Skip to content

build(deps-dev): bump @anthropic-ai/claude-code from 2.1.259 to 2.1.280 - #114

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/anthropic-ai/claude-code-2.1.280
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/anthropic-ai/claude-code-2.1.280

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps @anthropic-ai/claude-code from 2.1.259 to 2.1.280.

Release notes

Sourced from @​anthropic-ai/claude-code's releases.

v2.1.280

What's changed

  • Added Claude Opus 5.5 (claude-opus-5-5), now the default Opus model — 1M context, $4/$20 per Mtok with $0.20/Mtok cache reads
  • Added mouse support to more lists in fullscreen mode: the wheel scrolls the /skills list, and a skill's state options in /plugin can be clicked
  • Added CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTH to change the 2,048-character cap on MCP tool descriptions and server instructions for every MCP server in the session
  • Added hook output sizes and the number of oversized outputs saved to a file to the hook_execution_complete OpenTelemetry event
  • Fixed writes through a symlinked path being judged by their in-tree spelling: the prompt names where the write lands, and acceptEdits, allow rules and auto mode no longer approve one landing outside
  • Fixed auto mode retrying an action over and over when a safety check declined to review it; the action is now denied once, noting that retrying won't help
  • Fixed auto mode denying actions over and over without pause when a safety check gave no answer; retries now back off, and the turn stops with a message after ten in a row
  • Fixed Write calls failing validation when a model sends path, file_text, file_content or a stray description instead of file_path and content
  • Fixed Ctrl+C or Ctrl+D pressed twice in most dialogs (/model, /effort, /config, /status, /usage, /plugin, /sandbox, /permissions, /artifacts, /mobile, /login, /upgrade, /usage-credits, /install-github-app, /setup-bedrock, /setup-vertex) quitting Claude Code instead of closing the dialog
  • Fixed a click that only brought the terminal window to the front also triggering the item under the pointer — in search pickers, tab bars, agent/workflow rows, slash-command links and suggestion dropdowns
  • Fixed a stray n closing dialogs and a stray y confirming them; Enter and Esc accept and cancel (bind y/n to confirm:yes/confirm:no in keybindings.json to restore)
  • Fixed text fields in dialogs losing a typed letter, digit or Space to a keybinding on that key
  • Fixed the prompt line staying scrambled on Windows terminals after invisible characters were removed on Enter; the screen is now repainted so you review the exact text that will be sent
  • Fixed the invisible-character cleanup removing the zero-width non-joiner that Persian and Arabic text uses to attach a suffix to a Latin word or number, such as the plural of "PDF"
  • Fixed voice dictation not stopping on Ctrl+C (the prompt cleared but the microphone kept recording), Esc not cancelling while a transcript was processing, and held Space starting dictation from the transcript view and vim NORMAL mode
  • Fixed a model switch made from a host app (Claude Desktop, VS Code, SDK) while Claude is working causing a prompt-cache miss on the next prompt
  • Fixed resumed fork subagents rebuilding their tool list instead of re-sending the one they first used, which broke prompt caching for that agent
  • Fixed subagent hand-back messages showing an internal provenance preamble when expanded outside verbose mode
  • Fixed installed_plugins.json keeping the install-time commit after updating a plugin from a GitHub repository or git URL that tracks a branch or tag
  • Fixed skills in ~/.claude/skills/ being moved to ~/.claude/skills/.trash/ when a manifest.json in that folder listed their names
  • Fixed the session feedback survey showing no hover highlight on light and ANSI themes
  • Fixed /workflows briefly showing a one-row list before opening the only run
  • Fixed the mouse wheel not scrolling selection lists with hidden options (such as /model and /permissions) in fullscreen mode
  • Fixed a skill you switched off showing the same red ✘ as a plugin that failed to load in /plugin and /skills; off now shows a dim ◯
  • Fixed multi-select option descriptions being indented under the option number instead of under the label
  • Fixed the search box in /plugin, /skills and /mcp losing its right border in fullscreen mode
  • Fixed /mcp showing △ in the server list but ⚠ in the detail view for the same server; the list, detail views and /plugin now all show ⚠
  • Fixed Home and End doing nothing in the /config settings list and in selection lists such as /model, /memory and permission prompts
  • Fixed PgUp/PgDn in the /skills menu wrapping past the first or last skill instead of stopping there
  • Fixed Tab silently changing the selected setting's value in the /config list; it now does nothing there
  • Fixed conversations failing on every turn with a "role 'system' must precede an 'assistant' message" API error
  • Fixed conversations with the advisor on failing every turn with API Error 400 "Input tag 'advisor_20260301'" behind a proxy or gateway that doesn't support it; the request now retries without it
  • Fixed a session failing on every turn and /compact when its saved history held a malformed notice about MCP tools that could not be loaded
  • Fixed a crash when resuming a session whose saved transcript holds a malformed system message or a memory-saved notice without its file list
  • Fixed one cause of long-running fullscreen sessions exiting with "Claude Code exited after an unrecoverable interface error": a damaged cached message list is now rebuilt
  • Fixed Claude Code hanging when a settings file, or a file it re-reads after an edit, is replaced by a named pipe mid-read
  • Fixed /config crashing and some on/off preferences being misread when a preference that has moved to settings.json still holds a value like null or "false" in ~/.claude.json
  • Fixed resuming a session with unfinished background agents, shells or workflows starting a model turn on its own before you typed anything
  • Fixed messages sent to a background subagent being silently lost in headless and SDK sessions when the subagent was finishing its turn
  • Fixed a finished subagent's report being lost when the conversation that launched it was compacted before the report was read
  • Fixed background subagents being unable to use the LSP tool when an LSP plugin is active
  • Fixed background shell tasks reporting benign non-zero exits (e.g. grep with no matches) as failures
  • Fixed background sessions (claude --bg) being unable to run git, hooks, plugins and other helper programs when an environment variable handed to the session contained a NUL character
  • Fixed Ctrl+C needing three or four presses to exit while background subagents are running; two presses now exit
  • Fixed IDE selection being dropped when a sent prompt comes back into the input, such as pressing Esc to edit it, rewinding to it, or pressing Esc while startup hooks run
  • Fixed a ! shell-mode prompt stashed with Ctrl+S coming back as a plain prompt when restored, and / listing file paths right after stashing one
  • Fixed claude agents showing a blank, unresponsive screen instead of an error when the temp directory is full, not writable or owned by another user

... (truncated)

Changelog

Sourced from @​anthropic-ai/claude-code's changelog.

2.1.280

  • Added Claude Opus 5.5 (claude-opus-5-5), now the default Opus model — 1M context, $4/$20 per Mtok with $0.20/Mtok cache reads
  • Added mouse support to more lists in fullscreen mode: the wheel scrolls the /skills list, and a skill's state options in /plugin can be clicked
  • Added CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTH to change the 2,048-character cap on MCP tool descriptions and server instructions for every MCP server in the session
  • Added hook output sizes and the number of oversized outputs saved to a file to the hook_execution_complete OpenTelemetry event
  • Fixed writes through a symlinked path being judged by their in-tree spelling: the prompt names where the write lands, and acceptEdits, allow rules and auto mode no longer approve one landing outside
  • Fixed auto mode retrying an action over and over when a safety check declined to review it; the action is now denied once, noting that retrying won't help
  • Fixed auto mode denying actions over and over without pause when a safety check gave no answer; retries now back off, and the turn stops with a message after ten in a row
  • Fixed Write calls failing validation when a model sends path, file_text, file_content or a stray description instead of file_path and content
  • Fixed Ctrl+C or Ctrl+D pressed twice in most dialogs (/model, /effort, /config, /status, /usage, /plugin, /sandbox, /permissions, /artifacts, /mobile, /login, /upgrade, /usage-credits, /install-github-app, /setup-bedrock, /setup-vertex) quitting Claude Code instead of closing the dialog
  • Fixed a click that only brought the terminal window to the front also triggering the item under the pointer — in search pickers, tab bars, agent/workflow rows, slash-command links and suggestion dropdowns
  • Fixed a stray n closing dialogs and a stray y confirming them; Enter and Esc accept and cancel (bind y/n to confirm:yes/confirm:no in keybindings.json to restore)
  • Fixed text fields in dialogs losing a typed letter, digit or Space to a keybinding on that key
  • Fixed the prompt line staying scrambled on Windows terminals after invisible characters were removed on Enter; the screen is now repainted so you review the exact text that will be sent
  • Fixed the invisible-character cleanup removing the zero-width non-joiner that Persian and Arabic text uses to attach a suffix to a Latin word or number, such as the plural of "PDF"
  • Fixed voice dictation not stopping on Ctrl+C (the prompt cleared but the microphone kept recording), Esc not cancelling while a transcript was processing, and held Space starting dictation from the transcript view and vim NORMAL mode
  • Fixed a model switch made from a host app (Claude Desktop, VS Code, SDK) while Claude is working causing a prompt-cache miss on the next prompt
  • Fixed resumed fork subagents rebuilding their tool list instead of re-sending the one they first used, which broke prompt caching for that agent
  • Fixed subagent hand-back messages showing an internal provenance preamble when expanded outside verbose mode
  • Fixed installed_plugins.json keeping the install-time commit after updating a plugin from a GitHub repository or git URL that tracks a branch or tag
  • Fixed skills in ~/.claude/skills/ being moved to ~/.claude/skills/.trash/ when a manifest.json in that folder listed their names
  • Fixed the session feedback survey showing no hover highlight on light and ANSI themes
  • Fixed /workflows briefly showing a one-row list before opening the only run
  • Fixed the mouse wheel not scrolling selection lists with hidden options (such as /model and /permissions) in fullscreen mode
  • Fixed a skill you switched off showing the same red ✘ as a plugin that failed to load in /plugin and /skills; off now shows a dim ◯
  • Fixed multi-select option descriptions being indented under the option number instead of under the label
  • Fixed the search box in /plugin, /skills and /mcp losing its right border in fullscreen mode
  • Fixed /mcp showing △ in the server list but ⚠ in the detail view for the same server; the list, detail views and /plugin now all show ⚠
  • Fixed Home and End doing nothing in the /config settings list and in selection lists such as /model, /memory and permission prompts
  • Fixed PgUp/PgDn in the /skills menu wrapping past the first or last skill instead of stopping there
  • Fixed Tab silently changing the selected setting's value in the /config list; it now does nothing there
  • Fixed conversations failing on every turn with a "role 'system' must precede an 'assistant' message" API error
  • Fixed conversations with the advisor on failing every turn with API Error 400 "Input tag 'advisor_20260301'" behind a proxy or gateway that doesn't support it; the request now retries without it
  • Fixed a session failing on every turn and /compact when its saved history held a malformed notice about MCP tools that could not be loaded
  • Fixed a crash when resuming a session whose saved transcript holds a malformed system message or a memory-saved notice without its file list
  • Fixed one cause of long-running fullscreen sessions exiting with "Claude Code exited after an unrecoverable interface error": a damaged cached message list is now rebuilt
  • Fixed Claude Code hanging when a settings file, or a file it re-reads after an edit, is replaced by a named pipe mid-read
  • Fixed /config crashing and some on/off preferences being misread when a preference that has moved to settings.json still holds a value like null or "false" in ~/.claude.json
  • Fixed resuming a session with unfinished background agents, shells or workflows starting a model turn on its own before you typed anything
  • Fixed messages sent to a background subagent being silently lost in headless and SDK sessions when the subagent was finishing its turn
  • Fixed a finished subagent's report being lost when the conversation that launched it was compacted before the report was read
  • Fixed background subagents being unable to use the LSP tool when an LSP plugin is active
  • Fixed background shell tasks reporting benign non-zero exits (e.g. grep with no matches) as failures
  • Fixed background sessions (claude --bg) being unable to run git, hooks, plugins and other helper programs when an environment variable handed to the session contained a NUL character
  • Fixed Ctrl+C needing three or four presses to exit while background subagents are running; two presses now exit
  • Fixed IDE selection being dropped when a sent prompt comes back into the input, such as pressing Esc to edit it, rewinding to it, or pressing Esc while startup hooks run
  • Fixed a ! shell-mode prompt stashed with Ctrl+S coming back as a plain prompt when restored, and / listing file paths right after stashing one
  • Fixed claude agents showing a blank, unresponsive screen instead of an error when the temp directory is full, not writable or owned by another user
  • Fixed an MCP server re-added under the same name after claude mcp remove still showing as needing authentication instead of reconnecting

... (truncated)

Commits
  • 56f3653 chore: Update CHANGELOG.md and feed.xml
  • b486776 Merge pull request #95932 from anthropics/add-github-connection-issue-template
  • 411c240 Add issue template for GitHub connection problems on claude.ai
  • 8187baa chore: Update CHANGELOG.md and feed.xml
  • 7974a70 diff: a resumed session with edits opens the pane before any new edit, /clear...
  • 4564326 telemetry: complete rows gathered through $, sent in batches, serving built-i...
  • bf7d404 chore: Update CHANGELOG.md and feed.xml
  • 92ec78f diff: a docked pane reads the repository before it opens, so it never lands o...
  • 2287e5d diff: the first edit opens the pane only from the main loop with checkpointin...
  • 6ce37e9 mods/diff: type openPane's answer as unknown so a richer $.ui.open result com...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@anthropic-ai/claude-code](https://github.com/anthropics/claude-code) from 2.1.259 to 2.1.280.
- [Release notes](https://github.com/anthropics/claude-code/releases)
- [Changelog](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-code@v2.1.259...v2.1.280)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/claude-code"
  dependency-version: 2.1.280
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a routine Dependabot patch bump of the @anthropic-ai/claude-code devDependency (2.1.259 → 2.1.280), touching only package.json/package-lock.json. It is the npm-ecosystem package, not the pinned anthropics/claude-code-action upstream SHA, so the dependabot workflow's "investigate" step is correctly skipped for it and this is a plain review.

Should fix

  • package.json:43 — the allowScripts entry approving this package's postinstall script is still keyed to the old version (@anthropic-ai/claude-code@2.1.259). Per this repository's own commit history, that field exists to satisfy npm 12's lifecycle-script gate and is keyed by exact version, so the approval doesn't carry forward to 2.1.280 — it needs the same version bump the dependency itself just got. Suggestion included inline.

Title and description are the standard, complete Dependabot-generated content — no changes needed there. Nothing else in the diff to flag.

@github-actions

Copy link
Copy Markdown

🗜️ Headroom context compression

Metric Value
Requests proxied 39
Tokens saved 210822
Aggregate savings 5.9% of all tokens sent
Average per-request compression 7.7%

@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #117.

@dependabot dependabot Bot closed this Oct 1, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/anthropic-ai/claude-code-2.1.280 branch October 1, 2026 14:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants