Skip to content

chore(deps): update devcontainer agent tools - #124

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/devcontainer-agent-tools
Sep 9, 2026
Merged

renovate[bot] merged 1 commit into
masterfrom
renovate/devcontainer-agent-tools

Conversation

@renovate

@renovate renovate Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Update
@anthropic-ai/claude-code 2.1.263 → 2.1.266 age confidence patch
agent-browser (source) 0.36.0 → 0.37.1 age confidence minor
umputun/ralphex 1.6.1 → 1.7.0 age confidence minor

Release Notes

anthropics/claude-code (@​anthropic-ai/claude-code)

v2.1.266

Compare Source

  • Fixed a 2.1.265 regression affecting LLM-gateway and proxy setups: the undocumented CLAUDE_CODE_USE_GATEWAY environment variable, previously ignored unless ANTHROPIC_BASE_URL and ANTHROPIC_AUTH_TOKEN were both set, began forcing Cloud-gateway sign-in on its own in 2.1.265, so configurations that set it alongside an API key, apiKeyHelper, or custom auth headers failed every request with "Not signed in to the Cloud gateway". The variable on its own is ignored again; no configuration change is needed

v2.1.265

Compare Source

  • Added user.email and user.groups to the telemetry Claude Desktop and Cowork send through a Claude apps gateway, matching terminal sessions
  • Added support for pointing --plugin-dir at a folder of plugins: each child folder with a manifest loads, and children added or removed while running are picked up
  • Added a 1 GB cap on tool results saved to disk; the in-conversation preview says when a saved file was truncated
  • Fixed resuming a foreground-spawned subagent changing its tool list and system prompt prefix, which broke prompt-cache reuse for that agent
  • Fixed agent teammates and resumed subagents moving SubagentStart hook context and preloaded skills out of the prompt prefix on later turns, which broke prompt-cache reuse
  • Fixed resume after the previous process died while a tool was running: the last prompt is no longer rewritten, and the interrupted tool call is kept and marked interrupted
  • Fixed /model opusplan[1m] being rejected with "Model not found"
  • Fixed syntax-highlighted code in permission prompts and messages sometimes omitting a character after a Ruby ?, Erlang $, or Perl $ sigil
  • Fixed the fullscreen transcript jumping by one row whenever the slash-command or @​-file suggestion list opened or closed
  • Fixed a plugin path containing a backslash bypassing the symlink containment check on macOS and Linux
  • Fixed plugin directories whose names begin with two dots being wrongly refused as outside the plugin root
  • Fixed VS Code and SDK sessions occasionally requiring re-login when a session was closed while refreshing its token
  • Fixed Remote Control sessions sending the end-of-turn signal before the reply's last message, which could show a reply as finished in the Claude app before its last part arrived
  • Fixed background (--bg) sessions occasionally being retired mid-turn when a message arrived just before the idle timeout
  • Fixed Claude Code's own git status and diff probes running clean filters configured by a nested repository inside the working tree
  • Fixed the advisor tool and its instructions being re-decided per request from the request's model; the decision is now made once and announced in the conversation when it changes
  • Fixed artifact publish accepting connector tool names the connector doesn't expose; the publish is now refused when none of the declared tools exist, and warned when only some don't
  • Fixed /add-dir <subdirectory> refusing to load a subdirectory's agents when managed settings lock only skills to plugins, and promising agents when only agents are locked
  • Fixed two-key keyboard shortcuts cancelling silently when the second key arrived more than a second later, as happens inside tmux; they now wait 3 seconds and show a notice when they time out
  • Fixed forked skills (context: fork) not streaming their kickoff prompt and, with --forward-subagent-text, their text turns as progress events in stream-json
  • Fixed a plugin's default component folder that the OS cannot check, such as a symlink loop, being silently skipped; it is now reported in /plugin with the error code
  • Fixed the Claude apps gateway's OTLP telemetry relay pausing all forwarding to a collector for 30 seconds after it rejected a few payloads as malformed or too large
  • Fixed /plugin Discover/Browse and claude plugin list --json --available showing no description or display name for marketplace plugins whose metadata lives only in their plugin.json
  • Fixed /login showing "no gateway URL is configured" when re-run in a session that signed in to a Claude apps gateway set by managed settings
  • Fixed /model claiming a model was "saved as your default" when the settings file couldn't be written; it now says the save failed and why
  • Fixed /clear from Remote Control waiting on SessionStart hooks and on open terminal dialogs before completing
  • Fixed the /config dialog changing height when switching between its tabs
  • Fixed resuming a workflow run after its container restarted; a resume whose run journal is missing now fails with a clear error instead of rerunning every agent
  • Fixed the claude-api skill's error-code reference: model access failures return 404 and unavailable beta headers return 400, not 403
  • Fixed non-interactive sessions (-p with stream-json input, Agent SDK, cloud sessions) resetting the shell working directory at each new user message; a cd now persists across turns
  • Fixed MCP servers configured as http that only speak the legacy HTTP+SSE transport never connecting; Claude Code now falls back to SSE as the MCP spec describes
  • Fixed some claude.ai connectors in cloud sessions showing as needing authentication even though they are connected in claude.ai (servers that answer an unsupported request with HTTP 401)
  • Fixed remote sessions keeping their sandbox container alive while a connector approval or sign-in link waits for you
  • Fixed resumed sessions showing long model-facing recovery instructions in "background task didn't finish" notices instead of a short status line
  • Windows: Fixed Read, Write and Edit refusing every file ("symlink resolution changed after permission was checked") when running inside an AppContainer or restricted-token sandbox
  • Improved --worktree startup on large repositories: the new worktree is now checked out in parallel (git 2.32+)
  • Improved /workflows agent detail: tool calls are marked running, failed or done, the subagent's task list is shown when it has one, and Enter unfolds the listed calls with their inputs and results
  • Improved slash commands typed mid-prompt: matches now show in a list (Tab opens it outside fullscreen) instead of a single suggestion, and a plugin skill is now found by its bare name
  • Improved remote MCP servers that need sign-in: Claude Code no longer registers an OAuth client with them until you actually authenticate
  • Improved the time to resume long sessions that read many files
  • Improved the error shown when an image over the size limits cannot be decoded: it now names the cause and how to fix it instead of only citing the limit
  • Improved the Artifact tool's read of an artifact someone else wrote: the summary now treats the page as untrusted content and flags embedded instructions rather than relaying them
  • Updated the .claude folder permission option to say what it actually allows: editing files in the project's .claude folder (or ~/.claude) for the session
  • Changed machines with forceLoginGatewayUrl in managed settings to be Claude apps gateway sessions from startup, like forceLoginMethod: "gateway"; a leftover claude.ai login or API key is not used
  • Changed image processing to use the runtime's built-in image support; the CLI no longer extracts a native image module to the temp directory
  • Changed plugin display metadata to prefer the marketplace entry over plugin.json on the Installed tab and claude plugin details, filling gaps from plugin.json
  • Changed Claude apps gateway sessions to export OpenTelemetry directly to a collector the gateway's managed settings name in OTEL_EXPORTER_OTLP_ENDPOINT, instead of through the gateway's relay; sessions without a named collector still use the relay
  • [VSCode] Added automatic archiving of sessions inactive for a set period (new "Archive inactive sessions" setting, default 14 days)
  • [VSCode] Fixed the sidebar chat coming back blank after Reload Window or a restart when the conversation had been open for more than 10 minutes
  • [VSCode] Fixed the timeline dot sitting below the text on the "Remote Control is active" message
vercel-labs/agent-browser (agent-browser)

v0.37.1

Compare Source

Bug Fixes
  • Fixed Windows headless Chrome desktop artifacts by isolating owned headless Chrome on a private desktop and ensuring its process tree is cleaned up when the daemon exits or is forcibly terminated. Headed and externally connected browsers retain their existing desktop behavior (#​1498, #​1820)
Contributors

v0.37.0

Compare Source

New Features
  • Added higher-quality video recording: record start and record restart now capture the current active page at 30 fps by default, support --fps 1-60, use Page.startScreencast for smoother motion, and preserve wall-clock timing. WebM and MP4 output are documented, and doctor reports the ffmpeg recording dependencies (#​1763, #​1776, #​1778)
  • Added WebMCP availability output so navigation responses advertise when a page exposes allowed WebMCP tools, including availability metadata for CLI, JSON, and MCP clients (#​1760)
  • Added session setup inheritance for new tabs. Tabs opened with tab new or through page clicks now inherit the active session's headers, credentials, user agent, locale, timezone, geolocation, offline mode, routes, color scheme, and init scripts before their first navigation (#​1777)
Bug Fixes
  • Fixed recording startup validation so missing ffmpeg, extensionless output paths, and invalid recording options fail before browser or recording state changes. Failed replacements preserve the active take, and ffmpeg errors now include useful diagnostics (#​1778)
  • Fixed recording navigation state so URL navigation during recording clears stale element refs, frame scope, and page WebMCP state like normal navigation (#​1776)
Contributors
umputun/ralphex (umputun/ralphex)

v1.7.0

Compare Source

New Features
Improved
Fixed

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/devcontainer-agent-tools branch from 9da54f1 to 31d6b72 Compare September 9, 2026 00:31
gatezh added a commit that referenced this pull request Sep 9, 2026
`automerge: true` has never merged a PR since it was added in #116. #121 sat
open, green and CLEAN for 3.5 weeks; #124 was on the same path.

Root cause is a race created by `platformAutomerge: false`. That setting means
only a Renovate run can merge, and a run merges when it observes an
already-green branch. But @anthropic-ai/claude-code ships ~2 releases/day while
Renovate runs every 2-9 days, so every run found a newer version, force-pushed
the branch (resetting CI to pending) and ended seconds later. The last run is
typical: pushed at 19:56:39, run ended 19:56:45, first check went green at
19:56:53, last at 19:59:40 -- nobody was watching. The run that could merge is
always the run that just invalidated CI.

Note this is not fixable with `minimumReleaseAge`: at any threshold there are
still newly-eligible versions by the next run, so the force-push repeats.

Switch to `platformAutomerge: true` so GitHub's native auto-merge merges on
green with no Renovate run involved. This is also the freshest option -- no
version-age delay at all.

Native auto-merge needs something to wait for, i.e. branch protection with a
required check, and a required check that never runs blocks a PR forever. CI is
currently path-filtered at the `on:` level, so a docs-only PR (#123 touches only
README.md and docs/*.md) triggers no CI at all and would deadlock. So drop the
paths filter and add one `CI complete` job aggregating the others, passing on
success-or-skipped so path-filtered builds still don't block. Per-image builds
are still gated by detect-changes; the always-on jobs are lint-only.

Verified with actionlint (exit 0, no findings).
@renovate
renovate Bot merged commit 1e9e293 into master Sep 9, 2026
11 checks passed
@renovate
renovate Bot deleted the renovate/devcontainer-agent-tools branch September 9, 2026 03:02
gatezh added a commit that referenced this pull request Sep 9, 2026
* fix(ci): make Renovate auto-merge actually fire

`automerge: true` has never merged a PR since it was added in #116. #121 sat
open, green and CLEAN for 3.5 weeks; #124 was on the same path.

Root cause is a race created by `platformAutomerge: false`. That setting means
only a Renovate run can merge, and a run merges when it observes an
already-green branch. But @anthropic-ai/claude-code ships ~2 releases/day while
Renovate runs every 2-9 days, so every run found a newer version, force-pushed
the branch (resetting CI to pending) and ended seconds later. The last run is
typical: pushed at 19:56:39, run ended 19:56:45, first check went green at
19:56:53, last at 19:59:40 -- nobody was watching. The run that could merge is
always the run that just invalidated CI.

Note this is not fixable with `minimumReleaseAge`: at any threshold there are
still newly-eligible versions by the next run, so the force-push repeats.

Switch to `platformAutomerge: true` so GitHub's native auto-merge merges on
green with no Renovate run involved. This is also the freshest option -- no
version-age delay at all.

Native auto-merge needs something to wait for, i.e. branch protection with a
required check, and a required check that never runs blocks a PR forever. CI is
currently path-filtered at the `on:` level, so a docs-only PR (#123 touches only
README.md and docs/*.md) triggers no CI at all and would deadlock. So drop the
paths filter and add one `CI complete` job aggregating the others, passing on
success-or-skipped so path-filtered builds still don't block. Per-image builds
are still gated by detect-changes; the always-on jobs are lint-only.

Verified with actionlint (exit 0, no findings).

* fix(ci): drop redundant platformAutomerge, soak non-claude bumps, guard the gate

Review follow-ups on this branch.

platformAutomerge:true is Renovate's own default (renovate-schema.json:
platformAutomerge.default = true), so the explicit setting was noise. Deleted
it and kept only the part of the comment that is still load-bearing: what the
config depends on being configured on the GitHub side.

These bumps merge unreviewed and publish to ghcr.io, so a compromised upstream
release would reach the published images with no human in the loop. Added
minimumReleaseAge: '3 days' as a soak period, with a second packageRule
clearing it for @anthropic-ai/claude-code, which is tracked at latest on
purpose. internalChecksFilter defaults to 'strict', so a too-young version is
never offered and the group PR simply carries whichever tools are eligible.

ci-complete is about to become the only required check on master, gating
unattended merges, so two hardening changes:

- A new job added to this workflow but omitted from `needs` would fail while
  the gate stayed green. The first step now derives the job list from the
  workflow file with yq and fails if `needs` has drifted.
- The failure message named a bare result ('failure') with no job attached.
  Iterating toJSON(needs) instead of join(needs.*.result) keeps the job ids,
  so the error now says which job failed and how.

Also recorded why this job uses always() rather than !cancelled(): GitHub
counts a skipped required check as passing, so !cancelled() would turn a
cancelled run into a green gate.

Verified: actionlint exit 0; renovate-config-validator "Config validated
successfully"; both jq filters and the yq job-list extraction exercised
locally against success/skipped/failure/cancelled fixtures.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants