Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
72 changes: 36 additions & 36 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@
"format:check": "prettier --check ."
},
"devDependencies": {
"@anthropic-ai/claude-code": "2.1.259",
"@anthropic-ai/claude-code": "2.1.281",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should fix [policy] — the allowScripts entry at package.json:43 is still pinned to the old exact version:

"allowScripts": {
  "@anthropic-ai/claude-code@2.1.259": true
}

That field was added deliberately in 2d35b3f to approve this package's postinstall script under npm 12's lifecycle-script allow-list (keyed by exact package@version, per npm's allow-scripts config added in 11.20.0/12.1.0) — "npm 12's lifecycle-script gate now blocks by default" per that commit's own message. Since this PR bumps the dependency to 2.1.281 but doesn't add a matching "@anthropic-ai/claude-code@2.1.281": true entry, the new version's postinstall script will no longer match the allow-list on the next clean install.

This isn't just cosmetic: .github/workflows/dependabot.yml's investigate job runs npm ci and then invokes this exact CLI via npx claude immediately afterwards (the comment there notes the CLI is installed as an ordinary devDependency by npm ci above), so a blocked postinstall could affect that job as soon as this merges and a future Dependabot bump re-triggers it.

Can't offer a one-click suggestion here since line 43 falls outside this diff's hunk, but the fix is to bump the key alongside the version:

"allowScripts": {
  "@anthropic-ai/claude-code@2.1.281": true
}

"@commitlint/cli": "21.2.2",
"@commitlint/config-conventional": "21.2.2",
"@eslint/json": "2.1.0",
Expand Down
Loading