Repository navigation
build(deps-dev): bump @anthropic-ai/claude-code from 2.1.259 to 2.1.273 - #95
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@anthropic-ai/claude-code](https://github.com/anthropics/claude-code) from 2.1.259 to 2.1.273. - [Release notes](https://github.com/anthropics/claude-code/releases) - [Changelog](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md) - [Commits](anthropics/claude-code@v2.1.259...v2.1.273) --- updated-dependencies: - dependency-name: "@anthropic-ai/claude-code" dependency-version: 2.1.273 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
❌ Claude's run did not complete (outcome: failure). View job run |
Superseded by re-review on the latest commit: the prior approval missed that package.json's allowScripts entry pins the old version.
There was a problem hiding this comment.
Routine Dependabot devDependency bump of @anthropic-ai/claude-code (2.1.259 → 2.1.273), confined to package.json and package-lock.json. One finding, otherwise clean.
Should fix — package.json's allowScripts block still pins the old version (@anthropic-ai/claude-code@2.1.259) instead of 2.1.273. See inline comment for details and a suggested fix.
Verified:
- No other file in the repository hardcodes this version string.
- This is the npm CLI dependency the
investigatejob independabot.ymlruns (npx claude), not the pinnedanthropics/claude-code-actionSHA inaction.yml— per this repository's own documented policy, noaction.ymlinput/output compatibility check applies here. package.json'sengines.node(>=22.22.1 <23.0.0 || >=23.6.0) already satisfies the new release's own>=22.0.0requirement.- Title and description are Dependabot's standard, accurate output; no rewrite needed.
I dismissed and cleared the prior APPROVED review on this same commit from this bot identity: it claimed "no other file hardcodes this version," which is incorrect — package.json itself does, in the allowScripts key noted above.
| }, | ||
| "devDependencies": { | ||
| "@anthropic-ai/claude-code": "2.1.259", | ||
| "@anthropic-ai/claude-code": "2.1.273", |
There was a problem hiding this comment.
Should fix [policy]
This bump updates the devDependencies entry to 2.1.273 but misses the matching allowScripts key further down this same file (line 43), which still pins the old version:
"allowScripts": {
"@anthropic-ai/claude-code@2.1.259": true
}That key was introduced deliberately in 2d35b3f ("build(deps): adopt @exadev/eslint-config and bump to npm 12.0.2") specifically to approve @anthropic-ai/claude-code's postinstall script under npm 12's lifecycle-script gate — the commit message notes the dependabot.yml investigate job invokes this CLI directly via npx claude and the script "genuinely needs to run." Since allowScripts is keyed by exact package@version string, leaving it at 2.1.259 means npm 12 will block the postinstall script for the newly-installed 2.1.273, silently breaking whatever that script does for the investigate job going forward.
| "@anthropic-ai/claude-code": "2.1.273", | |
| "@anthropic-ai/claude-code@2.1.273": true |
Since the automatic-fix pass is off for this run: @claude fix package.json's allowScripts key to pin @anthropic-ai/claude-code@2.1.273 instead of 2.1.259, matching the devDependencies bump in this PR.
|
🗜️ Headroom context compression
|
|
Superseded by #97. |
Bumps @anthropic-ai/claude-code from 2.1.259 to 2.1.273.
Release notes
Sourced from @anthropic-ai/claude-code's releases.
... (truncated)
Changelog
Sourced from @anthropic-ai/claude-code's changelog.
... (truncated)
Commits
aad35bachore: Update CHANGELOG.md and feed.xmlf96c3b4chore: Update CHANGELOG.md and feed.xmlf2ccbe2chore: Update CHANGELOG.md and feed.xmlf4ceeecMerge pull request #94184 from anthropics/poteat/diff-parity-27d4f947diff: the docked window's hunks are made printable and split under a leaf's c...9d302a8Merge remote-tracking branch 'origin/main' into poteat/diff-parity-218be13bmods: the diff, sec-default and telemetry tests move next to the mods (#93951)0fdc7b2diff tests: the walk stops at the last file17db2e1diff: the dialog's walk stops at the first and last file as the built-in's do...78c94cediff: the rows' widths and reserves live under limits, sparing six of the fil...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)