Repository navigation
chore(deps): update ⬆️ aqua-packages - #849
Merged
Merged
Conversation
1 task
1 task
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2.1.100→v2.1.104v2.1.112(+6)v1.0.22→v1.0.24v1.0.31(+6)v1.15.2→v1.15.3v2026.4.8→v2026.4.11v2026.4.16(+4)v0.35.3→v0.36.0v0.38.0(+2)0.111.0→0.112.10.112.2v0.118.0→v0.120.0v0.121.0v4.9.3→v4.10.1v1.8.3→v1.8.4Release Notes
anthropics/claude-code (anthropics/claude-code)
v2.1.104Compare Source
v2.1.101Compare Source
What's changed
/team-onboardingcommand to generate a teammate ramp-up guide from your local Claude Code usageCLAUDE_CODE_CERT_STORE=bundledto use only bundled CAs)/ultraplanand other remote-session features now auto-create a default cloud environment instead of requiring web setup firstclaude -p --resume <name>to accept session titles set via/renameor--namesettings.jsonno longer causes the entire file to be ignoredallowManagedHooksOnlyis set/pluginandclaude plugin updateto show a warning when the marketplace could not be refreshed, instead of silently reporting a stale versionOTEL_LOG_USER_PROMPTS,OTEL_LOG_TOOL_DETAILS, andOTEL_LOG_TOOL_CONTENT; sensitive span attributes are no longer emitted unless opted inquery()to clean up subprocess and temp files when consumersbreakfromfor awaitor useawait usingwhichfallback used by LSP binary detection--resume/--continuelosing conversation context on large sessions when the loader anchored on a dead-end branch instead of the live conversation--resumechain recovery bridging into an unrelated subagent conversation when a subagent message landed near a main-chain write gap--resumewhen a persisted Edit/Write tool result was missing itsfile_pathAPI_TIMEOUT_MSpermissions.denyrules not overriding a PreToolUse hook'spermissionDecision: "ask"— previously the hook could downgrade a deny into a prompt--setting-sourceswithoutusercausing background cleanup to ignorecleanupPeriodDaysand delete conversation history older than 30 daysANTHROPIC_AUTH_TOKEN,apiKeyHelper, orANTHROPIC_CUSTOM_HEADERSset an Authorization headerclaude -w <name>failing with "already exists" after a previous session's worktree cleanup left a stale directorymktemp: No such file or directoryafter a fresh bootclaude mcp servetool calls failing with "Tool execution failed" in MCP clients that validateoutputSchemaRemoteTriggertool'srunaction sending an empty body and being rejected by the server/resumepicker issues: narrow default view hiding sessions from other projects, unreachable preview on Windows Terminal, incorrect cwd in worktrees, session-not-found errors not surfacing in stderr, terminal title not being set, and resume hint overlapping the prompt inputrgand self-heals mid-session/btwwriting a copy of the entire conversation to disk on every use/contextFree space and Messages breakdown disagreeing with the header percentagename:frontmatter,/plugin updatefailing withENAMETOOLONG, Discover showing already-installed plugins, directory-source plugins loading from a stale version cache, and skills not honoringcontext: forkandagentfrontmatter fields/mcpmenu offering OAuth-specific actions for MCP servers configured withheadersHelper; Reconnect is now offered instead to re-invoke the helper scriptctrl+],ctrl+\, andctrl+^keybindings not firing in terminals that send raw C0 control bytes (Terminal.app, default iTerm2, xterm)/loginOAuth URL rendering with padding that prevented clean mouse selectionsettings.jsonenv values are numbers instead of strings/add-dir --remember,/config) not refreshing the in-memory snapshot, preventing removed directories from being revoked mid-session~/.claude/keybindings.json) not loading on Bedrock, Vertex, and other third-party providersclaude --continue -pnot correctly continuing sessions created by-por the SDK/remote-controlfailing over SSH when onlyCLAUDE_CODE_ORGANIZATION_UUIDis set/insightssometimes omitting the report file link from its responsegithub/copilot-cli (github/copilot-cli)
v1.0.24: 1.0.24Compare Source
2026-04-10
v1.0.23: 1.0.23Compare Source
2026-04-10
int128/ghcp (int128/ghcp)
v1.15.3Compare Source
What's Changed
Refactoring
Dependencies
Full Changelog: int128/ghcp@v1.15.2...v1.15.3
jdx/mise (jdx/mise)
v2026.4.11: : Task dependency templates and npm semver range supportCompare Source
A small release with two meaningful bug fixes: task dependency templates with
{{usage.*}}references now resolve correctly even when the task is called without arguments, andpackage.jsondevEnginesversion fields are now parsed as full npm semver ranges instead of being simplified into prefix matches.Fixed
Task dependency templates now render without arguments -- When a task declared dependencies using
{{usage.*}}templates (e.g.depends = ["child {{usage.app}}"]), those templates were only rendered if the task received explicit CLI arguments. If the usage spec defined defaults but no args were passed, the templates were left unresolved and the dependencies were silently dropped, causing the task to run with no dependencies at all. The guard now checks whether dependencies contain usage references rather than whether args are non-empty. #9062 by @MatthiasGrandlnpm semver ranges in
devEngines-- mise previously simplifiedpackage.jsondevEnginesversion fields by stripping range operators (>=,^,~) and trimming trailing.0segments to produce a prefix for fuzzy matching. This was lossy and incorrect in many cases (e.g.^20.0.1was simplified to20, matching20.0.0). mise now preserves the original range string and resolves it against available versions using proper npm semver semantics via thenodejs-semvercrate. Compound ranges (>=20 <21 || >=22), caret/tilde ranges, and wildcard segments all work correctly. #9061 by @risu729Documentation typo in Go backend -- The docs for Go build tags incorrectly showed
--tagsinstead of the correct-tagsflag. #9065 by @dolmenNew Contributors
Full Changelog: jdx/mise@v2026.4.10...v2026.4.11
v2026.4.10: : Fix spurious warnings from postinstall hooks running tasksCompare Source
A small patch release that fixes a single bug affecting tool postinstall hooks.
Fixed
postinstallhook ran a nestedmise run, the child process inherited theMISE_TOOL_VERSIONenvironment variable set during hooks.ToolsetBuilderwas incorrectly parsing this as a request to install a tool namedtoolat the given version via theMISE_<TOOL>_VERSIONconvention, producing spurious registry warnings before the task executed. mise now ignoresMISE_TOOL_VERSIONin the same way it already ignoredMISE_INSTALL_VERSION. #9050 by @risu729Full Changelog: jdx/mise@v2026.4.9...v2026.4.10
v2026.4.9: : Cross-device installs, deterministic lockfiles, and sandbox template supportCompare Source
This release fixes cross-device tool installation failures, makes lockfile provenance resolution deterministic across platforms, and adds sandbox field support to task templates. Several smaller fixes address env precedence in multi-environment setups and spurious warnings from
tools=truemodule hooks.Highlights
rename()returns a cross-device error.mise locknow resolves SLSA provenance URLs for all target platforms, not just the current host. This eliminates non-deterministic lockfile diffs when runningmise lockon different machines.deny_all,deny_read,deny_write,deny_net,deny_env,allow_read,allow_write,allow_net,allow_env), with deny fields composing restrictively and allow lists combining template and task-local values.Fixed
Cross-device tool installation -- When the downloads folder is on a different mount than the installs folder (common with Docker cache mounts or devcontainers),
rename()fails withEXDEV. mise now uses amove_filehelper that falls back to copy+remove, fixing installation of bun, deno, erlang, java, and ruby in these setups. #9032 by @bgeronDeterministic SLSA provenance in lockfiles --
mise lockpreviously only resolved full SLSA provenance URLs for the current host platform, writingprovenance = "slsa"(short form) for cross-platform entries. Now both the GitHub and Aqua backends resolve provenance URLs for all target platforms, producing byte-for-byte identical lockfiles regardless of which machine generates them. #8982 by @cameronbrillSandbox fields in task templates -- Task templates now accept sandbox configuration fields. Deny fields compose restrictively (OR with task-local settings), and allow lists combine template values with task-local values. #9046 by @risu729
Env precedence for task config -- With multiple
MISE_ENVvalues (e.g.,MISE_ENV=prod,ci),task_config.includesandtask_config.dirnow correctly respect the documented last-env-wins precedence. Previously the order was reversed, causing the wrong profile's task config to take effect. #9039 by @risu729Spurious warnings from
tools=truemodule hooks -- When a vfox backend tool triggereddependency_env(), it previously resolved alltools=trueenv modules with an incomplete PATH, causing "command not found" warnings. The dependency env now skipstools=truemodule resolution entirely. #9011 by @jdxImplicit
self_updatewith rustls features -- Building mise with--features rustlsor--features rustls-native-rootsno longer implicitly enables theself_updatefeature. Theself_update/rustlsentries in these feature lists were redundant and caused the optionalself_updatedependency to be silently pulled in. #9040 by @salim-bJSON schema completeness -- Added missing fields to the mise JSON schema: sandbox fields on tasks, legacy top-level
env_file/dotenv/env_pathshortcuts (marked deprecated), and age encryption directive options with proper nesting. #9044 by @risu729Windows
.exein release checksums -- Release builds now publish the extractedmise.exealongside the Windows.ziparchives and include it inSHASUMS256.txt, enabling SHA256 verification of the standalone binary (e.g., bymise-action). #8997 by @zeitlingergrantedregistry entry -- Updated thegrantedtool to point to the newfwdcloudsec/grantedrepository after the project moved fromcommon-fate/granted. #9033 by @risu729New Contributors
Full Changelog: jdx/mise@v2026.4.8...v2026.4.9
max-sixty/worktrunk (max-sixty/worktrunk)
v0.36.0: 0.36.0Compare Source
Release Notes
Improved
Git-style external subcommands:
wt foonow runswt-foofrom PATH whenfoois not a built-in, mirroringgit foo→git-foo. Third-party tools can be installed and invoked aswt <name>without touching this repo. Unrecognized commands show a git-style error with typo suggestions. Docs (#2054, thanks @pablospe for the suggestion in #2053){{ owner }}template variable: Expands to the GitHub/GitLab repository owner, useful for constructing URLs or paths in hook templates andworktree-path. (#2051, thanks @greggdonovan)Typed env-var config overrides:
WORKTRUNK__LIST__TIMEOUT_MS=30and other typed overrides now work correctly. Previously, string-typed env values silently failed deserialization, wiping all user config and falling back to defaults. (#2062)Config error attribution: Config load errors now identify the source — file errors show TOML line/column pointers, env-var errors list the offending
WORKTRUNK_*variable. Previously all failures showed a generic message. (#2068)Per-symbol atomic status rendering: The Status column in
wt listand thewt switchpicker now renders each symbol independently — unresolved gates show⋯at their position instead of fabricating defaults when the collect deadline expires. (#2067)Hook error messages: Malformed hook command config now lists the three accepted forms (string, named table, pipeline list) with a pointer to
wt hook --help, instead of an opaque serde error. (#2042)Stale trash cleanup:
wt removenow sweeps orphaned.git/wt/trashentries older than 24 hours after each removal, reclaiming space from interrupted background removals. (#2039)Changed
wt hook <type>exits successfully when no hooks are configured: Previously errored; now prints a warning and exits 0, so scripts and CI can invokewt hookunconditionally. (#2056)Hook output log layout: Log files moved from flat
.git/wt/logs/{name}.logto nested{branch}/{source}/{hook-type}/{name}.log. Per-branch listing/clearing is now O(that branch).logs get --format=jsonpaths changed to relative. Legacy flat files are swept automatically. (#2041)Fixed
wt config showfalse "Not configured": When the shell init line lives in a sourced file (common with dotfile managers),config showno longer reports "Not configured" — it checks whether integration is actually active at runtime. Fixes #1306. (#2066, thanks @wouter-intveld for reporting)Remove-then-switch hint: The hint for shadowed remote branches now uses
--foregroundso the chainedwt remove && wt switchactually works (background removal left a placeholder directory blocking the switch). (#2040)Conflict detection unified: The
wt switchpicker andwt listnow both run both conflict probes (commit-level and working-tree). Previously the picker skipped the cheaper probe, leaving the fallback unreachable for clean worktrees;wt listnon-full skipped the working-tree probe, missing conflicts from interrupted rebases. (#2064)Documentation
Internal
Install worktrunk 0.36.0
Install prebuilt binaries via shell script
Install prebuilt binaries via powershell script
Install prebuilt binaries via Homebrew
brew install worktrunk && wt config shell installDownload worktrunk 0.36.0
Install via Cargo
cargo install worktrunk && wt config shell installInstall via Winget (Windows)
winget install max-sixty.worktrunk && git-wt config shell installInstall via AUR (Arch Linux)
paru worktrunk-bin && wt config shell installnushell/nushell (nushell/nushell)
v0.112.1Compare Source
This is the 0.112.1 release of Nushell. You can learn more about this release here: https://www.nushell.sh/blog/2026-04-11-nushell_v0_112_1.html
(We skipped release 0.112.0 due to issue when releasing to crates.io.)
For convenience, we are providing full builds for Windows, Linux, and macOS. Be sure you have the requirements to enable all capabilities: https://www.nushell.sh/book/installation.html#dependencies
This release was made possible by PR contributions from @0xRozier, @amaanq, @andrewgazelka, @app/, @app/dependabot, @ayax79, @Bahex, @Benjas333, @blackhat-hemsworth, @blindFS, @Bortlesboat, @ChrisDenton, @CloveSVG, @cmtm, @coravacav, @cosineblast, @cptpiepmatz, @Dexterity104, @dxrcy, @fdncred, @galuszkak, @guluo2016, @hustcer, @ian-h-chamberlain, @Juhan280, @kiannidev, @kx0101, @Moayad717, @musicinmybrain, @niklasmarderx, @pickx, @preiter93, @rayzeller, @rbran, @Rohan5commit, @seroperson, @sholderbach, @smartcoder0777, @stuartcarnie, @tauanbinato, @Tyarel8, @weirdan, @WindSoilder, @WookiesRpeople2, @xtqqczze, @ymcx, @ysthakur, @zhiburt
openai/codex (openai/codex)
v0.120.0: 0.120.0Compare Source
New Features
outputSchemadetails so structured tool results are typed more precisely (#17210)/clearfrom fresh startup or resume sessions (#17073)Bug Fixes
apply_patchworkflows (#15981)codex --remote wss://...panics by installing the Rustls crypto provider before TLS websocket connections (#17288)Documentation
/clearSessionStart source (#17073)Chores
Changelog
Full Changelog: openai/codex@rust-v0.119.0...rust-v0.120.0
v0.119.0: 0.119.0Compare Source
New Features
--cdforwarding, runtime remote-control enablement, sandbox-aware filesystem APIs, and an experimentalcodex exec-serversubcommand (#15951, #16700, #16973, #16751, #17059, #17142, #17162).Ctrl+O, including better clipboard behavior over SSH and across platforms (#16966)./resumecan now jump directly to a session by ID or name from the TUI (#17222).Bug Fixes
/statusnow refreshes stale limits instead of showing frozen or misleading quota information (#16201, #17039)./copyoutput, percent-decoded local file links, and clearer truncated exec-output hints (#16202, #16829, #16648, #16810, #17076)./fast offin app-server-backed TUI sessions (#16833)./mcpavoids slow full inventory probes, disabled servers skip auth probing, and residency headers are honored bycodex mcp-server(#16674, #16831, #17098, #16952).apply_patcherrors, refreshed network proxy policy after sandbox changes, suppressed irrelevant bubblewrap warnings, a macOS HTTP-client sandbox panic fix, and Windows firewall address handling (#16885, #17040, #16667, #16670, #17053).Documentation
argument_comment_lintwas updated to favor getting CI started instead of blocking on slow local lint runs (#16375).codex-cliREADME content was removed to avoid stale setup guidance (#17096).codex exec --helpnow shows clearer usage and approval-mode wording (#16881, #16888).Chores
codex-corewas slimmed down through major crate extractions for MCP, tools, config, model management, auth, feedback, protocol, and related ownership boundaries (#15919, #16379, #16508, #16523, #16962).--all-featuresruns (#16455, #16473).Changelog
Full Changelog: openai/codex@rust-v0.118.0...rust-v0.119.0
/feedbacksubmission through the app server @etraut-openaiConfiguration
📅 Schedule: (in timezone America/Los_Angeles)
* 5-7 * * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.