Skip to content

build(deps-dev): bump @anthropic-ai/claude-code from 2.1.259 to 2.1.283 - #121

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/anthropic-ai/claude-code-2.1.283
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/anthropic-ai/claude-code-2.1.283

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps @anthropic-ai/claude-code from 2.1.259 to 2.1.283.

Release notes

Sourced from @​anthropic-ai/claude-code's releases.

v2.1.283

What's changed

  • Added x-claude-code-prompt-id to the gateway hint headers so LLM gateways can group the requests that serve one user prompt; opt in with CLAUDE_CODE_GATEWAY_HINT_HEADERS=1
  • Added availableModelsMatch managed setting: with "exact", an availableModels entry allows only the model version it names, so new releases stay blocked until listed
  • Added deniedModels managed setting to block specific models, even when availableModels allows them
  • Added MCP tool, WebFetch and WebSearch outputs to the tool.output OpenTelemetry span event when OTEL_LOG_TOOL_CONTENT=1
  • Added /doctor prompt-audit (also /checkup prompt-audit) to audit your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models
  • Added click-to-expand for truncated messages from your other sessions in fullscreen mode
  • Added path to --plugin-dir load-failure entries in the stream-json system/init plugin_errors, naming the directory that did not load
  • Added an opt-in load_test_mode block to the Claude apps gateway config: requests are built and signed but not sent upstream, and clients get a canned reply, so a deployment can be load tested
  • Added a mantle upstream provider to the Claude apps gateway for Amazon Bedrock's Mantle endpoint
  • Fixed SDK sessions losing a deferred tool call or finished tool result when a turn ended early, a held approval prompt after a worker restart, and a non-streaming fallback's result.usage
  • Fixed MCP progress notifications being discarded once a long-running tool call moved to the background; the background task now shows the latest progress
  • Fixed stdio MCP servers being left running when the session ended while they were still starting
  • Fixed a brief HTTP 404 from a stateless remote MCP server (for example a proxy mid-redeploy) leaving that server unusable for the rest of the session while still shown as connected
  • Fixed MCP sign-in for a server with no valid URL failing with an opaque SDK error; /mcp no longer offers Authenticate for such servers
  • Fixed the weekly Fable limit not appearing in /usage and the VS Code usage meters when telemetry is disabled
  • Fixed /model accepting Sonnet 4.6 or Sonnet 5 with [1m] when the id carried a date or -v1:0 suffix, in the cases where the plain id was refused
  • Fixed /model picker showing a hardcoded Haiku version and price when ANTHROPIC_DEFAULT_HAIKU_MODEL pins a different model
  • Fixed dynamic workflows started during a model fallback running every agent on the fallback model instead of retrying the configured model
  • Fixed DISABLE_PROMPT_CACHING_HAIKU having no effect when Haiku is the session's main model
  • Fixed claude plugin validate saying Claude Code accepts a plugin or marketplace name it cannot install; such names in marketplace.json now fail validation
  • Fixed claude plugin validate passing plugins whose outputStyles, themes, monitors, or lspServers paths are missing or point outside the plugin directory
  • Fixed claude plugin details showing 0 MCP servers for plugins that declare their servers in plugin.json
  • Fixed claude plugin marketplace remove not saying which installed plugins it uninstalled with the marketplace; it now lists them
  • Fixed claude plugin uninstall removing the other of two installed plugins whose ids differ only in case, with its options and secrets, when the one named had no enabledPlugins entry at that scope
  • Fixed plugins that declare no version being silently restored at their source's newest commit, not the installed one, when their cached files were missing
  • Fixed user-installed plugins and marketplaces failing to load with "cache-miss" after the home or config directory was moved, for example in bind-mounted devcontainers
  • Fixed installed_plugins.json showing no plugins when it holds a record under an invalid plugin id; such a file loads again
  • Fixed installed_plugins.json being rewritten, losing records, when it holds a record this version cannot read; claude plugin commands now name the record and say how to recover
  • Fixed permission dialogs in screen-reader mode reading quoted commands and paths as if they were the dialog's own text
  • Fixed /context not counting MCP server instructions: they now appear as their own row and count toward the total
  • Fixed markdown links in the Warp terminal rendering as plain text instead of clickable hyperlinks
  • Fixed claude mcp add, add-json, and remove reporting success when the user or local config file could not be written, for example inside a sandbox
  • Fixed the first words of a reply in a cloud session sometimes appearing late instead of streaming as Claude writes them
  • Fixed Claude's built-in keybindings guide saying chords time out after 1 second instead of 3, and calling cmd an alias of meta, which could produce cmd+ shortcuts most terminals never send
  • Fixed keybindings.json silently accepting a misspelled modifier such as ctl+k; it now warns in the debug log and suggests the fix
  • Fixed footer hints still saying "Enter to view" after footer:openSelected was rebound or unbound in keybindings.json
  • Fixed keys typed quickly together (type-ahead, key repeat, bursts over ssh or tmux) sometimes being handled against stale state
  • Fixed worktree checkouts failing certificate verification (for example on Git LFS downloads) when the CA certificate is passed to git as GIT_CONFIG_COUNT environment pairs
  • Fixed sandboxed git asking credential helpers to store the sandbox proxy's login, which printed "failed to store"
  • Fixed managed sandbox settings being ignored entirely when one nested value was invalid; the invalid value now fails closed and the rest of the block still applies
  • Fixed Claude's edits to its own auto-memory notes being blocked as sensitive-file writes when Claude Code was started in a subdirectory of a git repository
  • Fixed Remote Control being unavailable on paid plans when telemetry is turned off with DISABLE_TELEMETRY or DO_NOT_TRACK
  • Fixed the /remote-control menu cutting its QR-code hint mid-word in narrow terminals
  • Fixed vim mode . dropping a Shift+Enter newline, leaving the cursor inside an accented letter, and repeating an older change after 3J or Visual-mode J on the last line
  • Fixed vim mode cursor placement: recalling a prompt over 10,000 characters in normal mode no longer leaves the cursor past the end, and V then p now lands on the first non-blank
  • Fixed vim mode J joining lines with different spacing than Vim (such as a space before ) or after a tab), and 3J or Visual-mode J on the last line not moving the cursor as Vim does
  • Windows: Fixed the PowerShell tool letting cmd /c rd, rmdir, del or erase delete drive roots, the home folder and other folders that Remove-Item refuses

... (truncated)

Changelog

Sourced from @​anthropic-ai/claude-code's changelog.

2.1.283

  • Added x-claude-code-prompt-id to the gateway hint headers so LLM gateways can group the requests that serve one user prompt; opt in with CLAUDE_CODE_GATEWAY_HINT_HEADERS=1
  • Added availableModelsMatch managed setting: with "exact", an availableModels entry allows only the model version it names, so new releases stay blocked until listed
  • Added deniedModels managed setting to block specific models, even when availableModels allows them
  • Added MCP tool, WebFetch and WebSearch outputs to the tool.output OpenTelemetry span event when OTEL_LOG_TOOL_CONTENT=1
  • Added /doctor prompt-audit (also /checkup prompt-audit) to audit your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models
  • Added click-to-expand for truncated messages from your other sessions in fullscreen mode
  • Added path to --plugin-dir load-failure entries in the stream-json system/init plugin_errors, naming the directory that did not load
  • Added an opt-in load_test_mode block to the Claude apps gateway config: requests are built and signed but not sent upstream, and clients get a canned reply, so a deployment can be load tested
  • Added a mantle upstream provider to the Claude apps gateway for Amazon Bedrock's Mantle endpoint
  • Fixed SDK sessions losing a deferred tool call or finished tool result when a turn ended early, a held approval prompt after a worker restart, and a non-streaming fallback's result.usage
  • Fixed MCP progress notifications being discarded once a long-running tool call moved to the background; the background task now shows the latest progress
  • Fixed stdio MCP servers being left running when the session ended while they were still starting
  • Fixed a brief HTTP 404 from a stateless remote MCP server (for example a proxy mid-redeploy) leaving that server unusable for the rest of the session while still shown as connected
  • Fixed MCP sign-in for a server with no valid URL failing with an opaque SDK error; /mcp no longer offers Authenticate for such servers
  • Fixed the weekly Fable limit not appearing in /usage and the VS Code usage meters when telemetry is disabled
  • Fixed /model accepting Sonnet 4.6 or Sonnet 5 with [1m] when the id carried a date or -v1:0 suffix, in the cases where the plain id was refused
  • Fixed /model picker showing a hardcoded Haiku version and price when ANTHROPIC_DEFAULT_HAIKU_MODEL pins a different model
  • Fixed dynamic workflows started during a model fallback running every agent on the fallback model instead of retrying the configured model
  • Fixed DISABLE_PROMPT_CACHING_HAIKU having no effect when Haiku is the session's main model
  • Fixed claude plugin validate saying Claude Code accepts a plugin or marketplace name it cannot install; such names in marketplace.json now fail validation
  • Fixed claude plugin validate passing plugins whose outputStyles, themes, monitors, or lspServers paths are missing or point outside the plugin directory
  • Fixed claude plugin details showing 0 MCP servers for plugins that declare their servers in plugin.json
  • Fixed claude plugin marketplace remove not saying which installed plugins it uninstalled with the marketplace; it now lists them
  • Fixed claude plugin uninstall removing the other of two installed plugins whose ids differ only in case, with its options and secrets, when the one named had no enabledPlugins entry at that scope
  • Fixed plugins that declare no version being silently restored at their source's newest commit, not the installed one, when their cached files were missing
  • Fixed user-installed plugins and marketplaces failing to load with "cache-miss" after the home or config directory was moved, for example in bind-mounted devcontainers
  • Fixed installed_plugins.json showing no plugins when it holds a record under an invalid plugin id; such a file loads again
  • Fixed installed_plugins.json being rewritten, losing records, when it holds a record this version cannot read; claude plugin commands now name the record and say how to recover
  • Fixed permission dialogs in screen-reader mode reading quoted commands and paths as if they were the dialog's own text
  • Fixed /context not counting MCP server instructions: they now appear as their own row and count toward the total
  • Fixed markdown links in the Warp terminal rendering as plain text instead of clickable hyperlinks
  • Fixed claude mcp add, add-json, and remove reporting success when the user or local config file could not be written, for example inside a sandbox
  • Fixed the first words of a reply in a cloud session sometimes appearing late instead of streaming as Claude writes them
  • Fixed Claude's built-in keybindings guide saying chords time out after 1 second instead of 3, and calling cmd an alias of meta, which could produce cmd+ shortcuts most terminals never send
  • Fixed keybindings.json silently accepting a misspelled modifier such as ctl+k; it now warns in the debug log and suggests the fix
  • Fixed footer hints still saying "Enter to view" after footer:openSelected was rebound or unbound in keybindings.json
  • Fixed keys typed quickly together (type-ahead, key repeat, bursts over ssh or tmux) sometimes being handled against stale state
  • Fixed worktree checkouts failing certificate verification (for example on Git LFS downloads) when the CA certificate is passed to git as GIT_CONFIG_COUNT environment pairs
  • Fixed sandboxed git asking credential helpers to store the sandbox proxy's login, which printed "failed to store"
  • Fixed managed sandbox settings being ignored entirely when one nested value was invalid; the invalid value now fails closed and the rest of the block still applies
  • Fixed Claude's edits to its own auto-memory notes being blocked as sensitive-file writes when Claude Code was started in a subdirectory of a git repository
  • Fixed Remote Control being unavailable on paid plans when telemetry is turned off with DISABLE_TELEMETRY or DO_NOT_TRACK
  • Fixed the /remote-control menu cutting its QR-code hint mid-word in narrow terminals
  • Fixed vim mode . dropping a Shift+Enter newline, leaving the cursor inside an accented letter, and repeating an older change after 3J or Visual-mode J on the last line
  • Fixed vim mode cursor placement: recalling a prompt over 10,000 characters in normal mode no longer leaves the cursor past the end, and V then p now lands on the first non-blank
  • Fixed vim mode J joining lines with different spacing than Vim (such as a space before ) or after a tab), and 3J or Visual-mode J on the last line not moving the cursor as Vim does
  • Windows: Fixed the PowerShell tool letting cmd /c rd, rmdir, del or erase delete drive roots, the home folder and other folders that Remove-Item refuses
  • Improved the /mcp tool list: it shows more tools at once, scrolls with the page keys and mouse, and marks tools your organization blocked with a warning icon

... (truncated)

Commits
  • 7779afb chore: Update CHANGELOG.md and feed.xml
  • c948155 diff: the focus hook answers to either name the engine stamps on its elements...
  • e1bb7b0 telemetry, agents-md: the test plugins hook and call the collector stream by ...
  • 163ae3a chore: Update CHANGELOG.md and feed.xml
  • 6557bbe telemetry: log and mark are what the mod's hooks do, the noun added only wher...
  • 684ffc4 agents-md: the truncated-read tests laid out as the formatter lays them
  • 653d32f fix(agents-md): retain instructions after truncated reads
  • ddcb43a chore: Update CHANGELOG.md and feed.xml
  • 32251d1 diff: the shared diff arguments' doc says what --no-color pins
  • 4536209 fix(diff): preserve hunks when Git forces colored output
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@anthropic-ai/claude-code](https://github.com/anthropics/claude-code) from 2.1.259 to 2.1.283.
- [Release notes](https://github.com/anthropics/claude-code/releases)
- [Changelog](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-code@v2.1.259...v2.1.283)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/claude-code"
  dependency-version: 2.1.283
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Routine Dependabot devDependency bump of @anthropic-ai/claude-code (2.1.259 → 2.1.283), isolated to its own PR per this repo's .github/dependabot.yml grouping. package.json and package-lock.json are updated consistently, the commit type (build) correctly maps to a patch release per release.config.ts's commitTypes, and the PR body is Dependabot's own complete, standard release-notes body — nothing to fix there.

One finding:

  • Should fix [policy] — package.json:43's allowScripts entry still pins the pre-bump version (@anthropic-ai/claude-code@2.1.259), not updated alongside the version bumped everywhere else in this diff. See inline comment for detail; I could not confirm whether this field is actually enforced anywhere in this repo's own tooling, so I can't say how much practical effect the staleness has, but the inconsistency itself is concrete and worth closing.

Using Comment rather than Changes Requested here: this is a Dependabot-authored automated bump, the finding is in a field whose enforcement in this pipeline I could not verify, and blocking an otherwise-correct routine bump over an unverified consequence felt like the wrong default — a maintainer should weigh that trade-off rather than have it made for them.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

🗜️ Headroom context compression

Metric Value
Requests proxied 31
Tokens saved 155192
Aggregate savings 5.9% of all tokens sent
Average per-request compression 7.6%

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants