Skip to content

chore(deps): update ⬆️ mise-packages - #1091

Merged
renovate[bot] merged 2 commits into
mainfrom
renovate/mise-packages
Oct 3, 2026
Merged

renovate[bot] merged 2 commits into
mainfrom
renovate/mise-packages

Conversation

@renovate

@renovate renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending Age Adoption Passing Confidence
aqua:astral-sh/uv tools patch 0.12.19 → 0.12.20 0.12.22 (+1) age adoption passing confidence
aqua:mikefarah/yq tools minor 4.53.6 → 4.54.1 age adoption passing confidence
aqua:openai/codex tools minor rust-v0.158.0 → rust-v0.159.0 rust-v0.160.0 (+3) age adoption passing confidence
aqua:twpayne/chezmoi tools minor 2.72.2 → 2.73.0 age adoption passing confidence
droid (source) minor 0.229.0 → 0.230.0 0.233.0 (+2) age adoption passing confidence
github:anthropics/claude-code tools patch v2.1.283 → v2.1.284 v2.1.288 (+3) age adoption passing confidence
github:backnotprop/plannotator tools patch v0.27.21 → v0.27.22 v0.27.25 (+2) age adoption passing confidence
usage tools minor 6.11.1 → 6.12.0 age adoption passing confidence

Release notes are maintained in a PR comment by the renovate-release-notes-comment workflow.


Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • Between 03:00 AM and 05:59 AM (* 3-5 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Oct 3, 2026
@renovate
renovate Bot requested a review from scottames as a code owner October 3, 2026 10:02
@renovate
renovate Bot enabled auto-merge (squash) October 3, 2026 10:02
@scottames-github-bot

Copy link
Copy Markdown
Contributor

Renovate Release Notes

Generated from Renovate's update table by the renovate-release-notes-comment workflow.

Packages that cannot be summarized from GitHub releases are listed explicitly below.

astral-sh/uv (aqua:astral-sh/uv)

0.12.20: 0.12.20

Compare Source

Release Notes

Released on 2026-09-28.

Enhancements

  • Reuse lockfiles when dependency declarations are semantically equivalent (#21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#21990)

Preview features

  • Write normalized requirement declarations with the lockfile-normalization preview feature (#21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#22050)

Configuration

  • Continue searching XDG_CONFIG_DIRS after empty entries (#21987)

Performance

  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#22051)

Bug fixes

  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#21979)
  • Prevent commands from running and changing state after displaying --show-settings (#21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#22034)

Install uv 0.12.20

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.20/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.20/uv-installer.ps1 | iex"

Download uv 0.12.20

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
uv-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
uv-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
uv-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum
uv-armv7-unknown-linux-gnueabihf.tar.gz ARMv7 Linux checksum
uv-aarch64-unknown-linux-musl.tar.gz ARM64 MUSL Linux checksum
uv-i686-unknown-linux-musl.tar.gz x86 MUSL Linux checksum
uv-riscv64gc-unknown-linux-musl.tar.gz RISCV MUSL Linux checksum
uv-x86_64-unknown-linux-musl.tar.gz x64 MUSL Linux checksum
uv-arm-unknown-linux-musleabihf.tar.gz ARMv6 MUSL Linux (Hardfloat) checksum
uv-armv7-unknown-linux-musleabihf.tar.gz ARMv7 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
mikefarah/yq (aqua:mikefarah/yq)

v4.54.1: v4.54.1 - if-then-else

Compare Source

  • Added jq style if-then-elif-else-end conditional operator (#2871) Thanks to @​anandghegde
  • Added @&#8203;base64url/@&#8203;base64urld operators (RFC 4648 §5) (#2827) Thanks @​MsfPablo
  • Fixed: preserve explicit assignments in read-only expressions (#2850) Thanks @​RRXXZZYY
  • Fixed: error on int64 overflow in +, -, * instead of silently wrapping (#2826) Thanks @​MsfPablo
  • Fixed(toml): quote empty keys (#2870) Thanks @​jakezwang
  • Fixed: /dev/null was triggering colour output (#2852) Thanks @​laraibg786
  • Fixed dead snapcraft confinement link in README (#2840) Thanks @​ShurongCAO
  • Bumped dependencies
openai/codex (aqua:openai/codex)

rust-v0.159.0: 0.159.0

Compare Source

New Features

  • Opt-in instant_interrupt lets new input steer Codex during model responses or long-running code-mode calls. (#48135, #48141)
  • New sessions get a compact welcome screen and consistent headers, with occasional tips during and after turns. (#48513, #48562, #48352)
  • The warnings viewer dismisses reviewed warnings when closed; press k to keep one for later. (#48205, #48206)
  • You can scroll the transcript while deciding whether to implement a plan. (#48805)
  • Native Mermaid rendering supports more flowchart edges, labels, and node groups. (#48814, #48895)
  • App-server clients can paginate thread history from a specific item. (#48151)

Bug Fixes

  • Windows launches avoid stray console windows for MCP servers, code-mode hosts, and piped commands; restrictive launchers can fall back to embedded mode. (#48138, #48238, #48483, #48491)
  • Copying transcript selections preserves Markdown tables, formatting, and significant whitespace. More terminals now copy automatically on selection. (#48548, #48549, #48469)
  • Blank sessions retain drafts when switching tasks, and threads can be archived and listed before their first turn. (#48628, #48828, #48199)
  • Local ChatGPT sign-in opens the browser reliably; onboarding also provides a shortcut to copy the login link. (#48502, #48544)
  • Approved commands retain explicit filesystem denials, and .aws directories are protected by default under writable roots. (#48155, #48176)
  • Fixed macOS TLS access in network-enabled sandboxes and remote environments that require proxy access. (#48565, #48198)

Chores

  • Removed automatic follow-up prompt suggestions and the tui.prompt_suggestions setting. (#48621)
  • Removed the bundled plugin-creator skill. (#48604)

Changelog

Full Changelog: openai/codex@rust-v0.158.0...rust-v0.159.0

  • #48135 Add opt-in code-mode yielding on new user input @​pakrym-oai
  • #48138 Suppress console windows when spawning the code-mode host on Windows @​zm-oai
  • #48141 Preempt model responses when new user input arrives @​pakrym-oai
  • #48143 Preserve executor MCP credential boundaries across reconnects @​rreichel3-oai
  • #48151 Add item anchors to thread/items/list pagination @​btraut-openai
  • #48155 Preserve filesystem denials when preparing approved commands @​viyatb-oai
  • #48157 Allow Windows daemon launches with residual job membership @​etraut-openai
  • #48158 Fix Guardian retained context spacing and empty assistant handling @​olliem-oai
  • #48168 Generate unique exec-server process IDs for every request @​sdcoffey
  • #48174 Preserve usage limit windows in turn and compaction analytics @​rhan-oai
  • #48176 Protect .aws directories under sandbox writable roots @​jackz100
  • #48187 Fix zsh alias quoting in sourced shell snapshots @​jif-oai
  • #48190 Bound agent message board SSE frames before parsing @​jif-oai
  • #48197 Optimize blake3 in Bazel fastbuilds @​jif-oai
  • #48198 Honor execution environment proxy requirements @​seanh-oai
  • #48199 Keep archived threads with empty previews visible in listings @​acrognale-oai
  • #48200 Extract Responses header conversion into a shared module @​anp-oai
  • #48205 Dismiss viewed TUI warnings when closing the viewer @​fcoury-oai
  • #48206 Add a keep-and-next action to the warnings viewer @​fcoury-oai
  • #48207 Preserve queued output for observers during code-mode termination @​pakrym-oai
  • #48211 Keep Codex visible during external editor handoff @​etraut-openai
  • #48213 Isolate executable fixture copies in CLI tests on Linux @​jif-oai
  • #48222 Preserve late result metadata for truncated code-mode calls @​ningyi-oai
  • #48224 Preserve model and access program pairs during compaction @​jamy-OAI
  • #48229 Extract Responses failure parsing into a dedicated module @​anp-oai
  • #48238 Suppress console windows for local Windows MCP servers @​malsamiri-oai
  • #48272 Prevent Windows daemon launches from retaining launcher stdio @​zm-oai
  • #48318 Keep TUI reconnect attempts running until the shared deadline @​etraut-openai
  • #48344 Preserve tool metadata for OpenAI provider endpoint overrides @​peilin-openai
  • #48350 Display reconnect commands on a separate line @​etraut-openai
  • #48352 Show turn tips while working and after completion in the TUI @​fcoury-oai
  • #48353 Stabilize skill catalogs across executor availability changes @​vkg-oai
  • #48469 Default to copying transcript selections in more terminals @​fcoury-oai
  • #48483 Prevent console windows for piped Windows child processes @​fcoury-oai
  • #48489 Fix Mermaid shape, relationship, and state description parsing @​etraut-openai
  • #48491 Fall back to embedded mode under restrictive Windows launchers @​fcoury-oai
  • #48502 Fix ChatGPT browser sign-in for local app servers @​etraut-openai
  • #48508 Preserve WebSocket continuations when steering a turn @​pakrym-oai
  • #48513 Refresh the TUI welcome screen for new sessions @​fcoury-oai
  • #48531 Add context to Windows sandbox runtime registration errors @​zm-oai
  • #48544 Make onboarding login links easier to copy @​etraut-openai
  • #48547 Fade blossom replays back to the idle state @​fcoury-oai
  • #48548 Preserve table cell source metadata through TUI rendering @​fcoury-oai
  • #48549 Preserve Markdown tables and whitespace when copying TUI responses @​fcoury-oai
  • #48551 Fix TUI math rendering for zero and big wedge expressions @​etraut-openai
  • #48560 Keep working tips stable during transcript interaction @​fcoury-oai
  • #48562 Use a consistent borderless session header in the TUI @​fcoury-oai
  • #48565 Allow macOS TLS trust evaluation in network-enabled Seatbelt profiles @​winston-openai
  • #48568 Allow exec-server to proxy permitted private IPs upstream @​open-matt
  • #48574 Preserve deferred tool namespace names before descriptions @​adaley-openai
  • #48575 Allow provisioned executors more time to come online @​richardopenai
  • #48604 Remove the bundled plugin-creator skill @​martinauyeung-oai
  • #48611 Centralize persistent mode enablement checks @​alishobeiri-oai
  • #48621 Remove follow-up prompt suggestions from the TUI @​etraut-openai
  • #48623 Preserve empty Markdown list markers in the TUI @​etraut-openai
  • #48626 Stop showing previous-session summaries when switching TUI sessions @​etraut-openai
  • #48628 Preserve blank TUI sessions when switching tasks @​etraut-openai
  • #48643 Set the provisioned macOS CLI bundle name to ChatGPT @​riley-oai
  • #48646 Fix the session-start helper call in the command center test @​etraut-openai
  • #48686 Remove WebSocket headers and tool payloads from info logs @​chess-oai
  • #48724 Prevent Linux ETXTBSY races in MCP stdio tests @​jif-oai
  • #48725 Retain confirmed Code Mode messages for Guardian reviews @​ankushg
  • #48727 Centralize executable fixture creation to avoid Linux ETXTBSY races @​jif-oai
  • #48754 Render /status without borders and wrap long values @​fcoury-oai
  • #48757 Match TUI status shimmer timing to desktop headers @​fcoury-oai
  • #48761 Show hidden output line counts in compact terminal activity @​fcoury-oai
  • #48764 Preserve MCP app resource URIs without defaulting display mode @​victor-openai
  • #48772 Fix Unix socket connections through long symlink paths @​etraut-openai
  • #48775 Match pinned transcript headers to the original prompt style @​etraut-openai
  • #48776 Remove the current badge from TUI task rows @​etraut-openai
  • #48779 Preserve independent Guardian history across parent compaction @​felixxia-oai
  • #48783 Add single-server MCP status discovery with thread connection reuse @​victor-openai
  • #48796 Add opt-in structured errors for Guardian circuit-breaker interruptions @​won-openai
  • #48799 Fix SGR mouse reporting for Windows terminal capture @​etraut-openai
  • #48800 Use the terminal palette for ordered Markdown list markers @​etraut-openai
  • #48805 Allow transcript wheel scrolling while a modal is open @​fcoury-oai
  • #48807 Show short turn durations in TUI completion footers @​fcoury-oai
  • #48812 Add history-aware prewarming for idle threads @​vkg-oai
  • #48814 Preserve punctuation and semicolons in Mermaid labels @​etraut-openai
  • #48819 Use explicit histogram buckets for tool and skill context metrics @​mzeng-openai
  • #48824 Keep voice RTP timestamps aligned to 20 ms packets @​bc-openai
  • #48827 Show a hand pointer over transcript links in Ghostty and Kitty @​bc-openai
  • #48828 Allow archiving threads before their first turn @​bc-openai
  • #48829 Wait briefly for the Windows sandbox provisioning service to start @​zm-oai
  • #48830 Show a short, neutral TUI interruption notice @​fcoury-oai
  • #48895 Expand native Mermaid flowchart syntax support @​etraut-openai
  • #48973 Isolate realtime auth fallback test from startup prewarm @​jif-oai
  • #48982 Prevent message-board notifications from reopening final answers @​eknight-oai
twpayne/chezmoi (aqua:twpayne/chezmoi)

v2.73.0: v2.73.0

Compare Source

Changelog

Features

  • 1c6895f91841de7b916a0b0a1e4814ab00879d0f feat: Add push command
  • 593166436bf621259efb33d12ebeecd7bae17329 feat: Notify user if chezmoi is not in their PATH in install script

Documentation

  • f4628961795b64a8b3b26a4e04136056443b23dc docs: Add push command to daily operations
  • 0b73091b1c93a19fa9ee2299724c08a74be8e1a0 docs: Align documentation with source
  • e5c1a39158b08ec441fd52f7c1faafc147ea1fc3 docs: Add link to article
anthropics/claude-code (github:anthropics/claude-code)

v2.1.284: v2.1.284

Compare Source

What's changed

  • Added Claude Sonnet 5.5 (claude-sonnet-5-5), now the default Sonnet model on the Anthropic API — 1M context, $2/$10 per Mtok with $0.20/Mtok cache reads
  • Added a "Yes, but ask again next time" answer to auto mode's prompt before a read outside the working directories, so you can allow that one read and still be asked about later ones
  • Added dollar amounts to the Claude apps gateway spend limit in /usage and the status line (for example "$271.40 / $500.00 spent this month") when the gateway runs this version or later; the status line's rate_limits.spend_limit also gains used_usd, limit_usd and period
  • Added effortSlider:decreaseEffort, increaseEffort and toggleUltracode keybinding actions, so the /effort slider's arrow and Tab keys can be rebound in keybindings.json
  • Added /rate-limit-options to /help and the command menu for claude.ai subscribers, so the usage-limit notices that mention it point to a command you can find
  • Added /mcp reconnect all in the interactive terminal to retry every MCP server that failed to connect or needs authentication at once
  • Added Claude apps gateway startup warnings when a managed policy's availableModels is empty, or leaves out the model Claude Code starts on without setting model or enforceAvailableModels
  • Added auth: { google: {} } for Claude apps gateway telemetry.forward_to destinations, so telemetry can be exported straight to Google Cloud's OTLP endpoint using the gateway's Google Cloud credentials
  • Added certificate client authentication (private_key_jwt) between the Claude apps gateway and its identity provider, for identity providers that issue certificate credentials instead of client secrets
  • Fixed a damaged response stream showing raw errors such as "JSON Parse error" or "undefined is not an object", or writing the word "undefined" into an answer, instead of being retried or reported as an interrupted response
  • Fixed an overloaded or server error arriving right after a thinking block ending the turn with an error instead of being retried
  • Fixed "Prompt is too long" errors that persisted after compacting: when the compacted request is still too long, Claude Code now compacts once more, keeping less of the recent conversation
  • Fixed a session whose model is unavailable, with no fallback model left, showing a bare "is currently unavailable" message (or "Something went wrong" in cloud sessions) instead of the model-unavailable notice and its Learn more link
  • Fixed Agent SDK sessions crashing when a user message contains an image with a malformed source, and failing on every later turn after a malformed document block; a malformed image is now replaced with an explanatory note
  • Fixed MCP tool calls in a resumed session failing with "No such tool available" while their server was still connecting; the call now waits up to 10 seconds for the server
  • Fixed repeated calls to the plan-usage endpoint after it rate-limits or rejects your login: /usage, /extra-usage and IDE usage views now back off instead of re-asking
  • Fixed claude mcp add reporting success when managed settings restrict MCP servers to plugins; it now refuses and says what to do, instead of saving a server that never loads
  • Fixed the /plugin configure screen: boolean options are now a true/false choice instead of free text, number options refuse invalid input, and ←/→ change an options field instead of switching tabs
  • Fixed ANTHROPIC_FOUNDRY_RESOURCE being interpolated into the Foundry endpoint host unvalidated; a value that is not a plain resource name is now refused
  • Fixed Claude Desktop behind a Claude apps gateway offering no 1M context option: the gateway now marks each 1M-capable model for Desktop automatically
  • Fixed ↓ in shell mode selecting a hidden background-tasks pill, which stopped Backspace and Ctrl+U from editing the prompt
  • Fixed Bash tool failing on Windows with many plugins enabled: plugin bin/ directories that don't exist are no longer added to PATH, and inherited entries aren't added twice
  • Fixed sparsePaths plugin marketplaces cloning empty and replacing a working local copy on older git (before 2.39), which failed every refresh with "marketplace.json file is no longer present"
  • Fixed fullscreen rendering erasing the terminal output above the session when [ in transcript mode writes the conversation to scrollback (macOS and Linux)
  • Fixed fullscreen scroll position jumping to the previous message or to the bottom when a reply finished streaming while scrolled up
  • Fixed tab bars in dialogs such as /config and /plugin breaking the title and tab labels mid-word in a narrow terminal; a tab that doesn't fit now moves to the next line whole
  • Fixed the /model picker showing "+1 model" below the list after scrolling to the last model; the count now covers only the models below the visible rows
  • Fixed /keybindings writing Backspace and Delete bindings for a footer action that does nothing into the generated keybindings.json
  • Fixed a rebound agent panel close key (footer:close) typing "x" instead of itself on the row of the agent you're viewing
  • Fixed vim mode . not repeating text typed very fast (for example over ssh or in tmux) or pasted without bracketed paste, and leaving the prompt in INSERT mode after repeating a change with nothing typed (such as cw then Esc)
  • Fixed vim mode leaving the cursor on an image placeholder's opening bracket after dd on the last line or yy at the end of the prompt, where r or x would break or delete the image
  • Fixed a key pressed the instant the terminal regained focus answering the Remote Control enable prompt before its short safety delay restarted
  • Fixed the workspace trust dialog appearing a second time after switching renderers or updating when Claude Code was started in the home directory
  • Fixed rules symlinked into .claude/rules from outside the project being skipped without ever showing the external-imports approval prompt; a .claude directory symlinked from outside the project now asks for the same approval
  • Fixed plugins from marketplaces, claude.ai and npm pre-approving their own tools via allowed-tools under managed allowManagedPermissionRulesOnly; only plugins from an official Anthropic source or a source that managed settings vouch for keep that pre-approval
  • Fixed a failed first claude plugin install leaving the plugin enabled and recorded when a dependency's version range could not be met
  • Fixed the debug log dropping a failed hook's stderr when the hook also wrote to stdout, and logging nothing for a failed hook with no output; failed hooks now also log their status code
  • Fixed {"decision":"block"} returned by Elicitation and ElicitationResult hooks being ignored; it now declines the MCP elicitation, as exit code 2 does
  • Fixed sessions launched without the SendMessage tool (such as by Claude Desktop) still being told to message other sessions with it
  • Fixed a photo sent from the Claude app over Remote Control being lost when its queued message was pulled back into the terminal prompt to edit, and the cursor moving one character for a photo with no caption
  • Fixed typing a message during an automatic usage-limit wait taking the wait out of the "Continue automatically at usage limit" setting's control when that turn hit the limit again
  • Fixed usage-limit warnings suggesting /upgrade to users already on the highest Max plan; the warnings and /upgrade itself now point at /usage-credits when it is available
  • Fixed the Explore subagent switching to Opus on the Claude API when the session runs a model ID Claude Code doesn't recognize, such as a custom model behind a proxy; Explore now inherits that model
  • Fixed /loop status updates in self-paced mode often not being shown because Claude wrote them only in its reasoning; Claude now writes each update, and the outcome when the loop stops, as visible text
  • Fixed /ultrareview failing to upload the working tree when started from a git worktree that the Claude desktop app created on macOS or Linux
  • Fixed sandboxed Bash commands failing to start on Linux when the working directory is write-denied and contains a read-denied directory
  • Fixed artifact database write results telling Claude that every viewer sees a write to a viewer's private data/users/ subtree, and added a "view" level to as_level
  • Fixed the Claude apps gateway answering 431 Request Header Fields Too Large to every request from a sign-in whose identity provider lists many groups; it now accepts request headers up to 256 KiB
  • Improved the usage-limit wait: the limit's state and the countdown with the usage-credits option now show as one block under the prompt, and limit messages no longer repeat the countdown
  • Improved the "No such tool available" error for Claude in Chrome tools called without their prefix: it now names the tool to call
  • Improved Monitor event rows to show what each event printed instead of repeating the description, and stopped repeating an unchanged "Waiting for N … to finish" line after every event
  • Improved Workflow tool sandbox hardening for errors thrown by async script hooks
  • Improved startup time and memory use by building only the parts of the settings schema that your settings files actually use
  • Improved /claude-api: hillclimb no longer spends rounds on prompt rewordings too small for the eval to measure, and an extra page you ask for beside report.html is built as one local file that loads nothing from the network
  • Improved lists such as /tasks, /copy and /hooks: the details after each name now line up in one column when they fit, and otherwise sit at the right edge
  • Improved claude plugin marketplace add to say when it replaces a marketplace already added under the same name from a different source, and how to undo it
  • Improved the startup refusal when managed settings require a sign-in (forceLoginMethod or forceLoginOrgUUID) and an API key, token or apiKeyHelper is configured: it now names the credential in use, where it is set, and how to remove it
  • Improved auto-memory loading: invisible characters and tags that imitate Claude Code's own markup are neutralized in MEMORY.md and recalled memory notes before they reach Claude
  • Improved claude remote-control: in a folder you haven't trusted yet, it now asks for workspace trust on the terminal instead of exiting
  • Improved artifact pages: Claude writes its design plan into the page instead of the reply, and uses the name you already gave something as the page title
  • Improved the Artifact tool so that when Claude is given a claude.ai chat or project link, an artifact from a chat, or an artifact id on its own, it asks for the right link or the content instead of stopping
  • Changed interactive terminal and VS Code sessions to start in auto mode when no permission mode is configured, on every plan and provider; permissions.defaultMode still overrides it
  • Changed Ultracode into its own toggle in /effort (Tab, or /effort ultracode [on|off]): it no longer forces xhigh effort and stays on at any effort level
  • Changed retries after a dropped connection mid-response to share one budget with the rest of the request's retries, so a failing request gives up sooner
  • Changed the notice shown when a Sonnet model's safeguards flag a message to explain why it happened and to offer editing and retrying
  • Changed safety-related model switches in sessions that pin an Opus model with ANTHROPIC_DEFAULT_OPUS_MODEL or modelOverrides: on the Anthropic API, the API now picks the model to switch to for each kind of flag, not the pinned model
  • Changed the non-interactive first turn to still wait up to 2s for connecting MCP servers named by --allowedTools or an mcp_tool hook, even when CLAUDE_CODE_MCP_STARTUP_WAIT_MS is 0
  • Changed /recap to decline with a short notice when it arrives relayed from a chat thread (your own included) or from a routine or webhook; typed in the terminal, the Claude apps, Remote Control, -p or an SDK host, it runs as before
  • Changed /artifacts to show its filter tabs beside the title with one-word labels (All, Mine, Shared), using the same tab bar as /config and /plugin
  • Changed artifact publishing to refuse a file on a network share (a \\host\share path or a /net automount) unless it is on a mapped network drive added with --add-dir
  • [VSCode] Added an optional time above each prompt and response, with a date line where the day changes (Claude Code: Show Message Timestamps setting, off by default)
  • [VSCode] Added plugin load errors and notes to the Manage plugins rows, with a popup to disable, uninstall or copy the error
  • [VSCode] Added an Ultracode on/off switch under the Effort slider, replacing the slider's Ultracode stop; the model pill shows "· Ultracode" at any effort level
  • [VSCode] Fixed Reload Claude from the Memory dialog restarting before an edited file was saved
  • [VSCode] Fixed a restored tab opening a conversation another Claude process still has open; it now asks first
  • [VSCode] Fixed Focus view sections you expanded closing on their own while a sub-agent is working or when the section's first step is trimmed from view
  • [VSCode] Fixed typing /model and Enter printing usage text into the chat instead of opening the model selector
  • [VSCode] Fixed /feedback on Vertex, Bedrock and Foundry being refused after you pressed Send; the report is now saved on this computer, as the terminal does
  • [VSCode] Fixed sign-in waiting up to a minute for the Python extension after a window reload
  • [VSCode] Fixed Claude Code tabs that stopped responding after Restart Extensions: they now reopen on their conversation
  • [VSCode] Fixed a message from another agent with no recorded sender showing as raw XML in the chat
  • [VSCode] Fixed messages from other agents, sessions or channels disappearing after a reload
  • [VSCode] Fixed a user's own /mcp, /config or /settings command being shadowed by the extension's dialog
  • [VSCode] Fixed Escape stopping every background agent when no turn was running
  • [VSCode] Fixed plugin install links replacing a marketplace you already have that uses the same name
  • [VSCode] Fixed "Prompt is too long" errors after compaction when a large text file is attached to a message
  • [VSCode] Fixed chat links to files with non-ASCII characters, spaces or brackets in their path not opening
  • [VSCode] Changed CLAUDE_CONFIG_DIR in the claudeCode.environmentVariables setting to apply only when it is an absolute path, and passed it to terminals that continue the chat
  • [Cloud sessions] Fixed a routine's Edit and Duplicate controls saying the routine was still loading while you were offline; they now tell you you're offline
  • [Claude Tag] Added model family choices such as "Opus (latest)" for a thread, a channel default or your DM, so the choice follows the newest model in that family
  • [Claude Tag] Added the spend that counts toward your organization-wide limit to the analytics spend projection chart, with how much of the limit is used
  • [Claude Tag] Fixed the earlier Claude in Slack app's progress card and link previews omitting the repository and Create PR button when a GitHub Enterprise host name contains an underscore
  • [Claude Tag] Fixed Claude staying silent in a channel whose environment declines to start it; it now posts one notice asking you to contact an admin, and retries when @​-mentioned
  • [Claude Tag] Changed Claude to post its private sign-in notice at every @​mention from someone who hasn't connected their Claude account, instead of going quiet after the first
  • [Claude Tag] Improved "Notify members now" in admin settings: one press reaches every workspace your organization claimed in an Enterprise Grid, and more members in large workspaces
  • [Claude Tag] Improved Claude's wait notice on self-hosted environments with on-demand runners: it now says whether a runner is starting, a start will be retried, or no runner will start
  • [Claude Tag] Improved the error shown when adding a channel manager fails because the channel's Slack workspace can't be confirmed as connected to your organization
  • [Claude Tag] Improved a channel's access lists in admin settings to show the connectors, repositories and plugins an auto-join pattern attaches, and where each comes from
  • [Claude Tag] Improved adding repositories as a channel manager: when your GitHub sign-in can't confirm you're a repository admin, the page asks you to sign in with GitHub
  • [Code Review] Fixed Code Review giving up without posting a finished review when an unsubmitted review under its GitHub App was open on the pull request; it now retries the post first
backnotprop/plannotator (github:backnotprop/plannotator)

v0.27.22: v0.27.22

Compare Source

Follow @​plannotator on X for updates

Missed recent releases?

Release Highlights
v0.27.21 Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocks
v0.27.19 Before/After image previews in code review, file comments as GitHub file threads, forge-correct #123 links, /plannotator-last finds the right session
v0.27.18 Model pickers from your installed Claude and Codex (Opus 5.5, Fable 5.1, GPT-6), unsent PR review comments survive new pushes
v0.27.17 Diagram files open in the diagram viewer, OpenCode switches model with agent, idle review stops polling the git remote, Tree is the default review view
v0.27.16 Themed diagrams on Mermaid 12, comment on any node or edge, patch-file review, embedded HTML documents render
v0.27.15 Plannotator TUI and Herdr Annotate announcement, element context on pinpoints, HTML links open as linked documents, All files panel, Classic diff default
v0.27.14 Pi plan progress survives compaction, Codex threads across rollout files, WSL browser setting, Mod+E edit mode
v0.27.13 Open a review on a specific base (--base, --diff-type), symlink containment on /api/doc, CI flake fix, Amp decision relay
v0.27.12 Unified decision control, token hover cards, local-vs-remote diff, approval notes
v0.27.11 OpenCode server leak fix, durable local feedback archive, unknown-subcommand fix
v0.27.10 Auto-viewed files on scroll, annotation undo/redo, OpenCode 2 slash commands restored, npm 12 agent terminal fix

What's New in v0.27.22

A fix release. Plans can open the documents they link to, Claude review jobs are locked down more tightly, Code Tour works on Linux machines where Claude Code's sandbox cannot start, and Pi no longer reviews an outdated plan. Eight pull requests, two of them from community contributors, answering four reports.

Plans can open the documents they link to

Claude Code saves plans in ~/.claude/plans/, outside your project. Plannotator only looked inside the project for linked files, so a plan that linked [notes](notes.md) or [[notes]] to a file saved beside it showed a link that went nowhere.

Plan review now also looks in the plan file's own folder, but only for files the plan actually links to, matched by exact name. Every plan you have ever made lives in that folder, so a plan can open its own notes without being able to reach any other plan. Links inside code blocks do not count, and plans kept inside the project still fall back to the project root as before. If a file beside the plan has the same name as a project file, the one beside the plan wins.

(#1620, closing #1443, by @​bendrucker)

Claude review jobs are locked down

Code review, Code Tour and Guided Review run Claude Code with a list of read-only commands they are allowed to use. That list had grown looser than its purpose: a few entries accepted options that could run other programs or write files, and the review prompt contains the diff under review, which is untrusted text. For most people, Claude Code's own sandbox is off, so that list was the only thing standing between a hostile diff and the machine.

The list is now narrowed to the commands the prompts actually use, shared by all three job types, with the risky options explicitly refused. Jobs also no longer read a repository's own .claude/settings.json, so a pull request you are reviewing cannot add permissions or hooks to the job. Your personal Claude Code settings and any managed settings still apply. Jobs no longer load your MCP servers either; before, a Code Tour could wander into tools from your IDE.

(#1628, #1629)

Code Tour on Linux when Claude Code's sandbox cannot start

If your Claude Code settings enable its sandbox and the machine lacks bubblewrap and socat, the sandbox fails to start and Claude refuses every command. Code Tour then ended with "Tour blocked: git access is unavailable" and no hint why.

Now, when a Claude job has every ordinary git command refused, the Agents tab shows a warning explaining what happened. You can install those two packages, or turn Claude's sandbox off for Plannotator's jobs only with PLANNOTATOR_CLAUDE_SANDBOX=0 or { "claudeSandbox": false } in ~/.plannotator/config.json. Plannotator never turns the sandbox off on its own, since that would quietly override a choice you made.

(#1628, closing #1627, reported by @​Infeligo)

Pi reviews the plan you just wrote

Pi runs all the tool calls in one assistant message at the same time. When the agent edited the plan and submitted it in the same message, the submit could read the file before the edit landed, so the review opened on the previous version and version history recorded it. The submit tool now tells Pi to run its batch in order, so the edit always finishes first. Every Pi version the extension supports honors this.

(#1623, closing #1622, reported by @​bugs-wkettlitz)

Additional Changes

  • Claude reviews no longer fail after producing findings. Recent Claude Code versions can end one run with several result messages when the model uses background subagents, and the last one is often empty. Plannotator read only the last message, so about one code review in three was marked failed even though Claude had returned findings. Review, Code Tour and Guided Review now read the newest message that carries results (#1630).
  • VS Code tabs follow a changed data folder. Plannotator looked up VS Code's connection file once at startup, so setting PLANNOTATOR_DATA_DIR later made opening a review in VS Code quietly fall back to the browser. It now looks the file up each time (#1621, closing #1502, by @​gwynnnplaine).
  • Tests stay out of your data folder. Running the test suite from a package directory wrote drafts, history and saved plans into the real ~/.plannotator, and a personal config could make tests fail. Every package now uses the same temporary data folder the root run does (#1624, #1626).

Install / Update

macOS / Linux:

curl -fsSL https://plannotator.ai/install.sh | bash

Windows:

irm https://plannotator.ai/install.ps1 | iex

Claude Code Plugin: Run /plugin in Claude Code, find plannotator, and click "Update now".

Pi: Update @&#8203;plannotator/pi-extension to 0.27.22 and restart Pi.

OpenCode: Clear cache and restart:

rm -rf ~/.bun/install/cache/@&#8203;plannotator

What's Changed

  • fix(server): resolve the VS Code IPC registry path per call by @​gwynnnplaine in #1621
  • fix(plan): open docs linked beside the plan file by @​bendrucker in #1620
  • fix(pi): run plannotator_submit_plan sequentially so it never reads a stale plan by @​backnotprop in #1623
  • test(pi): sandbox review-server tests from the user's config by @​backnotprop in #1624
  • test: sandbox the data dir when tests run from a package directory by @​backnotprop in #1626
  • fix(agents): hermetic Claude review jobs + sandbox opt-out for Linux by @​backnotprop in #1628
  • security(agents): narrow Claude job command allowlists to what the prompts use by @​backnotprop in #1629
  • fix(agents): read structured output from any Claude result event, not just the last by @​backnotprop in #1630

Contributors

@​bendrucker made plans able to open the notes and documents saved next to them, a gap every Claude Code user with multi-file plans ran into.

@​gwynnnplaine tracked down the last module that froze the data folder at startup and fixed it with tests that reproduce the bug.

Community

  • @​bugs-wkettlitz diagnosed the Pi race down to pi's parallel tool execution and proposed the exact fix in #1622
  • @​Infeligo reported Code Tour failing on Linux, with the full tool log, in #1627

Full Changelog: backnotprop/plannotator@v0.27.21...v0.27.22

jdx/usage (usage)

v6.12.0: v6.12.0: Delegated shell completion, command-backed choices, and usage_cmd for scripts

Compare Source

Wrapper CLIs can now pass completion of their trailing words to the wrapped tool's own shell completion. Argument values can come from a command's output with choices run=, and scripts get the chosen subcommand as $usage_cmd. The release also fixes several completion bugs in bash, zsh and fish, and two crashes in #[derive(Cli)] binaries.

Added

  • (complete) complete … delegate="<command>" completes a wrapped command's arguments with that command's own shell completion (#1498, @​jdx). With the spec below, wrapper layer1 plan -o<Tab> offers whatever terraform plan -o<Tab> would. delegate can carry fixed arguments (delegate="kubectl --context prod"), and it can't be combined with run or type. It works in fish, bash (requires bash-completion) and zsh. PowerShell and Nushell get no delegated candidates. Typed words are passed to the shell as arguments, not spliced into a script, so they are never run. If the shell can't answer within 3 seconds, completion falls back to files. Fig output leaves delegated args bare.

    arg "<layer>"
    arg "<command>" var=#true
    complete "command" delegate="terraform"
  • (spec) choices run="…" builds an argument's or flag's allowed values from a command that prints one value per line (#1497, @​jdx). These values are used to check input (strict and ignore_case still apply), for Tab completion, and in --help handled by the parser, usage bash and usage exec. Any values written on the node are kept alongside them. Static outputs never run the command. render_help, Markdown and man pages describe it as output of `…` , Fig emits a generator, and Go tables and TypeScript/Python SDK types treat the value as an open string. During a parse, the command runs at most once and only when a declared value doesn't match. Parser::with_env values are passed to it. New library API includes SpecChoices::run, resolved_values(env), SpecArgBuilder::choices_run, usage::docs::cli::render_runtime_help and usage::sh::sh_with_env. Fig generator commands, from both choices run= and complete run=, now escape backslashes, backticks and ${.

    arg "<service>" {
      choices run="docker compose config --services"
    }
  • (spec) A complete node can now sit inside the arg it completes, including a flag's arg, or directly inside a flag as shorthand for its value (#1496, @​jdx). The inline form takes run, type and descriptions but no name. It takes precedence over a named complete "<name>" for the same arg. The new Spec::completer(cmd, arg) applies this order, and complete-word, Fig, usage-dynamic and the Go generator all follow it.

    flag "--out <path>" {
        complete type="dir"
    }
  • (lib) Scripts run by usage bash, zsh, fish, powershell and exec get the chosen subcommand's canonical name in usage_cmd, with nested names joined by spaces, such as "db migrate" (#1505, @​jdx). It is unset at the top level, and a usage_cmd inherited from a parent process is cleared. If the spec declares its own flag or arg named cmd, that one keeps the variable. The value comes from ParseOutput::as_env, so other embedders such as mise tasks get it too.

  • (lib) FlagMeta, CommandMeta and ArgMeta in usage-rs/usage-argv have a const fn getter for every field, including the fields that 6.11.1 moved into extra (#1491, @​jdx). For example, flag.env_fallback() works however the struct is laid out. The fields stay public for now, but v7 plans to hide them, so switch to the getters.

  • (lib) Parser::without_running_commands() parses without starting any choices run= command (#1503, @​jdx). A value outside the declared choices is accepted unchecked. usage explain now uses this mode, so explaining a command line against an untrusted spec never runs that spec's commands.

  • (cli) Releases now ship a version-matched usage agent skill for writing specs, parsing script arguments, using usage explain, and generating completions and docs (#1509, @​jdx). mise users can install it with mise use usage and then mise skills sync --dir .agents/skills.

Fixed

  • (derive) A generated Cli::parse() no longer panics when output goes to a closed pipe, for example with mycli --help | head -1 or a cancelled completion (#1484, @​jdx). Before, panic = "abort" builds aborted with SIGABRT. Exit statuses are unchanged.
  • (derive) Async dispatch generated by #[usage(run_async)] and run_async_with now boxes the selected command's future (#1488, @​jdx). Before, debug builds reserved stack for every command's future at each dispatch level, which could overflow the stack in large CLIs (for example, STATUS_STACK_OVERFLOW on Windows). This costs one heap allocation per dispatch level. The API is unchanged.
  • (derive) A renamed usage-rs dependency inherited from [workspace.dependencies] now resolves even when an earlier entry uses a multi-line inline table (#1507, @​jdx). The derive now reads manifests with a real TOML parser.
  • (complete) Typed completers (#[usage(complete = my_fn)]) now receive the command line when called through a spec's run= (#1487, @​jdx). CompletionRequest::parse used to ignore --line=… and now accepts --option=value for every option that takes a value.
  • (complete) A command line that doesn't parse no longer prints an error over the prompt when you press Tab (#1495, @​jdx). zsh shows the message below the prompt with _message. bash, fish and Nushell discard it.
  • (bash) Values for --flag=value now complete when the cursor is after the =, in both per-binary scripts and the completion-init handler (#1499, @​jdx).
  • (fish) Words you've started quoting or escaping now complete: 'prod<Tab> finds 'prod env' (#1500, @​jdx). Text after the cursor is no longer sent. Multi-line help no longer shows up as extra fake candidates in fish, zsh, Nushell or PowerShell.
  • (zsh) With completion-init zsh sourced, file completion for commands that aren't usage scripts works normally again, including in cases like emacs --<Tab> that used to insert a literal * (#1493, @​jdx). The fix applies from the next shell start.
  • (cli) usage bash <(…), /dev/stdin and other pipe or FIFO script paths used to run an empty script and exit 0. usage now copies the script to a private temp directory first, for bash, zsh, fish and PowerShell (#1494, @​jdx).
  • (lib) The published usage-rs crate's tests now pass on their own, so downstream packagers such as Debian can test the released source (#1510, @​jdx).

Changed

  • All crates now use the Rust 2024 edition, and the minimum supported Rust version stays at 1.91 (#1511, @​jdx). Public macros accept 2024 expression syntax such as var_min = const { 1 }. Generated shadow crates rename reserved field names such as --gen to gen_.

Upgrading

Regenerate completion scripts made with usage generate completion <shell> <bin> to get the fixes from #1495 (all shells), #1499 (bash) and #1500 (fish). If you use completion-init, just start a new shell.

Full Changelog: jdx/usage@v6.11.1...v6.12.0

💚 Sponsor usage

usage is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If usage powers CLI specs, docs, or completions for a tool you maintain or use, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep usage fast, free, and independent.

Skipped Packages

GitHub Release Notes Unavailable

  • droid: No GitHub release was found for 0.230.0

@renovate
renovate Bot force-pushed the renovate/mise-packages branch from 9d3245a to e213b13 Compare October 3, 2026 12:34
@renovate
renovate Bot merged commit 8e3e4a2 into main Oct 3, 2026
6 checks passed
@renovate
renovate Bot deleted the renovate/mise-packages branch October 3, 2026 12:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants