Skip to content

build(deps-dev): bump @anthropic-ai/claude-code from 2.1.259 to 2.1.281 - #117

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/anthropic-ai/claude-code-2.1.281
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/anthropic-ai/claude-code-2.1.281

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps @anthropic-ai/claude-code from 2.1.259 to 2.1.281.

Release notes

Sourced from @​anthropic-ai/claude-code's releases.

v2.1.281

What's changed

  • Added Claude apps gateway support for newer Claude Desktop keys in desktop policy blocks, including blockReadsOutsideWorkingDirectories and disableBypassPermissionsMode
  • Added assume_role on Claude apps gateway Bedrock upstreams: the gateway calls Bedrock as an IAM role it assumes through STS, in another AWS account if needed, optionally one session per developer
  • Added guardrail: {id, version} on Claude apps gateway Bedrock upstreams to apply an Amazon Bedrock guardrail to every request sent through them (set it on all Bedrock upstreams or none)
  • Added telemetry.resource_attributes to the Claude apps gateway config, to put fixed labels on the telemetry of Claude Desktop and /login sessions
  • Added "attribution": false in settings.json to hide all commit and PR attribution; older CLI versions skip a settings file that holds it, so keep the object form in files shared across versions
  • Added MCP URL-mode elicitation on 2026-07-28 protocol connections, so servers can ask Claude Code to open a browser-based flow; no waiting dialog is left on screen when the server has no way to confirm completion
  • Added MCP server checks to claude plugin validate: it reports .mcp.json entries that would be silently dropped at load, undeclared ${user_config.*} references, and insecure URLs
  • Added an auto mode recommendation to /insights that estimates how many permission prompts auto mode could have handled in your recent sessions
  • Added a scrollbar to the /skills, /mcp and /plugin Installed lists in fullscreen mode, like the one /workflows now has: it appears while the mouse is over the list and can be clicked or dragged
  • Fixed a crash ("unrecoverable interface error") that could end a session while an API request was being retried
  • Fixed a turn that could retry indefinitely, ignoring --max-turns, when the model alternated unparseable tool calls and output-limit truncation
  • Fixed resumed sessions re-sending earlier turns in a changed form (a parallel tool-call turn, an MCP tool call's input or a tool-search result while its server was still reconnecting, or a tool-search result whose loading turn was interrupted), which could make the API drop the conversation's prior reasoning
  • Fixed resuming a very large session sometimes restoring only its last few messages
  • Fixed a session resumed after a restart during a pending permission prompt sending a different history than before, which broke the prompt cache from that point
  • Fixed resuming a session that ended during a tool call: Claude now sees the call and is told its outcome is unknown, and a manual resume no longer adds a hidden "Continue" message
  • Fixed sessions with an earlier advisor result the API could no longer read failing one request every turn and repeatedly losing earlier reasoning; the history is now repaired once
  • Fixed the prompt cache being lost when an MCP server disconnects mid-conversation, or is still connecting after a resume, while tool search is off (for example behind a proxy or gateway)
  • Fixed responses cut short by a proxy or gateway that closes the stream cleanly being shown as complete with no warning, and tool calls running twice on duplicated stream events
  • Fixed responses failing with "Content block not found" when a proxy drops a stream event mid-response; the partial response is now kept, and web search keeps results that already arrived
  • Fixed an empty completed response being requested twice when the connection dropped before the stream's final event
  • Fixed the stop reason being lost when a proxy sends a trailing usage-only frame
  • Fixed CLAUDE_CODE_RETRY_WATCHDOG sessions failing on the first 5xx or dropped connection after a run of 429/529 waits, and sleeping uncapped and silently on a long Retry-After from a 5xx
  • Fixed fast mode retrying rate-limited requests back to back when the server sent Retry-After: 0
  • Fixed a tool that returned an oversized image leaving sibling tool calls unanswered and still running, or ending the turn with no final message
  • Fixed conversations getting permanently stuck on "tool_use.name: String should have at most 200 characters" after the model called a tool by an overlong name
  • Fixed tool calls failing with "Failed to get memory usage", or being reported as failed after they ran, when Claude Code cannot read its own memory usage, for example when it has run out of file descriptors
  • Fixed --input-format stream-json sessions (Agent SDK, VS Code extension) and scheduled cloud sessions failing every turn with an error when an earlier assistant message had plain-string content
  • Fixed non-interactive sessions (-p, Agent SDK) failing on the next turn after the directory they were started in was deleted mid-session
  • Fixed headless sessions with host-side (SDK) MCP servers stalling on the first message when the host stops responding mid-handshake; remote sessions now wait a few seconds at most
  • Fixed interactive startup waiting on the managed-settings network request (about 80 ms, 17+ seconds when the network is unreachable) when no MCP servers or plugins are configured
  • Fixed a delay of up to two minutes before responding when reading or @-mentioning a PDF larger than 3 MB
  • Fixed an interrupted Read of specific PDF pages leaving its page render running for up to two minutes
  • Fixed permission dialogs and attachment checks reading a path under macOS's /.vol, /.nofollow or /.resolve (which can reach a network mount) before approval
  • Fixed a recursive rm whose target is only command-substitution output, such as rm -rf "$(pwd)", running unprompted in auto and --dangerously-skip-permissions mode; it now asks even with a Bash allow rule, unless run with CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT=1
  • Fixed a permission rule containing a NUL byte being expanded into a wildcard match; such a rule now matches nothing
  • Fixed sandbox excludedCommands entries not matching git rev-parse --git-dir, programs named like shell builtins, and commit messages containing [WIP] or # lines
  • Fixed sandboxed Bash commands being unable to write to $TMPDIR when CLAUDE_CODE_TMPDIR is set
  • Fixed claude --bg starting a background session, and running its project hooks, in a directory that had not passed the workspace trust prompt; it now asks for trust first, or exits when not run interactively
  • Fixed --setting-sources (and SDK settingSources) not being forwarded to spawned sessions: teammates, /bg, claude agents sessions and --worktree --tmux now start with the parent's restriction
  • Fixed Read, Write, Edit and NotebookEdit: a file path containing a null byte now fails that tool call with a clear error instead of ending the whole turn
  • Fixed Write refusing a call that gives the file path or content twice under two parameter names with identical values
  • Fixed CLAUDE.md and rules files from an --add-dir directory inside the working directory being sent to the model twice in headless and SDK sessions
  • Fixed remote sessions staying on "needs approval" with a stale prompt after a permission prompt and a sandbox network-access prompt overlapped and both were answered
  • Fixed cloud sessions not telling Claude about background agents that finished just before a worker restart
  • Fixed scheduled routine and notification turns in remote sessions not receiving turn-start notices (newly available tools, MCP changes, date, todos) until after the first tool call
  • Fixed scheduled tasks and /loop wakeups being fired again every second when their delivery failed, which could make Claude Code exit at the end of a turn
  • Fixed Remote Control reporting "disabled by your organization's policy" when the org policy simply hadn't loaded yet; it now retries the fetch and says it couldn't verify

... (truncated)

Changelog

Sourced from @​anthropic-ai/claude-code's changelog.

2.1.281

  • Added Claude apps gateway support for newer Claude Desktop keys in desktop policy blocks, including blockReadsOutsideWorkingDirectories and disableBypassPermissionsMode
  • Added assume_role on Claude apps gateway Bedrock upstreams: the gateway calls Bedrock as an IAM role it assumes through STS, in another AWS account if needed, optionally one session per developer
  • Added guardrail: {id, version} on Claude apps gateway Bedrock upstreams to apply an Amazon Bedrock guardrail to every request sent through them (set it on all Bedrock upstreams or none)
  • Added telemetry.resource_attributes to the Claude apps gateway config, to put fixed labels on the telemetry of Claude Desktop and /login sessions
  • Added "attribution": false in settings.json to hide all commit and PR attribution; older CLI versions skip a settings file that holds it, so keep the object form in files shared across versions
  • Added MCP URL-mode elicitation on 2026-07-28 protocol connections, so servers can ask Claude Code to open a browser-based flow; no waiting dialog is left on screen when the server has no way to confirm completion
  • Added MCP server checks to claude plugin validate: it reports .mcp.json entries that would be silently dropped at load, undeclared ${user_config.*} references, and insecure URLs
  • Added an auto mode recommendation to /insights that estimates how many permission prompts auto mode could have handled in your recent sessions
  • Added a scrollbar to the /skills, /mcp and /plugin Installed lists in fullscreen mode, like the one /workflows now has: it appears while the mouse is over the list and can be clicked or dragged
  • Fixed a crash ("unrecoverable interface error") that could end a session while an API request was being retried
  • Fixed a turn that could retry indefinitely, ignoring --max-turns, when the model alternated unparseable tool calls and output-limit truncation
  • Fixed resumed sessions re-sending earlier turns in a changed form (a parallel tool-call turn, an MCP tool call's input or a tool-search result while its server was still reconnecting, or a tool-search result whose loading turn was interrupted), which could make the API drop the conversation's prior reasoning
  • Fixed resuming a very large session sometimes restoring only its last few messages
  • Fixed a session resumed after a restart during a pending permission prompt sending a different history than before, which broke the prompt cache from that point
  • Fixed resuming a session that ended during a tool call: Claude now sees the call and is told its outcome is unknown, and a manual resume no longer adds a hidden "Continue" message
  • Fixed sessions with an earlier advisor result the API could no longer read failing one request every turn and repeatedly losing earlier reasoning; the history is now repaired once
  • Fixed the prompt cache being lost when an MCP server disconnects mid-conversation, or is still connecting after a resume, while tool search is off (for example behind a proxy or gateway)
  • Fixed responses cut short by a proxy or gateway that closes the stream cleanly being shown as complete with no warning, and tool calls running twice on duplicated stream events
  • Fixed responses failing with "Content block not found" when a proxy drops a stream event mid-response; the partial response is now kept, and web search keeps results that already arrived
  • Fixed an empty completed response being requested twice when the connection dropped before the stream's final event
  • Fixed the stop reason being lost when a proxy sends a trailing usage-only frame
  • Fixed CLAUDE_CODE_RETRY_WATCHDOG sessions failing on the first 5xx or dropped connection after a run of 429/529 waits, and sleeping uncapped and silently on a long Retry-After from a 5xx
  • Fixed fast mode retrying rate-limited requests back to back when the server sent Retry-After: 0
  • Fixed a tool that returned an oversized image leaving sibling tool calls unanswered and still running, or ending the turn with no final message
  • Fixed conversations getting permanently stuck on "tool_use.name: String should have at most 200 characters" after the model called a tool by an overlong name
  • Fixed tool calls failing with "Failed to get memory usage", or being reported as failed after they ran, when Claude Code cannot read its own memory usage, for example when it has run out of file descriptors
  • Fixed --input-format stream-json sessions (Agent SDK, VS Code extension) and scheduled cloud sessions failing every turn with an error when an earlier assistant message had plain-string content
  • Fixed non-interactive sessions (-p, Agent SDK) failing on the next turn after the directory they were started in was deleted mid-session
  • Fixed headless sessions with host-side (SDK) MCP servers stalling on the first message when the host stops responding mid-handshake; remote sessions now wait a few seconds at most
  • Fixed interactive startup waiting on the managed-settings network request (about 80 ms, 17+ seconds when the network is unreachable) when no MCP servers or plugins are configured
  • Fixed a delay of up to two minutes before responding when reading or @-mentioning a PDF larger than 3 MB
  • Fixed an interrupted Read of specific PDF pages leaving its page render running for up to two minutes
  • Fixed permission dialogs and attachment checks reading a path under macOS's /.vol, /.nofollow or /.resolve (which can reach a network mount) before approval
  • Fixed a recursive rm whose target is only command-substitution output, such as rm -rf "$(pwd)", running unprompted in auto and --dangerously-skip-permissions mode; it now asks even with a Bash allow rule, unless run with CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT=1
  • Fixed a permission rule containing a NUL byte being expanded into a wildcard match; such a rule now matches nothing
  • Fixed sandbox excludedCommands entries not matching git rev-parse --git-dir, programs named like shell builtins, and commit messages containing [WIP] or # lines
  • Fixed sandboxed Bash commands being unable to write to $TMPDIR when CLAUDE_CODE_TMPDIR is set
  • Fixed claude --bg starting a background session, and running its project hooks, in a directory that had not passed the workspace trust prompt; it now asks for trust first, or exits when not run interactively
  • Fixed --setting-sources (and SDK settingSources) not being forwarded to spawned sessions: teammates, /bg, claude agents sessions and --worktree --tmux now start with the parent's restriction
  • Fixed Read, Write, Edit and NotebookEdit: a file path containing a null byte now fails that tool call with a clear error instead of ending the whole turn
  • Fixed Write refusing a call that gives the file path or content twice under two parameter names with identical values
  • Fixed CLAUDE.md and rules files from an --add-dir directory inside the working directory being sent to the model twice in headless and SDK sessions
  • Fixed remote sessions staying on "needs approval" with a stale prompt after a permission prompt and a sandbox network-access prompt overlapped and both were answered
  • Fixed cloud sessions not telling Claude about background agents that finished just before a worker restart
  • Fixed scheduled routine and notification turns in remote sessions not receiving turn-start notices (newly available tools, MCP changes, date, todos) until after the first tool call
  • Fixed scheduled tasks and /loop wakeups being fired again every second when their delivery failed, which could make Claude Code exit at the end of a turn
  • Fixed Remote Control reporting "disabled by your organization's policy" when the org policy simply hadn't loaded yet; it now retries the fetch and says it couldn't verify
  • Fixed the Artifact tool missing from Remote Control sessions that claude remote-control starts for you to open from Claude Desktop, claude.ai or the mobile app

... (truncated)

Commits
  • d78be94 chore: Update CHANGELOG.md and feed.xml
  • 56f3653 chore: Update CHANGELOG.md and feed.xml
  • b486776 Merge pull request #95932 from anthropics/add-github-connection-issue-template
  • 411c240 Add issue template for GitHub connection problems on claude.ai
  • 8187baa chore: Update CHANGELOG.md and feed.xml
  • 7974a70 diff: a resumed session with edits opens the pane before any new edit, /clear...
  • 4564326 telemetry: complete rows gathered through $, sent in batches, serving built-i...
  • bf7d404 chore: Update CHANGELOG.md and feed.xml
  • 92ec78f diff: a docked pane reads the repository before it opens, so it never lands o...
  • 2287e5d diff: the first edit opens the pane only from the main loop with checkpointin...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@anthropic-ai/claude-code](https://github.com/anthropics/claude-code) from 2.1.259 to 2.1.281.
- [Release notes](https://github.com/anthropics/claude-code/releases)
- [Changelog](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-code@v2.1.259...v2.1.281)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/claude-code"
  dependency-version: 2.1.281
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Routine Dependabot bump of @anthropic-ai/claude-code (2.1.259 → 2.1.281), a devDependency only — package.json/package-lock.json changes are otherwise mechanical and correctly paired. One real gap found, so requesting changes:

  • Should fix [policy] — package.json:43's allowScripts entry is still keyed to the old exact version (@anthropic-ai/claude-code@2.1.259), so it won't cover 2.1.281's postinstall script under npm 12's lifecycle-script allow-list once this merges. .github/workflows/dependabot.yml's investigate job runs npm ci then npx claude against this exact package right after, so this is a real functional risk, not just a stale record. See the inline comment for detail and the one-line fix.

Title and description are already complete (Dependabot's own standard release-notes body) — left untouched. Nothing else to flag; didn't check whether 2.1.281's own release notes (MCP/elicitation, settings.json attribution flag, etc.) imply any adaptation here, since that's exactly what .github/workflows/dependabot.yml's own investigate job is designed to do separately for the anthropics/claude-code-action upstream bump — not applicable to this npm-ecosystem bump.

Comment thread package.json
},
"devDependencies": {
"@anthropic-ai/claude-code": "2.1.259",
"@anthropic-ai/claude-code": "2.1.281",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should fix [policy] — the allowScripts entry at package.json:43 is still pinned to the old exact version:

"allowScripts": {
  "@anthropic-ai/claude-code@2.1.259": true
}

That field was added deliberately in 2d35b3f to approve this package's postinstall script under npm 12's lifecycle-script allow-list (keyed by exact package@version, per npm's allow-scripts config added in 11.20.0/12.1.0) — "npm 12's lifecycle-script gate now blocks by default" per that commit's own message. Since this PR bumps the dependency to 2.1.281 but doesn't add a matching "@anthropic-ai/claude-code@2.1.281": true entry, the new version's postinstall script will no longer match the allow-list on the next clean install.

This isn't just cosmetic: .github/workflows/dependabot.yml's investigate job runs npm ci and then invokes this exact CLI via npx claude immediately afterwards (the comment there notes the CLI is installed as an ordinary devDependency by npm ci above), so a blocked postinstall could affect that job as soon as this merges and a future Dependabot bump re-triggers it.

Can't offer a one-click suggestion here since line 43 falls outside this diff's hunk, but the fix is to bump the key alongside the version:

"allowScripts": {
  "@anthropic-ai/claude-code@2.1.281": true
}

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

🗜️ Headroom context compression

Metric Value
Requests proxied 34
Tokens saved 160460
Aggregate savings 5.6% of all tokens sent
Average per-request compression 7.6%

@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #118.

@dependabot dependabot Bot closed this Oct 2, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/anthropic-ai/claude-code-2.1.281 branch October 2, 2026 14:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants