[{"id":"db22caa6-2b36-4f75-beb5-6773bfe64bec","source_id":"claude-code","dedupe_key":"claude-code:2.1.289","version":"2.1.289","title":"claude code 2.1.289","url":"https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md#21289","published_at":"2026-10-03T20:12:02.717Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.650Z","body_md":"- Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines\n- Fixed the terminal freezing on short code blocks with many unclosed `<script>` tags or deeply nested `${` substitutions\n- Fixed `Read` deny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink\n- [VSCode] Reverted a 2.1.288 change to `claude auth status` that may have made sign-outs more frequent\n- Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width\n- Fixed `plugin list`, `plugin eval` and `plugin update` showing a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked `--plugin-dir`\n- Fixed installed mods not loading in the first session after an upgrade\n- Fixed a plugin's rows above the prompt showing a stale row while the Background tasks dialog was open in fullscreen\n- Fixed plugin panes drawing nothing when a link used a localhost address, an `@` in its path, an uppercase host or a `file:` path\n- Fixed a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server's sign-in tools\n- Fixed a freeze or forced quit at launch when a plugin drew a Box with a border style the terminal does not know\n- Fixed supervised and background sessions ending when a plugin's on-screen handler threw asynchronously\n- Fixed sessions ending with an interface error when a plugin region with no height kept growing\n- Fixed Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value (e.g. `TZ=\"$HOME\" rm -rf build`) when the sandbox auto-allows commands\n- Fixed a Bash deny or ask rule being skipped under sandbox auto-allow when a bare variable assignment came before the command\n- Fixed `claude plugin validate` skipping the plugin when the folder also holds a marketplace manifest\n- Added `agent.spawn` for teammates, one agent id across plugin hook events, and idle and waiting states in `$.agent.list()`\n- Fixed sessions ending with \"unrecoverable interface error\" when a value a mod's `ui.render` hook wrote made a row throw while drawn; the engine now draws its own row instead\n- Fixed text with a tab, a stray escape and a C1 control, or a short text with a tab and CRLF line endings, drawing over the rows below it\n- Fixed right-aligned content in a mod's pane or band drawing under the close mark or `[-]`, which now also keep one column in from the terminal's edge\n- Fixed a mod's `Client` that fails while drawn taking down everything the mod drew around it; it now fails alone and raises `ui.fault`\n- Fixed `claude plugin validate` failing an Anthropic marketplace's own plugin and listing a clean `plugin.json` in `--json`\n- Fixed a mod's band that fails to draw briefly telling the cards under it to step aside\n- Fixed a failed plugin component showing `Error` or nothing as its reason when the failure carried no message\n- Improved the line a mod's author sees when its band or pane fails to draw: it names the mod and says nothing was drawn\n- Fixed published artifact pages freezing or crashing the reader's browser tab on short code blocks with many unclosed `<script>` tags\n- Fixed a mod's Client region staying failed for the whole session after the terminal threw while drawing it","body_html":null,"content_hash":"3226a716fffa6c02427d0ebb228b2bf94280acccb2336ab3fa0b273566b72fae","updated_at":"2026-10-05T18:14:33.808Z"},{"id":"a5cbab01-e370-4395-9a1a-83b27836ca23","source_id":"codex","dedupe_key":"codex:rust-v0.160.0","version":"0.160.0","title":"0.160.0","url":"https://github.com/openai/codex/releases/tag/rust-v0.160.0","published_at":"2026-10-01T20:19:13Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:38:02.977Z","body_md":"## New Features\n\n- Browse older tasks in the agent command center with a keyboard-accessible “Show more” action. (#49106)\n- Select transcript text and paste with middle-click in fullscreen mode on supported local Linux X11 terminals. (#49112)\n- Start sessions outside a project with workspace defaults when policy permits, and restore saved permissions when resuming. (#49160)\n- Added opt-in Guardian review capabilities to retrieve earlier user instructions and include context from agent handoffs. (#49036, #49057)\n\n## Bug Fixes\n\n- Unsent queued messages now resume after reconnection once uncertain submissions are resolved, avoiding duplicate sends. (#49105)\n- The terminal UI now preserves server provider, reasoning-summary, and verbosity settings and shows the correct sessions in resume and fork history. (#49144, #49161, #49171)\n- Fixed Windows sandbox PowerShell fallbacks and long-path permission repairs, and suppressed unwanted console windows from background helpers. (#49019, #49058, #49098, #49164, #49386)\n- Subagents now retain environments that are still starting and receive their configuration or preparation failure. (#49075)\n- Prevented SQLite stalls during connection setup and logging, and surfaced initialization errors instead of masking them as timeouts. (#49032, #49102)\n- Explicit provider model catalogs no longer include unsupported bundled models or reuse stale entries after refresh failures. (#49135)\n\n## Documentation\n\n- Clarified how provider credentials use the configured storage backend and how `env_key` identifies the API-key environment variable. (#49118)\n\n## Chores\n\n- Reduced repeated plugin-loading work by caching parsed manifests and reusing HTTP connections for remote plugin requests. (#49099, #49100)\n- Added background reclamation of unused log database space to reduce disk usage. (#49069)\n\n## Changelog\n\nFull Changelog: https://github.com/openai/codex/compare/rust-v0.159.0...rust-v0.160.0\n\n- #48983 Avoid full metadata rewrites for thread timestamp updates @jif-oai\n- #49000 Isolate the memory startup metadata test from Git enrichment @jif-oai\n- #49019 Use a compatible PowerShell fallback for the Windows MXC sandbox @iceweasel-oai\n- #49028 Use the numeric ioctl value in the macOS sandbox policy @aionescu-oai\n- #49031 Clarify ChatGPT sign-in success copy @bc-openai\n- #49032 Avoid SQLite stalls from connection setup and stderr span logging @jif-oai\n- #49036 Add opt-in conversation history retrieval to Guardian reviews @felixxia-oai\n- #49037 Show the Plan mode cycling hint in the fullscreen status line @fcoury-oai\n- #49038 Preserve encrypted agent messages in Guardian reviews @felixxia-oai\n- #49041 Copy selections within inline code as plain text @fcoury-oai\n- #49043 Update Pro plan display names in the TUI @etraut-openai\n- #49057 Add handoff-aware root context for Guardian reviews @jif-oai\n- #49058 Fix Windows sandbox ACL repair for long runtime paths @darius-oai\n- #49060 Update Guardian messaging snapshots for native agent messages @dkovalenko-oai\n- #49065 Update Guardian handoff snapshot for separate agent messages @cassirer-openai\n- #49067 Keep configuration values out of Windows sandbox policy events @zm-oai\n- #49069 Reclaim unused SQLite log database pages in the background @dkovalenko-oai\n- #49073 Surface realtime voice catalog failures in the TUI @etraut-openai\n- #49074 Propagate Cargo package versions to Bazel Rust targets @tamird\n- #49075 Preserve pending environments when spawning subagents @sayan-oai\n- #49076 Avoid collecting unused Git metadata in skill analytics @tamird\n- #49079 Update and centralize TUI subscription labels @etraut-openai\n- #49082 Skip remote Git discovery for Guardian diff paths @jif-oai\n- #49084 Track app-server running turns incrementally @tamird\n- #49089 Render follow-up directive labels in the TUI and copied responses @etraut-openai\n- #49093 Simplify startup promotions to platform-specific desktop app tips @etraut-openai\n- #49096 Update `h2` from 0.4.16 to 0.4.19 in Cargo and Bazel lockfiles @cassirer-openai\n- #49097 Notify lifecycle extensions of compaction usage limits @xli-oai\n- #49098 Resolve Windows sandbox PowerShell fallbacks on the exec server @zm-oai\n- #49099 Cache parsed plugin manifests across plugin workflows @dkovalenko-oai\n- #49100 Reuse the HTTP connection pool for remote plugin requests @dkovalenko-oai\n- #49102 Preserve SQLite vacuum modes and surface pool initialization errors @bc-openai\n- #49103 Balance Windows Bazel test shards using duration estimates @jgershen-oai\n- #49105 Resume unsent TUI input after reconnecting @etraut-openai\n- #49106 Add history pagination to the agent command center @bc-openai\n- #49112 Add X11 primary selection and middle-click paste support @fcoury-oai\n- #49114 Point remote compaction tests at the mock ChatGPT server @OLI-OAI\n- #49117 Attribute analytics requests to each thread's product SKU @papayo-oai\n- #49118 Correct provider authentication storage documentation @celia-oai\n- #49119 Add recovery guidance to content-filter retries @won-openai\n- #49127 Deduplicate cloud and executor skill listings before budgeting @TAFOYA-OAI\n- #49130 Move content-filter guidance into the shared Responses retry handler @won-openai\n- #49135 Treat explicit provider model catalogs as authoritative @andrewgu-oai\n- #49136 Remove the plus separator after Option symbols in TUI key hints @bc-openai\n- #49138 Expose original error details to turn lifecycle contributors @bryanashley\n- #49144 Preserve server reasoning summary and verbosity settings in the TUI @etraut-openai\n- #49145 Hide reasoning summary settings in `/status` for server connections @etraut-openai\n- #49147 Simplify cloud task base URL normalization @akira-oai\n- #49153 Omit blockquote markers when copying quoted selections in the TUI @bc-openai\n- #49160 Support projectless TUI sessions with workspace defaults @etraut-openai\n- #49161 Honor app-server provider defaults in the TUI @etraut-openai\n- #49164 Suppress Windows console windows for background subprocesses @etraut-openai\n- #49171 Fix model provider lookup for TUI history @etraut-openai\n- #49386 [0.160] Backport remaining Windows console fix to frozen alpha.6 @andrewgu-oai\n- #49763 [0.160] Backport maintenance-line catalog and security reminder updates @andrewgu-oai\n\n\n","body_html":null,"content_hash":"88f2cf6222ddfcc4ac2535d3475c5d7f28fd90f8fe756a3752378f41eeef853f","updated_at":"2026-10-05T08:38:02.977Z"},{"id":"1db77838-d2df-4fda-baba-5595d424064d","source_id":"cursor","dedupe_key":"cursor:https://cursor.com/changelog/rollouts-and-security-reviewer","version":"Rollouts and Security Review","title":"Rollouts and Security Review","url":"https://cursor.com/changelog/rollouts-and-security-reviewer","published_at":"2026-09-23T00:00:00.000Z","date_reconciled":1,"digest_import":0,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T08:37:53.651Z","body_md":null,"body_html":"<p><a href=\"/changelog/rollouts-and-security-reviewer\">Sep 23, 2026</a> · <a href=\"/changelog\">Changelog</a></p><h1><a href=\"/changelog/rollouts-and-security-reviewer\">Rollouts and Security Review</a></h1><p>Today we&#x27;re launching two Cursor bots for the last mile of shipping code. Rollouts watches every change as it deploys and reports its health per environment. Security Review reports exploitable bugs on every pull request.</p>\n<p>Both are available today on Teams and Enterprise plans.</p>\n<h2><a href=\"#rollouts\">#</a>Rollouts</h2>\n<p>Rollouts attaches a monitor to every pull request and watches the change as it deploys, reporting change health per environment: verified healthy, regression detected, or inconclusive. It&#x27;s the Cursor version of <a href=\"https://cursor.com/blog/firetiger\">Firetiger</a> Change Monitors, rebuilt with the Bot Development Kit.</p>\n\n<p>Enable it from the dashboard and connect source control, your deploy system, and your telemetry provider. Rollouts starts watching on the next pull request.</p>\n<h4><a href=\"#monitoring-plans\">#</a>Monitoring plans</h4>\n<p>When a pull request opens, Rollouts reads the diff and the systems it touches, then writes a monitoring plan as a PR comment. The plan lists the risks it identified, the effect the change is meant to have, the signals it will check, and any gaps in instrumentation that would make the change hard to verify. Edit the plan in the PR and Rollouts uses your version.</p>\n<h4><a href=\"#deploy-tracking\">#</a>Deploy tracking</h4>\n<p>Rollouts wakes on deploy events for the change&#x27;s commit and runs the plan against your logs, metrics, and traces. It tracks each environment separately, so a change can be verified in staging and still flagged in production. Rollouts checks the change&#x27;s intended effect alongside error and latency signals, and reports back on the PR when it reaches a verdict.</p>\n<h4><a href=\"#regressions\">#</a>Regressions</h4>\n<p>When Rollouts detects a regression, it names the change it suspects and notifies the author. Depending on configuration, it can also open a revert PR for review or hand the finding to a cloud agent for a fix. Rollouts does not merge or roll back on its own today.</p>\n<h4><a href=\"#integrations\">#</a>Integrations</h4>\n<p>Rollouts connects to Origin or GitHub for source control, to your continuous delivery system for deploy events, and to Datadog and other telemetry providers for signals. Feature flag integration is coming soon.</p>\n<h2><a href=\"#security-review\">#</a>Security Review</h2>\n<p>Security Review is available today. It reads every pull request in the context of the codebase and posts one review comment reporting exploitable bugs. Style and quality stay with Bugbot.</p>\n<img alt=\"Security Review comment on a pull request reporting an exploitable bug with a severity and proposed fix\" src=\"/marketing-static/_next/image?url=https%3A%2F%2Fptht05hbb1ssoooe.public.blob.vercel-storage.com%2Fassets%2Fchangelog%2Fsecurity-review-N8azgyLevr8FvNIRqJN6hk71os2Oxu.png&amp;w=1920&amp;q=70\">\n<p>Enable it from the dashboard for the repositories you want reviewed. Draft PRs are skipped.</p>\n<h4><a href=\"#what-it-reports\">#</a>What it reports</h4>\n<p>Security Review looks for injection across SQL, command, and template surfaces, along with authentication and authorization bypasses, including checks that a refactor stopped running. It also flags secrets and credentials committed to source, SSRF and unvalidated redirects, unsafe deserialization, and dependency changes that introduce known vulnerabilities. It traces where user input enters and what it passes through.</p>\n<h4><a href=\"#findings\">#</a>Findings</h4>\n<p>Each finding carries a severity, the attack path, and a proposed fix. Dismiss one with a reason and Security Review won&#x27;t raise it again on that PR.</p>\n<h4><a href=\"#team-rules\">#</a>Team rules</h4>\n<p>Add rules for your codebase, such as which client external calls must go through or which tables are never queried from a request handler, and Security Review enforces them on every PR.</p>\n<h2><a href=\"#get-started\">#</a>Get started</h2>\n<p>Rollouts and Security Reviewer are available today on Teams and Enterprise plans. Enable either bot from the <a href=\"https://cursor.com/automations\">automations</a> tab.</p>\n<p>For the next 10 days, we&#x27;re including usage credits so teams can try Rollouts on real changes. Teams and Enterprise customers receive credits for roughly 50 and 500 changes, respectively.</p>","content_hash":"23a86d2ea1f05817b52672361cfac6d319a3f8fcf30f15baa739b8a86caed443","updated_at":"2026-10-05T18:59:33.143Z"},{"id":"47a1f620-187b-4402-9e3f-9c5755e364b4","source_id":"grok","dedupe_key":"grok:grok-voice-transcribe-10-end-of-life","version":"1.0","title":"grok-voice-transcribe-1.0 end of life","url":"https://docs.x.ai/developers/release-notes#grok-voice-transcribe-10-end-of-life","published_at":"2026-10-02T00:00:00.000Z","date_reconciled":1,"digest_import":1,"historical_import":0,"date_kind":"published","first_seen_at":"2026-10-05T18:08:02.751Z","body_md":"grok-voice-transcribe-1.0 is deprecated and reaches end of life on October 2, 2026. All requests to that slug are routed to grok-voice-transcribe-2.0 at the same price, with higher accuracy. See the Speech to Text docs.","body_html":"<p><code>grok-voice-transcribe-1.0</code> is deprecated and reaches end of life on October 2, 2026. All requests to that slug are routed to <code>grok-voice-transcribe-2.0</code> at the same price, with higher accuracy. See the <a href=\"https://docs.x.ai/developers/model-capabilities/audio/speech-to-text\">Speech to Text docs</a>.</p>","content_hash":"64eeebf170952ad398e86083acad8584b533b509fa79a92d01f0f57e3fe5b382","updated_at":"2026-10-05T19:07:18.890Z"}]