Commit Graph

  • ef50f123a3 chore: bump Claude Code to 2.1.123 and Agent SDK to 0.2.123 main v1.0.110 v1 GitHub Actions 2026-04-29 03:29:24 +00:00
  • b3c0320e7e chore: bump Claude Code to 2.1.122 and Agent SDK to 0.2.122 v1.0.109 GitHub Actions 2026-04-28 22:05:53 +00:00
  • c93e8fe879
    docs: pull_request_target guidance and base-action trust model (#1250) Octavian Guzu 2026-04-28 18:01:48 +01:00
  • 11a9dadd19 chore: bump Claude Code to 2.1.121 and Agent SDK to 0.2.121 v1.0.108 GitHub Actions 2026-04-28 00:31:46 +00:00
  • 6d3147ce1b
    Rename VDP heading to Anthropic Bug Bounty oct/update-h1-links Octavian Guzu 2026-04-27 21:49:34 +00:00
  • 12294c58b3
    Update HackerOne links in SECURITY.md Octavian Guzu 2026-04-27 15:19:35 +00:00
  • 567fe954a4 chore: bump Claude Code to 2.1.119 and Agent SDK to 0.2.119 v1.0.107 GitHub Actions 2026-04-25 01:55:30 +00:00
  • 2da6cfae68 chore: bump Claude Code to 2.1.120 and Agent SDK to 0.2.120 v1.0.106 GitHub Actions 2026-04-25 00:15:05 +00:00
  • e58dfa5555 chore: bump Claude Code to 2.1.119 and Agent SDK to 0.2.119 v1.0.105 GitHub Actions 2026-04-23 23:24:21 +00:00
  • b6dac6f121
    Only pass wrapper defaultSettingSources when project config was restored from base setting-sources-default Octavian Guzu 2026-04-23 17:40:41 +00:00
  • 044a1036f6
    Include issue_comment in event-gated settingSources default Octavian Guzu 2026-04-23 17:24:56 +00:00
  • a551ae4682
    Gate base-action settingSources default on event type Octavian Guzu 2026-04-23 17:21:02 +00:00
  • 12f457aad8
    Apply setting_sources default at runtime instead of via YAML default Octavian Guzu 2026-04-23 17:19:03 +00:00
  • 625ab08afd
    Update MCP server tests for new setting_sources default Octavian Guzu 2026-04-23 17:07:32 +00:00
  • 8dfb31d8a5
    Add setting_sources input and default base-action to user-only Kashyap Murali 2026-03-23 20:04:15 -07:00
  • 6ee201f023
    fix: allow + in branch names (generated by Claude Code EnterWorktree) (#1248) Naoyoshi Aikawa 2026-04-23 14:17:44 +09:00
  • b4d6741327 chore: bump Claude Code to 2.1.118 and Agent SDK to 0.2.118 v1.0.104 GitHub Actions 2026-04-23 00:42:34 +00:00
  • 4e5d8b13ca chore: bump Claude Code to 2.1.117 and Agent SDK to 0.2.117 v1.0.103 GitHub Actions 2026-04-22 00:04:56 +00:00
  • 5d5c10a4f3 chore: bump Claude Code to 2.1.116 and Agent SDK to 0.2.116 v1.0.102 GitHub Actions 2026-04-20 22:18:45 +00:00
  • 632a368e81
    docs: nit updates to security.md (#1240) Octavian Guzu 2026-04-20 15:00:35 +01:00
  • 4c682d8b65
    chore: bump oven-sh/setup-bun to v2.2.0 (Node.js 24) (#1238) Ashwin Bhat 2026-04-19 17:53:46 -07:00
  • 38ec876110 chore: bump Claude Code to 2.1.114 and Agent SDK to 0.2.114 v1.0.101 GitHub Actions 2026-04-18 01:38:24 +00:00
  • 0d2971c794
    fix: pass install.sh binary path explicitly to Agent SDK (#1235) v1.0.100 Ashwin Bhat 2026-04-17 15:50:46 -07:00
  • c68f82cb11 chore: bump Claude Code to 2.1.113 and Agent SDK to 0.2.113 GitHub Actions 2026-04-17 19:40:20 +00:00
  • 78758edf84
    chore: bump model version in workflows (#1227) Ashwin Bhat 2026-04-16 15:25:28 -07:00
  • c3d45e8e94 chore: bump Claude Code to 2.1.112 and Agent SDK to 0.2.112 v1.0.99 GitHub Actions 2026-04-16 20:00:08 +00:00
  • 931e620273 chore: bump Claude Code to 2.1.111 and Agent SDK to 0.2.111 v1.0.98 GitHub Actions 2026-04-16 15:22:22 +00:00
  • 905d4eb99a chore: bump Claude Code to 2.1.110 and Agent SDK to 0.2.110 v1.0.97 GitHub Actions 2026-04-15 22:06:40 +00:00
  • 5fb899572b chore: bump Claude Code to 2.1.109 and Agent SDK to 0.2.109 v1.0.96 GitHub Actions 2026-04-15 04:05:34 +00:00
  • c3bf66dbc2
    fix: handle fork PRs by fetching via refs/pull/N/head (#962) (#963) 不做了睡大觉 2026-04-15 11:33:04 +08:00
  • 3943183052 chore: bump Claude Code to 2.1.108 and Agent SDK to 0.2.108 v1.0.95 GitHub Actions 2026-04-14 19:16:11 +00:00
  • 65f29cf68e chore: bump Claude Code to 2.1.107 and Agent SDK to 0.2.107 GitHub Actions 2026-04-14 06:14:35 +00:00
  • 1c8b699d43 chore: bump Claude Code to 2.1.105 and Agent SDK to 0.2.105 v1.0.94 GitHub Actions 2026-04-13 21:56:13 +00:00
  • ff49ec5fd6
    Prepend system bin dirs to PATH when allowed_non_write_users is set (#1208) Octavian Guzu 2026-04-12 21:51:15 +01:00
  • 25474bfe8b chore: bump Claude Code to 2.1.104 and Agent SDK to 0.2.104 GitHub Actions 2026-04-12 03:21:43 +00:00
  • b47fd721da chore: bump Claude Code to 2.1.101 and Agent SDK to 0.2.101 v1.0.93 GitHub Actions 2026-04-10 19:06:59 +00:00
  • c26cb6427d chore: bump Claude Code to 2.1.100 and Agent SDK to 0.2.98 GitHub Actions 2026-04-10 05:15:24 +00:00
  • 657fb7c9c9 chore: bump Claude Code to 2.1.98 and Agent SDK to 0.2.98 v1.0.92 GitHub Actions 2026-04-09 19:21:28 +00:00
  • 2ff1acb3ee chore: bump Claude Code to 2.1.97 and Agent SDK to 0.2.97 v1.0.91 GitHub Actions 2026-04-08 21:55:30 +00:00
  • b2fdd80112
    Use pinned bun binary for post-steps when allowed_non_write_users is set (#1190) Octavian Guzu 2026-04-08 10:20:15 +01:00
  • 26ddc358fe chore: bump Claude Code to 2.1.96 and Agent SDK to 0.2.96 v1.0.90 GitHub Actions 2026-04-08 04:40:59 +00:00
  • 398370690e chore: bump Claude Code to 2.1.94 and Agent SDK to 0.2.94 GitHub Actions 2026-04-07 21:22:37 +00:00
  • 6cad158a17
    security: reject PATH_TO_CLAUDE_CODE_EXECUTABLE with control characters (#1185) Max Flanagan 2026-04-05 20:26:08 -04:00
  • 0f1fe5ef85
    fix: forward MCP_TIMEOUT, MCP_TOOL_TIMEOUT, MAX_MCP_OUTPUT_TOKENS to action step (#1162) Max Flanagan 2026-04-05 13:37:03 -04:00
  • 6e2bd52842
    fix: pin bun runtime config and improve log hygiene (#1174) v1.0.89 Ashwin Bhat 2026-04-05 07:42:02 -07:00
  • 3534c326a5
    chore: fix prettier formatting in parse-sdk-options.test.ts (#1176) Ashwin Bhat 2026-04-04 23:10:12 -07:00
  • 6685b26dfb
    chore: fix prettier formatting (#1171) Ashwin Bhat 2026-04-04 20:56:18 -07:00
  • 5150ea9643
    fix: snapshot PR's .claude/ to .claude-pr/ before security restore (#1172) Max Flanagan 2026-04-04 23:47:27 -04:00
  • eb8baa46af
    fix: strip shell comment lines before parsing claude_args (#1055) VoidChecksum 2026-04-05 05:26:13 +02:00
  • f328a5c889
    fix: prevent hang in restoreConfigFromBase on repos with .gitmodules (#1166) Max Flanagan 2026-04-04 23:21:28 -04:00
  • b15d4751a6
    fix: allow # in branch names for PR checkout and base restore (#1167) Max Flanagan 2026-04-04 23:17:46 -04:00
  • d5db8208f9
    fix: restore ripgrep execute bits after bun install --production (#1163) Max Flanagan 2026-04-04 23:15:31 -04:00
  • d8af4e9f01
    fix: skip retries for non-retryable errors in retryWithBackoff (#1082) Andrew Grigorev 2026-04-05 06:14:47 +03:00
  • f37c786ad3
    Strip OIDC token request env vars from Claude session (#1011) chyipin 2026-04-04 23:13:05 -04:00
  • 21b0f0f9aa
    fix: use correct fallback type for reviewData in fetcher (#1034) Maxwell Calkin 2026-04-04 23:12:05 -04:00
  • 27f549ae64
    docs: document include/exclude_comments_by_actor inputs (#1130) Mario Yuri Mota Lara 2026-04-05 00:10:29 -03:00
  • 263993d836
    Use env vars for workflow_run context values in example workflows (#1125) David Dworken 2026-04-04 20:10:11 -07:00
  • 85133eeab2
    fix: skip token revocation when no token was acquired (#918) Dave London 2026-04-05 06:09:21 +03:00
  • 1eddb334cf chore: bump Claude Code to 2.1.92 and Agent SDK to 0.2.92 v1.0.88 GitHub Actions 2026-04-04 00:45:34 +00:00
  • 0432df8bfe chore: bump Claude Code to 2.1.91 and Agent SDK to 0.2.91 v1.0.87 GitHub Actions 2026-04-03 00:19:01 +00:00
  • ba026a3e56
    Pass env to execFileSync git calls (#1151) v1.0.86 Octavian Guzu 2026-04-02 21:52:02 +01:00
  • c95e735eb1
    Fix subprocess isolation install step never running (#1148) Octavian Guzu 2026-04-02 14:05:08 +01:00
  • 58dbe8ed68 chore: bump Claude Code to 2.1.90 and Agent SDK to 0.2.90 v1.0.85 GitHub Actions 2026-04-01 23:57:02 +00:00
  • c281e17d7f
    fix: fall back to repo default_branch instead of hardcoded "main" (#1143) Ashwin Bhat 2026-04-01 14:48:46 -07:00
  • 408a40e7c2
    Pin Claude Code to 2.1.87 (#1142) v1.0.84 Ashwin Bhat 2026-04-01 11:29:30 -07:00
  • bee87b3258 chore: bump Claude Code to 2.1.89 and Agent SDK to 0.2.89 v1.0.83 GitHub Actions 2026-04-01 01:13:44 +00:00
  • 32156b120b
    Add subprocess isolation setup and git credential helper (#1132) Octavian Guzu 2026-03-31 12:36:51 +01:00
  • 7225f045c6 chore: bump Claude Code to 2.1.88 and Agent SDK to 0.2.88 GitHub Actions 2026-03-31 00:35:26 +00:00
  • 88c168b39e chore: bump Claude Code to 2.1.87 and Agent SDK to 0.2.87 v1.0.82 GitHub Actions 2026-03-29 02:29:10 +00:00
  • e7b588b6ea chore: bump Claude Code to 2.1.86 and Agent SDK to 0.2.86 v1.0.81 GitHub Actions 2026-03-27 21:50:59 +00:00
  • 094bd24d57 chore: bump Claude Code to 2.1.85 and Agent SDK to 0.2.85 v1.0.80 GitHub Actions 2026-03-26 22:51:40 +00:00
  • 3ac52d0da9 chore: bump Claude Code to 2.1.84 and Agent SDK to 0.2.84 v1.0.79 GitHub Actions 2026-03-26 00:37:42 +00:00
  • 0ee1beea58 chore: bump Claude Code to 2.1.83 and Agent SDK to 0.2.83 v1.0.78 GitHub Actions 2026-03-25 06:35:03 +00:00
  • ff9acae588
    Auto-set subprocess env scrub when allowed_non_write_users is configured (#1093) v1.0.77 Octavian Guzu 2026-03-23 12:10:02 +00:00
  • 6062f37096 chore: bump Claude Code to 2.1.81 and Agent SDK to 0.2.81 v1.0.76 GitHub Actions 2026-03-20 22:30:13 +00:00
  • df37d2f076 chore: bump Claude Code to 2.1.79 and Agent SDK to 0.2.79 v1.0.75 GitHub Actions 2026-03-18 22:39:18 +00:00
  • 1ba15be4f0
    Remove redundant git status/diff/log from tag mode allowlist (#1075) v1.0.74 David Dworken 2026-03-18 09:06:33 -07:00
  • 9ddce40de8
    Restore .claude/ and .mcp.json from PR base branch before CLI runs (#1066) kashyap murali 2026-03-18 09:00:18 -07:00
  • 1b422b3517 chore: bump Claude Code to 2.1.78 and Agent SDK to 0.2.77 v1.0.73 GitHub Actions 2026-03-17 23:47:59 +00:00
  • 72a5802bde
    Close remaining gaps in .mcp.json change protection ashwin/disable-mcp-json-on-pr-change Kashyap Murali 2026-03-17 12:24:27 -07:00
  • 4c044bb2f5 chore: bump Claude Code to 2.1.77 and Agent SDK to 0.2.77 GitHub Actions 2026-03-17 00:33:47 +00:00
  • cd77b50d2b chore: bump Claude Code to 2.1.76 and Agent SDK to 0.2.76 v1.0.72 GitHub Actions 2026-03-14 01:29:31 +00:00
  • 0e80d3c5b8 chore: bump Claude Code to 2.1.75 and Agent SDK to 0.2.75 GitHub Actions 2026-03-13 17:07:33 +00:00
  • f956510b1a
    Harden tag mode tool permissions against prompt injection (#1002) kashyap murali 2026-03-12 13:35:17 -07:00
  • 5d0cc745cd
    feat(inline-comment): add confirmed param + probe-pattern safety net (#1048) v1.0.71 kashyap murali 2026-03-12 00:12:55 -07:00
  • 567be3da98 chore: bump Claude Code to 2.1.73 and Agent SDK to 0.2.73 GitHub Actions 2026-03-11 18:33:26 +00:00
  • eb99fb38f0 chore: bump Claude Code to 2.1.72 and Agent SDK to 0.2.72 GitHub Actions 2026-03-10 00:49:35 +00:00
  • 33fbb80626
    docs: warn that allowed_bots can expose the action to external triggers (#1039) dustin 2026-03-09 13:04:11 -07:00
  • 3428ca8991 chore: bump Claude Code to 2.1.71 and Agent SDK to 0.2.71 GitHub Actions 2026-03-07 00:11:30 +00:00
  • 26ec041249 chore: bump Claude Code to 2.1.70 and Agent SDK to 0.2.70 v1.0.70 GitHub Actions 2026-03-06 01:18:43 +00:00
  • 1fc90f3ed9 chore: bump Claude Code to 2.1.69 and Agent SDK to 0.2.69 v1.0.69 GitHub Actions 2026-03-05 00:24:53 +00:00
  • e763fe78de chore: bump Claude Code to 2.1.68 and Agent SDK to 0.2.68 v1.0.68 GitHub Actions 2026-03-04 10:09:58 +00:00
  • 5f8e5bfe5b chore: bump Claude Code to 2.1.66 and Agent SDK to 0.2.66 v1.0.67 GitHub Actions 2026-03-04 01:17:58 +00:00
  • 73367208d0
    Improve gh.sh wrapper: stricter validation and better error messages (#996) Octavian Guzu 2026-03-02 16:38:23 +00:00
  • 64c7a0ef71
    Only expose permission_denials count in sanitized output (#993) v1.0.66 David Dworken 2026-03-02 01:21:16 -08:00
  • 220272d388
    Change the default display_report option to false to restrict exposed data (#992) v1.0.65 David Dworken 2026-03-01 21:57:53 -08:00
  • ba7fa4bcf0 chore: bump Claude Code to 2.1.63 and Agent SDK to 0.2.63 v1.0.64 GitHub Actions 2026-02-28 03:51:01 +00:00
  • 1dd74842e5 chore: bump Claude Code to 2.1.61 and Agent SDK to 0.2.61 v1.0.63 GitHub Actions 2026-02-26 22:39:58 +00:00
  • 273fe82540 chore: bump Claude Code to 2.1.59 and Agent SDK to 0.2.59 v1.0.62 GitHub Actions 2026-02-26 01:05:07 +00:00
  • e750645f1b
    Add gh.sh wrapper for gh CLI commands in workflows (#975) Octavian Guzu 2026-02-25 20:42:29 +00:00