Repository navigation
chore(deps): update devcontainer agent tools - #124
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/devcontainer-agent-tools
branch
from
September 9, 2026 00:31
9da54f1 to
31d6b72
Compare
gatezh
added a commit
that referenced
this pull request
Sep 9, 2026
`automerge: true` has never merged a PR since it was added in #116. #121 sat open, green and CLEAN for 3.5 weeks; #124 was on the same path. Root cause is a race created by `platformAutomerge: false`. That setting means only a Renovate run can merge, and a run merges when it observes an already-green branch. But @anthropic-ai/claude-code ships ~2 releases/day while Renovate runs every 2-9 days, so every run found a newer version, force-pushed the branch (resetting CI to pending) and ended seconds later. The last run is typical: pushed at 19:56:39, run ended 19:56:45, first check went green at 19:56:53, last at 19:59:40 -- nobody was watching. The run that could merge is always the run that just invalidated CI. Note this is not fixable with `minimumReleaseAge`: at any threshold there are still newly-eligible versions by the next run, so the force-push repeats. Switch to `platformAutomerge: true` so GitHub's native auto-merge merges on green with no Renovate run involved. This is also the freshest option -- no version-age delay at all. Native auto-merge needs something to wait for, i.e. branch protection with a required check, and a required check that never runs blocks a PR forever. CI is currently path-filtered at the `on:` level, so a docs-only PR (#123 touches only README.md and docs/*.md) triggers no CI at all and would deadlock. So drop the paths filter and add one `CI complete` job aggregating the others, passing on success-or-skipped so path-filtered builds still don't block. Per-image builds are still gated by detect-changes; the always-on jobs are lint-only. Verified with actionlint (exit 0, no findings).
gatezh
added a commit
that referenced
this pull request
Sep 9, 2026
* fix(ci): make Renovate auto-merge actually fire `automerge: true` has never merged a PR since it was added in #116. #121 sat open, green and CLEAN for 3.5 weeks; #124 was on the same path. Root cause is a race created by `platformAutomerge: false`. That setting means only a Renovate run can merge, and a run merges when it observes an already-green branch. But @anthropic-ai/claude-code ships ~2 releases/day while Renovate runs every 2-9 days, so every run found a newer version, force-pushed the branch (resetting CI to pending) and ended seconds later. The last run is typical: pushed at 19:56:39, run ended 19:56:45, first check went green at 19:56:53, last at 19:59:40 -- nobody was watching. The run that could merge is always the run that just invalidated CI. Note this is not fixable with `minimumReleaseAge`: at any threshold there are still newly-eligible versions by the next run, so the force-push repeats. Switch to `platformAutomerge: true` so GitHub's native auto-merge merges on green with no Renovate run involved. This is also the freshest option -- no version-age delay at all. Native auto-merge needs something to wait for, i.e. branch protection with a required check, and a required check that never runs blocks a PR forever. CI is currently path-filtered at the `on:` level, so a docs-only PR (#123 touches only README.md and docs/*.md) triggers no CI at all and would deadlock. So drop the paths filter and add one `CI complete` job aggregating the others, passing on success-or-skipped so path-filtered builds still don't block. Per-image builds are still gated by detect-changes; the always-on jobs are lint-only. Verified with actionlint (exit 0, no findings). * fix(ci): drop redundant platformAutomerge, soak non-claude bumps, guard the gate Review follow-ups on this branch. platformAutomerge:true is Renovate's own default (renovate-schema.json: platformAutomerge.default = true), so the explicit setting was noise. Deleted it and kept only the part of the comment that is still load-bearing: what the config depends on being configured on the GitHub side. These bumps merge unreviewed and publish to ghcr.io, so a compromised upstream release would reach the published images with no human in the loop. Added minimumReleaseAge: '3 days' as a soak period, with a second packageRule clearing it for @anthropic-ai/claude-code, which is tracked at latest on purpose. internalChecksFilter defaults to 'strict', so a too-young version is never offered and the group PR simply carries whichever tools are eligible. ci-complete is about to become the only required check on master, gating unattended merges, so two hardening changes: - A new job added to this workflow but omitted from `needs` would fail while the gate stayed green. The first step now derives the job list from the workflow file with yq and fails if `needs` has drifted. - The failure message named a bare result ('failure') with no job attached. Iterating toJSON(needs) instead of join(needs.*.result) keeps the job ids, so the error now says which job failed and how. Also recorded why this job uses always() rather than !cancelled(): GitHub counts a skipped required check as passing, so !cancelled() would turn a cancelled run into a green gate. Verified: actionlint exit 0; renovate-config-validator "Config validated successfully"; both jq filters and the yq job-list extraction exercised locally against success/skipped/failure/cancelled fixtures.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.1.263→2.1.2660.36.0→0.37.11.6.1→1.7.0Release Notes
anthropics/claude-code (@anthropic-ai/claude-code)
v2.1.266Compare Source
CLAUDE_CODE_USE_GATEWAYenvironment variable, previously ignored unlessANTHROPIC_BASE_URLandANTHROPIC_AUTH_TOKENwere both set, began forcing Cloud-gateway sign-in on its own in 2.1.265, so configurations that set it alongside an API key,apiKeyHelper, or custom auth headers failed every request with "Not signed in to the Cloud gateway". The variable on its own is ignored again; no configuration change is neededv2.1.265Compare Source
user.emailanduser.groupsto the telemetry Claude Desktop and Cowork send through a Claude apps gateway, matching terminal sessions--plugin-dirat a folder of plugins: each child folder with a manifest loads, and children added or removed while running are picked up/model opusplan[1m]being rejected with "Model not found"?, Erlang$, or Perl$sigil--bg) sessions occasionally being retired mid-turn when a message arrived just before the idle timeout/add-dir <subdirectory>refusing to load a subdirectory's agents when managed settings lock only skills to plugins, and promising agents when only agents are lockedcontext: fork) not streaming their kickoff prompt and, with--forward-subagent-text, their text turns as progress events in stream-json/pluginwith the error code/pluginDiscover/Browse andclaude plugin list --json --availableshowing no description or display name for marketplace plugins whose metadata lives only in theirplugin.json/loginshowing "no gateway URL is configured" when re-run in a session that signed in to a Claude apps gateway set by managed settings/modelclaiming a model was "saved as your default" when the settings file couldn't be written; it now says the save failed and why/clearfrom Remote Control waiting on SessionStart hooks and on open terminal dialogs before completing/configdialog changing height when switching between its tabsclaude-apiskill's error-code reference: model access failures return 404 and unavailable beta headers return 400, not 403-pwith stream-json input, Agent SDK, cloud sessions) resetting the shell working directory at each new user message; acdnow persists across turnshttpthat only speak the legacy HTTP+SSE transport never connecting; Claude Code now falls back to SSE as the MCP spec describes--worktreestartup on large repositories: the new worktree is now checked out in parallel (git 2.32+)/workflowsagent detail: tool calls are marked running, failed or done, the subagent's task list is shown when it has one, and Enter unfolds the listed calls with their inputs and results.claudefolder permission option to say what it actually allows: editing files in the project's.claudefolder (or~/.claude) for the sessionforceLoginGatewayUrlin managed settings to be Claude apps gateway sessions from startup, likeforceLoginMethod: "gateway"; a leftover claude.ai login or API key is not usedplugin.jsonon the Installed tab andclaude plugin details, filling gaps fromplugin.jsonOTEL_EXPORTER_OTLP_ENDPOINT, instead of through the gateway's relay; sessions without a named collector still use the relayvercel-labs/agent-browser (agent-browser)
v0.37.1Compare Source
Bug Fixes
Contributors
v0.37.0Compare Source
New Features
record startandrecord restartnow capture the current active page at 30 fps by default, support--fps 1-60, usePage.startScreencastfor smoother motion, and preserve wall-clock timing. WebM and MP4 output are documented, anddoctorreports the ffmpeg recording dependencies (#1763, #1776, #1778)tab newor through page clicks now inherit the active session's headers, credentials, user agent, locale, timezone, geolocation, offline mode, routes, color scheme, and init scripts before their first navigation (#1777)Bug Fixes
Contributors
umputun/ralphex (umputun/ralphex)
v1.7.0Compare Source
New Features
Improved
76910af09fe05eFixed
51f0d2584100f4Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.