build(deps-dev): bump @anthropic-ai/claude-code from 2.1.259 to 2.1.281 - #117
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@anthropic-ai/claude-code](https://github.com/anthropics/claude-code) from 2.1.259 to 2.1.281. - [Release notes](https://github.com/anthropics/claude-code/releases) - [Changelog](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md) - [Commits](anthropics/claude-code@v2.1.259...v2.1.281) --- updated-dependencies: - dependency-name: "@anthropic-ai/claude-code" dependency-version: 2.1.281 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Routine Dependabot bump of @anthropic-ai/claude-code (2.1.259 → 2.1.281), a devDependency only — package.json/package-lock.json changes are otherwise mechanical and correctly paired. One real gap found, so requesting changes:
- Should fix [policy] —
package.json:43'sallowScriptsentry is still keyed to the old exact version (@anthropic-ai/claude-code@2.1.259), so it won't cover2.1.281's postinstall script under npm 12's lifecycle-script allow-list once this merges..github/workflows/dependabot.yml'sinvestigatejob runsnpm cithennpx claudeagainst this exact package right after, so this is a real functional risk, not just a stale record. See the inline comment for detail and the one-line fix.
Title and description are already complete (Dependabot's own standard release-notes body) — left untouched. Nothing else to flag; didn't check whether 2.1.281's own release notes (MCP/elicitation, settings.json attribution flag, etc.) imply any adaptation here, since that's exactly what .github/workflows/dependabot.yml's own investigate job is designed to do separately for the anthropics/claude-code-action upstream bump — not applicable to this npm-ecosystem bump.
| }, | ||
| "devDependencies": { | ||
| "@anthropic-ai/claude-code": "2.1.259", | ||
| "@anthropic-ai/claude-code": "2.1.281", |
There was a problem hiding this comment.
Should fix [policy] — the allowScripts entry at package.json:43 is still pinned to the old exact version:
"allowScripts": {
"@anthropic-ai/claude-code@2.1.259": true
}That field was added deliberately in 2d35b3f to approve this package's postinstall script under npm 12's lifecycle-script allow-list (keyed by exact package@version, per npm's allow-scripts config added in 11.20.0/12.1.0) — "npm 12's lifecycle-script gate now blocks by default" per that commit's own message. Since this PR bumps the dependency to 2.1.281 but doesn't add a matching "@anthropic-ai/claude-code@2.1.281": true entry, the new version's postinstall script will no longer match the allow-list on the next clean install.
This isn't just cosmetic: .github/workflows/dependabot.yml's investigate job runs npm ci and then invokes this exact CLI via npx claude immediately afterwards (the comment there notes the CLI is installed as an ordinary devDependency by npm ci above), so a blocked postinstall could affect that job as soon as this merges and a future Dependabot bump re-triggers it.
Can't offer a one-click suggestion here since line 43 falls outside this diff's hunk, but the fix is to bump the key alongside the version:
"allowScripts": {
"@anthropic-ai/claude-code@2.1.281": true
}|
🗜️ Headroom context compression
|
|
Superseded by #118. |
Bumps @anthropic-ai/claude-code from 2.1.259 to 2.1.281.
Release notes
Sourced from @anthropic-ai/claude-code's releases.
... (truncated)
Changelog
Sourced from @anthropic-ai/claude-code's changelog.
... (truncated)
Commits
d78be94chore: Update CHANGELOG.md and feed.xml56f3653chore: Update CHANGELOG.md and feed.xmlb486776Merge pull request #95932 from anthropics/add-github-connection-issue-template411c240Add issue template for GitHub connection problems on claude.ai8187baachore: Update CHANGELOG.md and feed.xml7974a70diff: a resumed session with edits opens the pane before any new edit, /clear...4564326telemetry: complete rows gathered through $, sent in batches, serving built-i...bf7d404chore: Update CHANGELOG.md and feed.xml92ec78fdiff: a docked pane reads the repository before it opens, so it never lands o...2287e5ddiff: the first edit opens the pane only from the main loop with checkpointin...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)