Skip to content

[ca] Update CLI and scanner pins for latest stable releases #63364

Description

@github-actions

Summary

Updated CLI and image pins after detecting upstream stable releases for Claude Code, Copilot CLI, Copilot SDK, Codex, Pi, Playwright CLI, Syft, and Grype.

Updates applied

CLI versions

  • Claude Code: 2.1.273 → 2.1.282
  • Copilot CLI: 1.0.87 → 1.0.88
  • Copilot SDK: 1.0.13 → 1.0.14
  • Codex: 0.154.0 → 0.157.0
  • Pi: 0.87.0 → 0.87.1
  • Playwright CLI: 0.1.19 → 0.1.21

Docker images

  • SyftImage: anchore/syft:v1.51.1@sha256:95fe0835e5bebc6f8b1f8acef68d47d63d594ef4c0f25c097ff853b23cbac74c → anchore/syft:v1.52.0@sha256:500e2d872ac019436926e8322b4fc1f39441d94d21f6f4046c6ff29b30e8cb02
  • GrypeImage: anchore/grype:v0.118.0@sha256:8a93fc48da96bd6ec5981279d099b69de11541dc68fdf222fb9161f8ff284af7 → anchore/grype:v0.119.0@sha256:8c2c9234a345577a6d321a4753aa3ee1276d8975c8452d2344a56b57733ecad3

Release timeline and analysis

Claude Code 2.1.273 → 2.1.282

Release metadata was available via npm; no public GitHub changelog is available.

  • Breaking: none observed from package metadata or top-level help output
  • Features: no top-level help changes detected
  • Fixes: likely included between 2.1.273 and 2.1.282, but upstream does not publish a public changelog in the sources reviewed
  • Security: not explicitly documented
  • Performance: not explicitly documented
  • Impact: low, because the main CLI surface stayed stable in --help
  • Risk: low
  • Source: https://www.npmjs.com/package/``@anthropic-ai/claude-code``

CLI help delta observed:

  • --agents broadened from --agents <json> to --agents <json-or-file>
  • --bare help text clarifies that built-in features remain active while settings/plugin hooks are skipped

Copilot CLI 1.0.87 → 1.0.88

Release notes, README, and changelog were available from the public repository.

  • Breaking: none called out
  • Features:
    • optional OSC 777 terminal notifications for Ghostty and WezTerm sessions
    • better prompt-mode waiting warnings
    • support for namespaced custom skills and ignored skill directories
    • indexed search glob filtering and --files listings
    • /fork during active turns
  • Fixes:
    • bottom-anchored dialog text selection
    • more reliable MCP recovery from transient failures
    • session resume reliability improvements
    • plugin/server display improvements
    • hook cwd regression fixed
  • Security:
    • GitHub MCP scope escalation now uses the registered /callback redirect URI
    • enterprise managed settings now apply to more startup modes, reducing policy gaps
  • Performance:
    • large-session resume keeps transcript memory bounded
  • Impact: medium positive for gh-aw because Copilot is a primary engine and MCP behavior, skills discovery, and resume stability directly affect workflows
  • Risk: medium-low; CLI surface in top-level help remained stable, but behavior changed in auth, MCP, and managed-policy areas
  • Release notes: https://github.com/github/copilot-cli/releases/tag/v1.0.88
  • Changelog: https://github.com/github/copilot-cli/blob/main/changelog.md
  • README: https://github.com/github/copilot-cli/blob/main/README.md

CLI help delta observed:

  • No top-level, config, or environment help output changes were detected between 1.0.87 and 1.0.88.

Copilot SDK 1.0.13 → 1.0.14

Codex 0.154.0 → 0.157.0

Reviewed release notes for rust-v0.157.0.

CLI help delta observed:

  • No top-level help changes detected between 0.154.0 and 0.157.0.

Pi 0.87.0 → 0.87.1

No public GitHub changelog was referenced in the package metadata available here.

CLI help delta observed:

  • No main help changes detected between 0.87.0 and 0.87.1.

Playwright CLI 0.1.19 → 0.1.21

Reviewed release notes for v0.1.21.

CLI help delta observed:

  • New Emulation: command section appeared in help output, including set-color-scheme, set-reduced-motion, set-forced-colors, and set-contrast.

Docker image updates

SyftImage

Syft changelog notes

See full release notes: https://github.com/anchore/syft/releases/tag/v1.52.0

GrypeImage

Grype changelog notes

See full release notes: https://github.com/anchore/grype/releases/tag/v0.119.0

Deferred or unchanged items

  • MCP Gateway remains pinned at v0.4.26 because the latest release was inside the 3-day cooldown window for Docker image version updates.
  • GitHub MCP Server remains at v1.12.2, already current.
  • Threat-detect remains at v0.5.2, already current.
  • Actionlint, Grant, Poutine, Runner Guard, and Yamllint did not require pin changes in this run.
  • GHCR anonymous digest lookup for Zizmor, Poutine, and Runner Guard returned 404 from the attempted manifest HEAD flow, so no digest-only changes were inferred from that path.

Validation

  • make fmt ✅
  • make recompile ✅
  • make agent-report-progress-no-test ⚠️ failed due to missing golangci-lint plus pre-existing custom linter findings in pkg/cli/docker_images.go
  • make agent-report-progress ⚠️ impacted tests passed, but the same lint/custom-lint failures remain

Files changed

  • pkg/constants/version_constants.go
  • pkg/cli/docker_images.go
  • actions/setup/sh/install_copilot_cli.sh
  • .github/aw/compat.json

Notes

This run also synced the Copilot fallback installer constant and compat matrix max-agent from 1.0.87 to 1.0.88 because the repository’s progress target updates those files to match the new default Copilot pin.

Generated by 🔢 CLI Version Checker · pi · gpt54 · 68.1 AIC · ⌖ 9.59 AIC · ⊞ 10.1K · ◷

  • expires on Sep 26, 2026, 9:39 PM UTC-08:00

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    automationcookieIssue Monster Loves Cookies!dependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions