Summary
Updated CLI and image pins after detecting upstream stable releases for Claude Code, Copilot CLI, Copilot SDK, Codex, Pi, Playwright CLI, Syft, and Grype.
Updates applied
CLI versions
- Claude Code: 2.1.273 → 2.1.282
- Copilot CLI: 1.0.87 → 1.0.88
- Copilot SDK: 1.0.13 → 1.0.14
- Codex: 0.154.0 → 0.157.0
- Pi: 0.87.0 → 0.87.1
- Playwright CLI: 0.1.19 → 0.1.21
Docker images
- SyftImage: anchore/syft:v1.51.1@sha256:95fe0835e5bebc6f8b1f8acef68d47d63d594ef4c0f25c097ff853b23cbac74c → anchore/syft:v1.52.0@sha256:500e2d872ac019436926e8322b4fc1f39441d94d21f6f4046c6ff29b30e8cb02
- GrypeImage: anchore/grype:v0.118.0@sha256:8a93fc48da96bd6ec5981279d099b69de11541dc68fdf222fb9161f8ff284af7 → anchore/grype:v0.119.0@sha256:8c2c9234a345577a6d321a4753aa3ee1276d8975c8452d2344a56b57733ecad3
Release timeline and analysis
Claude Code 2.1.273 → 2.1.282
Release metadata was available via npm; no public GitHub changelog is available.
- Breaking: none observed from package metadata or top-level help output
- Features: no top-level help changes detected
- Fixes: likely included between 2.1.273 and 2.1.282, but upstream does not publish a public changelog in the sources reviewed
- Security: not explicitly documented
- Performance: not explicitly documented
- Impact: low, because the main CLI surface stayed stable in
--help
- Risk: low
- Source: https://www.npmjs.com/package/``@anthropic-ai/claude-code``
CLI help delta observed:
--agents broadened from --agents <json> to --agents <json-or-file>
--bare help text clarifies that built-in features remain active while settings/plugin hooks are skipped
Copilot CLI 1.0.87 → 1.0.88
Release notes, README, and changelog were available from the public repository.
- Breaking: none called out
- Features:
- optional OSC 777 terminal notifications for Ghostty and WezTerm sessions
- better prompt-mode waiting warnings
- support for namespaced custom skills and ignored skill directories
- indexed search glob filtering and
--files listings
/fork during active turns
- Fixes:
- bottom-anchored dialog text selection
- more reliable MCP recovery from transient failures
- session resume reliability improvements
- plugin/server display improvements
- hook
cwd regression fixed
- Security:
- GitHub MCP scope escalation now uses the registered
/callback redirect URI
- enterprise managed settings now apply to more startup modes, reducing policy gaps
- Performance:
- large-session resume keeps transcript memory bounded
- Impact: medium positive for gh-aw because Copilot is a primary engine and MCP behavior, skills discovery, and resume stability directly affect workflows
- Risk: medium-low; CLI surface in top-level help remained stable, but behavior changed in auth, MCP, and managed-policy areas
- Release notes: https://github.com/github/copilot-cli/releases/tag/v1.0.88
- Changelog: https://github.com/github/copilot-cli/blob/main/changelog.md
- README: https://github.com/github/copilot-cli/blob/main/README.md
CLI help delta observed:
- No top-level,
config, or environment help output changes were detected between 1.0.87 and 1.0.88.
Copilot SDK 1.0.13 → 1.0.14
Codex 0.154.0 → 0.157.0
Reviewed release notes for rust-v0.157.0.
- Breaking: none called out
- Features:
- GPT-6 Sol and Luna model additions, including Bedrock support
- fullscreen transcripts enabled by default
- automatic background-server startup for eligible sessions
/import enabled in more session modes
- fork shortcut support
- improved TUI rendering for lists, math, and selections
- Fixes:
- voice conversation preservation
- history/draft recovery improvements
- proxy routing fixes for realtime and web search
- file upload retries and longer upload timeout
- Security:
- Performance:
- background-server startup and state-management work likely improve responsiveness
- several resume/metadata overlap changes reduce latency during restores
- Impact: medium for gh-aw because Codex is a supported engine and network-policy/security changes are relevant to sandboxed runs
- Risk: medium; substantial internal behavior churn despite stable top-level help output
- Release notes: https://github.com/openai/codex/releases/tag/rust-v0.157.0
- Full changelog: openai/codex@rust-v0.156.0...rust-v0.157.0
CLI help delta observed:
- No top-level help changes detected between 0.154.0 and 0.157.0.
Pi 0.87.0 → 0.87.1
No public GitHub changelog was referenced in the package metadata available here.
CLI help delta observed:
- No main help changes detected between 0.87.0 and 0.87.1.
Playwright CLI 0.1.19 → 0.1.21
Reviewed release notes for v0.1.21.
- Breaking: none called out
- Features:
video-start --fps=60
video-start --cursor
video-show-actions style flags
- page snapshots now expose WebMCP tools without requiring
webmcp-list
- new emulation commands:
set-color-scheme, set-reduced-motion, set-forced-colors, set-contrast, set-media, and matching clear commands
- optional absolute file paths in results
- Fixes:
- Security: no explicit security section, but secret redaction handling improved
- Performance: 60 fps video capture support; no explicit runtime perf claims
- Impact: medium for workflows using Playwright tools because new emulation and WebMCP discovery improve browser automation coverage
- Risk: medium-low
- Release notes: https://github.com/microsoft/playwright-cli/releases/tag/v0.1.21
CLI help delta observed:
- New
Emulation: command section appeared in help output, including set-color-scheme, set-reduced-motion, set-forced-colors, and set-contrast.
Docker image updates
SyftImage
- Version: v1.51.1 → v1.52.0
- Release date: 2026-09-17T14:38:17Z
- Cooldown: passed
- Digest: sha256:95fe0835e5bebc6f8b1f8acef68d47d63d594ef4c0f25c097ff853b23cbac74c → sha256:500e2d872ac019436926e8322b4fc1f39441d94d21f6f4046c6ff29b30e8cb02
- Release: https://github.com/anchore/syft/releases/tag/v1.52.0
- Summary:
Syft changelog notes
See full release notes: https://github.com/anchore/syft/releases/tag/v1.52.0
GrypeImage
- Version: v0.118.0 → v0.119.0
- Release date: 2026-09-17T16:45:23Z
- Cooldown: passed
- Digest: sha256:8a93fc48da96bd6ec5981279d099b69de11541dc68fdf222fb9161f8ff284af7 → sha256:8c2c9234a345577a6d321a4753aa3ee1276d8975c8452d2344a56b57733ecad3
- Release: https://github.com/anchore/grype/releases/tag/v0.119.0
- Summary:
Grype changelog notes
See full release notes: https://github.com/anchore/grype/releases/tag/v0.119.0
Deferred or unchanged items
- MCP Gateway remains pinned at v0.4.26 because the latest release was inside the 3-day cooldown window for Docker image version updates.
- GitHub MCP Server remains at v1.12.2, already current.
- Threat-detect remains at v0.5.2, already current.
- Actionlint, Grant, Poutine, Runner Guard, and Yamllint did not require pin changes in this run.
- GHCR anonymous digest lookup for Zizmor, Poutine, and Runner Guard returned 404 from the attempted manifest HEAD flow, so no digest-only changes were inferred from that path.
Validation
make fmt ✅
make recompile ✅
make agent-report-progress-no-test ⚠️ failed due to missing golangci-lint plus pre-existing custom linter findings in pkg/cli/docker_images.go
make agent-report-progress ⚠️ impacted tests passed, but the same lint/custom-lint failures remain
Files changed
pkg/constants/version_constants.go
pkg/cli/docker_images.go
actions/setup/sh/install_copilot_cli.sh
.github/aw/compat.json
Notes
This run also synced the Copilot fallback installer constant and compat matrix max-agent from 1.0.87 to 1.0.88 because the repository’s progress target updates those files to match the new default Copilot pin.
Generated by 🔢 CLI Version Checker · pi · gpt54 · 68.1 AIC · ⌖ 9.59 AIC · ⊞ 10.1K · ◷
Summary
Updated CLI and image pins after detecting upstream stable releases for Claude Code, Copilot CLI, Copilot SDK, Codex, Pi, Playwright CLI, Syft, and Grype.
Updates applied
CLI versions
Docker images
Release timeline and analysis
Claude Code 2.1.273 → 2.1.282
Release metadata was available via npm; no public GitHub changelog is available.
--helpCLI help delta observed:
--agentsbroadened from--agents <json>to--agents <json-or-file>--barehelp text clarifies that built-in features remain active while settings/plugin hooks are skippedCopilot CLI 1.0.87 → 1.0.88
Release notes, README, and changelog were available from the public repository.
--fileslistings/forkduring active turnscwdregression fixed/callbackredirect URICLI help delta observed:
config, orenvironmenthelp output changes were detected between 1.0.87 and 1.0.88.Copilot SDK 1.0.13 → 1.0.14
Codex 0.154.0 → 0.157.0
Reviewed release notes for rust-v0.157.0.
/importenabled in more session modesCLI help delta observed:
Pi 0.87.0 → 0.87.1
No public GitHub changelog was referenced in the package metadata available here.
CLI help delta observed:
Playwright CLI 0.1.19 → 0.1.21
Reviewed release notes for v0.1.21.
video-start --fps=60video-start --cursorvideo-show-actionsstyle flagswebmcp-listset-color-scheme,set-reduced-motion,set-forced-colors,set-contrast,set-media, and matching clear commandsCLI help delta observed:
Emulation:command section appeared in help output, includingset-color-scheme,set-reduced-motion,set-forced-colors, andset-contrast.Docker image updates
SyftImage
Syft changelog notes
See full release notes: https://github.com/anchore/syft/releases/tag/v1.52.0
GrypeImage
ignoredMatchesand--show-suppressed: feat: optionally include internally dropped matches in ignoredMatches anchore/grype#3705Grype changelog notes
See full release notes: https://github.com/anchore/grype/releases/tag/v0.119.0
Deferred or unchanged items
Validation
make fmt✅make recompile✅make agent-report-progress-no-testgolangci-lintplus pre-existing custom linter findings inpkg/cli/docker_images.gomake agent-report-progressFiles changed
pkg/constants/version_constants.gopkg/cli/docker_images.goactions/setup/sh/install_copilot_cli.sh.github/aw/compat.jsonNotes
This run also synced the Copilot fallback installer constant and compat matrix max-agent from 1.0.87 to 1.0.88 because the repository’s progress target updates those files to match the new default Copilot pin.