subagent's transcript, so resumed subagents keep them and shared transcripts show the delivery\n- Changed `allowedMcpServers` to govern only servers users add: a literal `managed-mcp.json` server your allowlist used to filter out now loads on upgrade; use `deniedMcpServers` to keep it off\n- [VSCode] Added an Active quick filter and a status filter menu (Needs input, Working, Completed) to the session list sidebar\n- Fixed remote and scheduled sessions doing nothing after a connector-tool permission prompt was approved while the session was paused","body_html":null,"content_hash":"6946b4951b7db81b93dbcbe6b0f8669261103a8d15fd9a0269a4cc33bfd16e5b","updated_at":"2026-10-05T19:08:46.471Z"},{"id":"b64330a8-aa48-49d4-94bf-bc20d8366017","source_id":"grok","dedupe_key":"grok:grok-imagine-image-quality-retirement-on-november-2","version":"update","title":"grok-imagine-image-quality retirement on November 2","url":"https://docs.x.ai/developers/release-notes#grok-imagine-image-quality-retirement-on-november-2","published_at":"2026-09-02T00:00:00.000Z","date_reconciled":1,"digest_import":1,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T18:08:02.751Z","body_md":"On November 2, 2026, grok-imagine-image-quality is retired. Requests to the slug will be served by grok-imagine-image-2.0 with quality set to low, with no change to the request or response shape and at a lower per-image price. grok-imagine-image (1.0) is not affected. See the migration guide.","body_html":"<p>On November 2, 2026, <code>grok-imagine-image-quality</code> is retired. Requests to the slug will be served by <code>grok-imagine-image-2.0</code> with <code>quality</code> set to <code>low</code>, with no change to the request or response shape and at a lower per-image price. <code>grok-imagine-image</code> (1.0) is not affected. See the <a href=\"https://docs.x.ai/developers/migration/imagine-image-quality-nov-2\">migration guide</a>.</p>","content_hash":"371a4c1859b8e4da442d193288437a55003ab4c84c18c4ab1366e4229eb616d7","updated_at":"2026-10-05T19:07:39.171Z"},{"id":"8306573e-5571-45fa-ad45-2aa326cd0fa1","source_id":"cursor","dedupe_key":"cursor:https://cursor.com/changelog/self-hosted-machines","version":"Self-hosted machines","title":"Self-hosted machines","url":"https://cursor.com/changelog/self-hosted-machines","published_at":"2026-09-02T00:00:00.000Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.651Z","body_md":null,"body_html":"<p><a href=\"/changelog/self-hosted-machines\">Sep 2, 2026</a> · <a href=\"/changelog\">Changelog</a></p><h1><a href=\"/changelog/self-hosted-machines\">Self-hosted machines</a></h1><p>Cursor supports <strong>self-hosted machines</strong>, which let you keep tool execution entirely in your own network.</p>\n<p>Your codebase, build outputs, and secrets all stay on internal machines running in your infrastructure, while the agent handles tool calls locally.</p>\n<img alt=\"Run on menu showing Remote Machines with self-hosted options lambda-test, cloud-demo, and jacks-desktop\" src=\"/marketing-static/_next/image?url=https%3A%2F%2Fptht05hbb1ssoooe.public.blob.vercel-storage.com%2Fassets%2Fuploads%2Fremote-machines-QjJ0ZzGDelSdT7v2CXDdh0BQHqjmH0.png&amp;w=1920&amp;q=70\">\n<h2><a href=\"#dynamic-pool-scheduling\">#</a>Dynamic pool scheduling</h2>\n<p><strong>My Machines</strong> connects a single laptop or VM to your account for personal workflows.</p>\n<p><strong>Team pools</strong> are named queues of workers for a team or enterprise. Capacity can grow as requests arrive and shrink when workers disconnect, so your self-hosted machines can scale with demand. Pools are not tied to one repository: name the pool, and any available worker can claim the request.</p>\n<p>Pools can also hibernate idle machines, then restore within a reconnect window when a follow-up arrives, so you don&#x27;t keep expensive capacity warm just for the next prompt.</p>\n<img alt=\"Cloud Agents dashboard listing Self-hosted Machines pools with active and idle worker counts\" src=\"/marketing-static/_next/image?url=https%3A%2F%2Fptht05hbb1ssoooe.public.blob.vercel-storage.com%2Fassets%2Fuploads%2Fpools-mNNea8rJyNxaBuz7rSVT2SJOKkRsmv.png&amp;w=1920&amp;q=70\">\n<h2><a href=\"#run-on-your-sandboxes\">#</a>Run on your sandboxes</h2>\n<p>Cloud agents can now execute on <a href=\"https://cursor.com/docs/cloud-agent/self-hosted/integrations\">infrastructure you already use</a>, including from AWS Lambda, Coder, Cloudflare, Daytona, Modal, Namespace, Vercel, and E2B.</p>\n<h2><a href=\"#computer-use-on-linux-and-mac\">#</a>Computer use on Linux and Mac</h2>\n<p>Self-hosted workers now support computer use on Linux and Mac. With the right desktop packages, an agent can click, type, take screenshots, and drive the browser. You can watch its desktop or take control from Cursor.</p>","content_hash":"02871186c80a71486245e7171d141b802699bb2ae7871f35fb64d7dd3f956256","updated_at":"2026-10-05T18:59:33.143Z"},{"id":"8cc3cf9b-d0e0-40e9-97e0-f471f2a89a6d","source_id":"claude-code","dedupe_key":"claude-code:2.1.258","version":"2.1.258","title":"claude code 2.1.258","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21258","published_at":"2026-09-01T22:25:07.449Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Fixed Claude Code failing to launch on macOS 12 (Monterey), a regression introduced in 2.1.255\n- Fixed remote and scheduled sessions failing with \"user messages must have non-empty content\" after a re-sent permission approval could not be applied","body_html":null,"content_hash":"de1ac41bc76e91fe3c5dc045882a5466697936a0cf8316f6ba9eccb1e4db9471","updated_at":"2026-10-05T19:08:59.698Z"},{"id":"a644ac8b-473d-4589-a52f-92e5c02c5377","source_id":"claude-code","dedupe_key":"claude-code:2.1.257","version":"2.1.257","title":"claude code 2.1.257","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21257","published_at":"2026-09-01T17:15:33.223Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added Claude Fable 5.1 (`claude-fable-5-1`), now the default Fable model — 1M context, $10/$50 per Mtok with $0.25/Mtok cache reads\n- Added \"Time format\" (`timeFormat`) and `timeZone` settings: 12-hour, 24-hour, 24-hour UTC, or a strftime pattern for the turn-end clock and transcript-view timestamps\n- Added a Containment Escape rule to auto mode so cloud metadata-credential fetches, egress evasion, and cross-tenant reach are no longer auto-approved unless your environment marks them expected\n- Added `CLAUDE_CODE_SUBAGENT_MODEL_FORCE` to apply `CLAUDE_CODE_SUBAGENT_MODEL` (or the main model) to every subagent, ignoring per-spawn and agent-definition model overrides\n- Added `s` in `/effort` to change effort for the current session only, matching `/model`\n- Added a `/doctor` warning for stale sandbox mask files left by a killed session\n- Added a one-time prompt in auto mode before the first file read outside the working directories, with the option to block such reads (`permissions.blockReadsOutsideWorkingDirectories`)\n- Added support for a gateway-supplied `description` on discovered `/model` picker entries (`CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY`); entries without one still read \"From gateway\"\n- Fixed settings in a `.claude/` folder created after startup not being picked up until restart\n- Fixed sessions dispatched from an agent view opened with `←` always starting in the original session's permission mode, overriding the target directory's `defaultMode` and the agent's `permissionMode`\n- Fixed `keybindings.json` rebinds of Ctrl+G being ignored in `claude agents`; its Ctrl+S / Ctrl+T are now rebindable via the new `Agents` context\n- Fixed background sessions failing to start on macOS npm installs during a self-update, and on Windows when a stale daemon lock file pointed at a reused process id\n- Fixed the working spinner stopping while a response streams behind a slash-command panel\n- Fixed a background session's `state.json` `detail` repeating its own dispatch prompt after a scheduled wake-up\n- Fixed `claude agents` keeping a background session you re-prompted buried in Completed after it finished again; Completed now orders by the latest finish\n- Fixed `claude --bg` from a directory that was just deleted reporting \"backgrounded\" and leaving a crashed session row; it now prints the reason and exits 1\n- Fixed Remote Control connecting mid-session re-sending the Bash tool definition, causing a prompt-cache miss\n- Fixed a doubly-listed custom `Authorization` header overriding the configured credential on Bedrock, Mantle, Vertex, and WIF, and the Vertex setup wizard picking up a leftover Anthropic profile from `~/.config/anthropic`\n- Fixed Claude apps gateway sending stray host `Authorization` or profile headers to Foundry, Vertex, and Bedrock, and Foundry Entra ID upstreams not starting when `ANTHROPIC_FOUNDRY_API_KEY` is set\n- Fixed a leftover Anthropic API key or auth token being sent alongside your Foundry subscription key in API-key mode\n- Fixed `/schedule` routines whose prompt was saved without a message role and then ran with nothing to do\n- Fixed `claude agents` not saying that a background session is waiting for you to approve a message from another session, or who sent it\n- Fixed a prompt stashed with Ctrl+S inside an opened background session being lost when the session went idle or was stopped and then reopened\n- Fixed telemetry (OTEL) settings pushed through server-managed settings being ignored on warm starts, including desktop-app Code sessions\n- Fixed a teammate permission request being answered twice when the leader's mailbox write was briefly locked\n- Fixed a phantom duplicate slash-command row rendering below the in-flight turn while a command's auto-continued response streamed\n- Fixed `policyHelper` `timeoutMs` and `refreshIntervalMs` values above the timer maximum (2147483647) causing failures or re-runs every millisecond; they are now clamped\n- Fixed the token counter freezing or crawling after switching to another subagent's transcript, and made background subagents' and teammates' counters update live while a response streams\n- Fixed sandbox network hosts written with a trailing dot (`example.com.`): a `deniedDomains` entry didn't block the host inside the sandbox, and \"don't ask again\" for such a host kept prompting\n- Fixed dismissing the Remote Control consent prompt (Esc, or `n` at `claude remote-control`) counting as consent, so the next request connected without asking\n- Fixed `/mcp` reconnect and enable still connecting a settings-file MCP server that a managed MCP allow/deny list or `strictPluginOnlyCustomization` loaded after startup should block\n- Fixed `claude mcp remove` leaving a remote server's stored OAuth credentials behind when `strictPluginOnlyCustomization` locks MCP to plugin-only servers\n- Fixed Remote Control (`claude remote-control`) sessions started from the Claude app ignoring the selected model and running on the machine's default instead\n- Fixed `--disallowedTools` and session deny rules being dropped after the first settings reload when `allowManagedPermissionRulesOnly` is enabled\n- Fixed `--resume` listing a backgrounded conversation twice and `--continue` reopening its stalled pre-background copy; `--continue` now also opens finished background sessions\n- Fixed fullscreen mode not letting you click `!` shell command output to expand it\n- Fixed background sessions left running an older Claude Code binary piling up across auto-updates instead of being retired\n- Fixed `claude agents --json` briefly switching the terminal to raw mode and undoing another program's terminal settings on exit\n- Fixed Proactive output style sessions busy-looping with filler messages and repeated log reads instead of idling while a background command or Monitor they started is still running\n- Fixed subagents stopping when a response was cut off mid-stream by a computer sleep, dropped connection, or server error; they now automatically continue instead of ending with an incomplete response\n- Fixed `←` doing nothing in the `/btw` panel inside a `claude agents` session: it now returns to the agents list (even mid-answer), and the panel comes back when you reopen the session\n- Fixed sessions with an advisor model set missing the prompt cache on background requests (compaction, `/recap`, prompt suggestions) and re-sending the full conversation uncached each time\n- Fixed `claude -p` exiting about 5 seconds after its final result while a Monitor the model armed was still running; it now waits for the watch to fire or time out\n- Fixed a `permissions.ask` rule being skipped in auto mode when the matching command ran inside a compound command or subshell, letting it run without the confirmation prompt\n- Fixed plugins being able to read files outside their own directory through a declared command, agent, skill, hooks or other component path that is a symlink; such paths are now refused with an error\n- Fixed `/add-dir` rejecting a directory inside the current working directory; it now loads that directory's skills, commands, and agents like `--add-dir` does at startup\n- Fixed the main agent not being told when you resume a subagent you had stopped from its transcript view\n- Fixed a crash when pasting ANSI-colored text (e.g. a CI log) into dialogs like `/feedback`\n- Fixed `claude mcp add/remove` hanging or exhausting memory when the project's `.mcp.json` is a FIFO or a device-file symlink; it now fails fast with an actionable message\n- Fixed unbounded memory growth when non-JSONL data is piped into `claude -p --input-format stream-json`; it now fails fast with a clear error\n- Fixed backgrounding a turn (`←` or Ctrl+B) while a subagent or other tool was running occasionally making the background session treat that tool as rejected instead of re-running it\n- Fixed Bash `Read()`/`Edit()` deny rules not applying to `< file` redirects and reader commands like `tac` and `egrep`; a deny rule on any argument or redirect target now refuses the command\n- Fixed resuming or messaging a subagent whose transcript had grown past 5 MB (for example after reading many images) failing with \"No transcript found\"\n- Fixed worktree-isolated sessions refusing Bash loops, `$VAR` reads, `\"$(…)\"` and heredocs that never touch git as \"too complex to verify that it stays inside the worktree\"\n- Fixed `/model` and `/effort` showing a prompt-cache warning after rewinding a conversation back to empty\n- Fixed prompt-cache misses on every turn in long screenshot-heavy sessions once images exceeded the per-request size cap\n- Fixed the Edit permission prompt's diff view rendering emoji and multi-code-point characters with incorrect widths\n- Fixed WebSocket MCP server connection failures being logged as \"[object ErrorEvent]\" instead of the underlying error\n- Fixed background sessions failing to open with \"Couldn't start the background service\" while another Claude Code process was downloading an npm update; the start now waits for it\n- Fixed background commands that detach from their shell (for example under `timeout` or `setsid`) surviving a task stop or Claude Code exit\n- Fixed Claude not being told when you stop a background command from the tasks panel or a connected client\n- Fixed stopping a background subagent leaving its monitors running\n- Fixed sandboxed git commands in a linked worktree losing write access to the repository's common `.git` directory after `cd` into a subdirectory\n- Fixed Bedrock and Bedrock Mantle requests going silent during long hidden-thinking phases on Opus 4.7 and later, which let idle timeouts cut the connection; the stream now carries progress events\n- Fixed launching Claude Code after a Claude apps gateway expired or revoked your session: it now says the session ended and offers `/login` instead of reporting a network error\n- Fixed cloud sessions losing git/GitHub credentials for the rest of the session when the session's network proxy failed to start at launch; it now retries in the background and recovers\n- Fixed leftover `cc-daemon-*` folders in the system temp directory after an interrupted background daemon start; the `cleanupPeriodDays` retention sweep now removes them\n- Fixed Bash permission checks auto-approving certain `[[ ]]` conditionals that zsh parses differently from bash; these commands now prompt for approval\n- Fixed the managed-settings approval prompt showing the generic warning instead of its telemetry wording when the settings also turn detailed tracing or raw API body logging off, or trace export on\n- Fixed agent-team teammates in tmux/iTerm2 panes sometimes staying open after acknowledging a shutdown request\n- Fixed the keyless Console sign-in (\"Sign in with your Console account\") not applying your organization's server-managed settings, and `/status` not showing the Organization for that sign-in\n- Improved rendering performance: less re-render work per turn in long conversations, streaming no longer slows down as the reply grows, and background-agent updates no longer re-render the whole screen\n- Improved prompt input responsiveness by reducing per-keystroke rendering work\n- Improved policy helper diagnostics — refresh failures now show in `/status`, declining the managed-settings dialog prints why Claude Code exited, and helper timeouts are reported as timeouts\n- Improved `/code-review --comment` to post findings on GitLab merge requests via `glab mr note` instead of reporting the target as unsupported\n- Improved notifications: an MCP elicitation or permission ask queued under another dialog now sends its idle desktop notification at the same delay as a visible ask\n- Improved verbose/transcript output: async hook completion notices that arrive together now appear on one line instead of one line per hook\n- Improved `claude self-hosted-runner --configure-git` to also enable git push negotiation, so the first push of a new branch from a stale clone uploads only the new commits instead of the whole tree\n- Improved liveness reporting to SDK hosts while a response is held open by gateway keep-alives, so long waits under a raised `CLAUDE_STREAM_IDLE_TIMEOUT_MS` are not mistaken for a hung session\n- Improved MCP connection and OAuth debug/error logs so credentials carried in a server's URL or request headers are redacted\n- Improved `/fork` to keep the original conversation's prompt cache in the new background session: its worktree briefing now arrives as a message instead of a system-prompt change\n- Improved emoji autocomplete to accept the remaining GitHub/Slack shortcode aliases (`:satisfied:`, `:telephone:`, `:collision:`, …)\n- Changed `--effort` to lift a new model's default-effort hold for that session only rather than permanently; an effort picked on claude.ai for a Remote Control session now applies during the hold\n- Changed a `policyHelper` in MDM or `managed-settings.json` shadowed at launch by cached server-managed settings to run (or exit) as soon as the fetch reports them removed, not at the next launch\n- Changed `managedSourcesBehavior: \"merge\"` to take `sandbox.credentials.awsPairs` and `sandbox.ripgrep` whole from the highest managed source that sets them instead of combining the sources' values\n- Changed gateway model discovery (`CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY=1`) to run even when `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC` is set, since it only queries your gateway\n- Changed `claude --resume <session-id> --bg` to continue that session under its own ID when nothing is running it, instead of silently starting a copy; a copy is now announced\n- Changed `/btw` history browsing from `←`/`→` to `Shift+←`/`Shift+→` (or `[`/`]`), stepping through your recent side questions and back to the live answer\n- Changed `defaultMode: \"bypassPermissions\"` in `.claude/settings.json` or `.claude/settings.local.json` to be ignored, like `\"auto\"`; set it in user or managed settings, or pass `--permission-mode`\n- Changed `fable` and `best` in Claude apps gateway sessions to keep resolving to Fable 5 for now, since gateways not yet configured for Fable 5.1 reject it; pick Fable 5.1 in `/model` to use it\n- Changed `--add-dir`, `/add-dir`, and `additionalDirectories` to refuse network paths (UNC shares, `/net/<host>` automounts) with a message before touching them; on Windows use a mapped drive letter\n- Changed Claude apps gateway sign-in and token refresh requests to verify the gateway's pinned TLS certificate, as the managed settings fetch already does\n- Changed Cowork and claude.ai cloud sessions: reading an artifact that isn't yours now always asks you first, even in auto mode\n- Removed the Ctrl+E command explanation on Bash and PowerShell permission prompts\n- [VSCode] Added collapsible ACCOUNT & USAGE and SESSION MANAGER section headers to the session list panel, with the account email, the usage meter, and a View details link opening the usage dialog\n- [VSCode] Added a model pill to the input footer that shows the current model and opens the model picker, with an Effort row and a \"More models\" page\n- [VSCode] Added a collapse toggle to the Ungrouped section of the session list\n- [VSCode] Added output style selection to the command menu, including custom styles\n- [VSCode] Fixed third-party provider deployments (Bedrock, Vertex, and others) still showing claude.ai-only features (remote sessions, dictation, usage) and calling claude.ai with a leftover login\n- [VSCode] Fixed the session list panel's usage meter staying blank after the panel loads; it now shows the last known usage immediately\n- [VSCode] Fixed the \"Enable Remote Control for all sessions\" toggle so turning it on or off applies to sessions that are already open, not only to new ones\n- [VSCode] Fixed screen reader announcements: a control character before a fence or heading no longer drops visible lines from speech, and bold markers spanning a heading are no longer mis-paired\n- [VSCode] Changed the action menu to list slash commands in a filterable \"Slash commands\" dialog instead of inline; picking one runs it; the MCP servers dialog gained the same filter box\n- [VSCode] Changed \"Delete session\" to \"Archive session\": archived sessions move to a collapsible \"Archived sessions\" group at the bottom of the list with an Unarchive action","body_html":null,"content_hash":"0467ba7c5ef1e58943325a54d8554d3aba02642c7f8d811f03f2e604f9d563ca","updated_at":"2026-10-05T19:08:59.698Z"},{"id":"de5e69d6-6cb4-4680-ba8e-d70ab08d324e","source_id":"claude-code","dedupe_key":"claude-code:2.1.252","version":"2.1.252","title":"claude code 2.1.252","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21252","published_at":"2026-08-31T17:07:28.168Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Fixed Bash commands failing with \"task output swap refused (tasks dir moved or linked)\" on some Macs\n- Fixed \"always allow\" not saving in a project that has no .claude/settings.local.json yet\n- Fixed Remote Control sessions hosted by Claude Desktop or VS Code stalling for minutes after a tool finished when the connection to claude.ai was degraded\n- Fixed background task notifications with very large failure output (for example git errors on a full disk) making the conversation exceed the API request size limit","body_html":null,"content_hash":"f3efe085fcb0180e3417412dd3446782cfbc8f250f1cbb5c5f64596fcd25947c","updated_at":"2026-10-05T19:08:59.698Z"},{"id":"60b5606c-9672-4a3e-9163-e9dbea6f01c7","source_id":"claude-code","dedupe_key":"claude-code:2.1.251","version":"2.1.251","title":"claude code 2.1.251","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21251","published_at":"2026-08-28T15:34:26.421Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Added `PreModelSwitch` and `PostModelSwitch` hook events (block, confirm, or annotate a model switch); `SessionStart` resume hooks now receive session staleness and the estimated re-cache cost\n- Added live streaming of a foreground subagent's tool calls and results to Remote Control clients (background subagents, the default, still show status only)\n- Added a Spend limit bar to `/usage` and a `rate_limits.spend_limit` status line field for developers behind a Claude apps gateway with spend limits\n- Added a per-session prompt-cache line to `/cost` (hit ratio, misses, tokens re-cached, warm/cold) and a matching `prompt_cache` object for status line scripts\n- Added `attach`, `logs`, `stop`, `respawn`, and `rm` to `claude --help`; the `--resume` message for a running background session now names the exact `claude attach <id>` command\n- Fixed file tools (Read, Write, Edit) following a symlink swapped inside the working directory after the permission check, which could read or write outside the approved location\n- Fixed plugin commands declared in a marketplace entry being able to point outside the plugin directory; such paths are now rejected with a path-traversal error\n- Fixed project settings being able to enable detailed beta tracing or raw API body logging, and a lower-scope beta tracing endpoint bypassing an OTLP collector pinned by managed settings or a host app\n- Fixed the Workflow tool reading (and quoting in errors) a `scriptPath` outside what the session may read before the permission check ran\n- Fixed Grep and Glob not applying `Read(...)` deny rules to files reached through a symlinked search path\n- Fixed conversations getting stuck on \"text content blocks must be non-empty\" errors after a turn where the model produced only thinking\n- Fixed the first launch on a fresh install starting in default mode instead of auto mode for accounts whose startup default is auto mode\n- Fixed Opus 5 requests failing with \"effort … is not supported when thinking is disabled\" when effort was xhigh/max and thinking was turned off; effort is now sent as `high` in that case\n- Fixed replying to a message Claude Desktop delivered from another session: `SendMessage` to that session id now delivers through Claude Desktop instead of failing with \"not reachable\"\n- Fixed TUI lag with many parallel subagents: per-second progress ticks now replace their predecessor instead of piling up in the transcript\n- Fixed agent teams: a teammate's final answer not reaching the team lead — it now arrives in the idle notification instead of a content-free \"available\" notice\n- Fixed background subagents being unable to reply to a message from an unnamed sibling or parent agent (`from` was the agent type, which is not an address)\n- Fixed managed-settings `disableAutoMode` arriving mid-session not moving an already-running auto-mode session back to default mode\n- Fixed a \"switch to Opus 1M for 5x more context\" tip that appeared even when the current Opus model already has a 1M context window\n- Fixed Claude apps gateway sessions treating a stored Anthropic profile (e.g. a Console sign-in) as active: listing it in `/status` and retrying gateway 401s with it, though requests never use it\n- Fixed cloud sessions telling Claude the model had changed when the host was only setting the session's initial model\n- Fixed Remote Control reporting a failure when an organization's policy disables it; it now shows a single quiet notice instead\n- Fixed `/mcp reconnect` on Remote Control showing a generic withheld-detail error instead of the real remedy when a server was disabled in another session\n- Fixed `--input-format stream-json`: client-injected assistant tool calls sent without a message id were merged into the first one and their results lost, including when resuming older sessions\n- Fixed session transcripts being silently overwritten when a directory change relocated a session onto an existing same-ID transcript\n- Fixed background sessions and their subagents being unable to edit files inside a git worktree they created with `git worktree add`\n- Fixed background sessions occasionally starting without any plugin skills (and staying that way) when another Claude Code process was refreshing the plugin marketplace at the same moment\n- Fixed selecting text in an opened background session inside tmux over SSH: it now copies to the tmux buffer like a foreground session instead of falling back to OSC 52\n- Fixed SDK and cloud sessions hanging indefinitely when an SDK MCP server's handshake acknowledgment was lost; the wait now times out after 70 seconds and marks only that server failed\n- Fixed self-hosted runner leaving a stuck session's Bash tool processes running after the session was force-stopped\n- Fixed `/usage-credits` for Team and Enterprise members whose admin set the org's usage-credit limit to $0: it now offers to ask the admin instead of saying a cap was reached\n- Fixed `--worktree --tmux` with a merge-request number on a gitlab.com origin trying a doomed GitHub-style fetch first instead of fetching the GitLab ref directly\n- Fixed Ctrl+G failing with \"Emacs quit unexpectedly\" in background sessions for editors that open `/dev/tty`, such as `emacs -nw` and `micro`\n- Fixed an `additionalDirectories` entry containing a null byte crashing startup, or breaking `/add-dir` and later settings updates when it came from an SDK host, IDE, or hook; it is now skipped\n- Fixed the MCP server menu's copy shortcut: it now says how the sign-in URL was copied instead of always claiming success\n- Fixed italic text (such as the session recap line) rendering as highlighted blocks in GNU screen and in tmux sessions using a `screen` terminal type\n- Fixed `claude mcp add --header` and `claude mcp add-json` help text naming the wrong transports\n- Fixed `claude ultrareview` and `/ultrareview` waiting the full 30 minutes when the cloud session fails to start; they now stop early and report the reason\n- Fixed Bash permission checks auto-approving commands that assign an arithmetic expression to an integer shell variable (e.g. `OPTIND=1/0`, `RANDOM=2+2`); these now prompt for approval\n- Fixed backgrounded sessions (`←`, `/background`, `--bg`) losing a Vertex/Bedrock gateway (`ANTHROPIC_*_BASE_URL` + `CLAUDE_CODE_SKIP_*_AUTH`) exported in the shell, so every request failed\n- Fixed `claude --bg --model fable` on Max plans stopping to ask for usage credits while the interactive session on the same account still had Fable allowance\n- Fixed the one-time \"make auto mode your default\" offer appearing in unattended sessions (e.g. agent-team teammate panes), where a stray keypress could accept it unread\n- Fixed the managed-settings approval prompt re-appearing after signing in again to the same Claude apps gateway when the settings are unchanged\n- Fixed disabled `/bug` and `/share` reporting that `/feedback` was disabled; tips, `/help`, and refusal messages no longer suggest `/feedback` when an org policy or env var turns it off\n- Fixed cloud session creation advising GitHub setup after a transient GitHub connection failure — the message now says to retry instead\n- Improved CPU usage during turns in interactive sessions by cutting redundant UI re-renders\n- Improved install size: the native binary is about 5 MB smaller\n- Improved cloud sessions: when the session's network proxy drops a connection during a Bash command, the tool result now names the host and reason instead of only \"connection reset\"\n- Improved `/schedule` to explain that MCP servers configured in Claude Code can't be attached to cloud routines, instead of a bare \"No MCP connectors\" message\n- Improved framing of messages from your own subagents: Claude is told the sender is a worker inside this session, not an unrelated Claude session\n- Improved the prompt placeholder to read \"Message @name…\" while viewing a background subagent or fork transcript opened from the subagent panel or `/tasks`\n- Improved sanitization of MCP server names in error messages, menus, and command results\n- Improved Amazon Bedrock session start under `CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST` (e.g. Claude Desktop): a session given a Bedrock model ID or ARN no longer waits for inference-profile discovery\n- Improved the managed settings approval dialog to list only the settings that changed since you last approved them\n- Improved retry when the model's tool call is malformed: the broken output is now dropped from the retry context, including on Bedrock, Vertex, and Foundry\n- Changed `/radio` to be available on Bedrock, Vertex AI, Foundry, and Claude Platform on AWS, and when telemetry is disabled\n- Changed Claude in Chrome so browser actions always go through Claude Code's permission checks, including in sessions with telemetry disabled, which previously used the Chrome extension's own prompts\n- Changed `CLAUDE_CODE_SUBAGENT_MODEL` to set the default subagent model rather than override everything: an agent definition's `model:` and an explicit per-spawn model now take precedence over it\n- Changed the default commit trailer to `Co-Authored-By: Claude Code` when the active model isn't a recognized Claude model (e.g. third-party models behind a custom `ANTHROPIC_BASE_URL`)\n- Changed the default model for seat-based Enterprise subscriptions to Opus 5, matching other premium plans\n- Changed `/effort` to save your default effort level per model, so each model keeps its own setting when you switch\n- Changed analytics to no longer turn off before sign-in solely because managed settings force gateway login (or cannot be read); they stay off once signed in to the gateway or via `DISABLE_TELEMETRY`\n- Changed the footer PR badge on Bedrock, Vertex, and Foundry, and when telemetry is off, to call the GitHub API directly (via `gh auth token`, `GH_TOKEN`, or `GITHUB_TOKEN`) instead of `gh pr view`\n- Changed how Bash command output files are created and read back when commands run in the sandbox, so a sandboxed command cannot redirect or replace them\n- Changed plugin/LSP install suggestions and the auto-mode default offer to wait until you've sent or cleared what you're typing, so the Enter that sends your prompt can't answer them\n- Changed server-managed settings that terminate sandbox TLS, route sandbox traffic through your own proxy, inject credentials, or weaken sandbox isolation to require approval before they apply\n- Changed `ANTHROPIC_CUSTOM_HEADERS` from managed or project settings to require approval when it sets a credential, org/tenant, routing, or API-behavior header (e.g. `Authorization`, `Host`)\n- Changed project-level `.claude/settings.json` `env` to no longer set `CLAUDE_CONFIG_DIR`, `CLAUDE_CODE_TMPDIR`, or `TMPDIR`/`TMP`/`TEMP`; set them in your shell, user, or managed settings instead\n- Removed syntax highlighting for six rarely used languages (1c, gml, isbl, mathematica, maxima, sqf); the binary is 2.5 MB smaller\n- [VSCode] Fixed the sign-in screen's \"Bedrock, Foundry, or Vertex\" button opening the docs at the top of the page instead of the third-party provider setup section\n- [VSCode] Changed the Remote Control banner to a footer pill (shown while Remote Control is on or has failed) that opens the session on claude.ai/code; turn it on or off with `/remote-control`","body_html":null,"content_hash":"5ba786dcb0fcbb9ec2848c72cfbaaefeba1089c3f166e111bf54ce0fa686e4c8","updated_at":"2026-10-05T19:08:59.698Z"}],"cursor":"[0,\"2026-08-28T15:34:26.421Z\",\"60b5606c-9672-4a3e-9163-e9dbea6f01c7\"]"}