141 wires and counting

$ follow Anthropic

Keep up with Anthropic in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-26
stories 18

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

Cowork folder file execution on macOS, axt-verify v0.1.0

By RepoJournal · Filed · About Anthropic · Composed from the cited sources · methodology

The day's two consequential items both concern trust boundaries: a Claude Desktop on macOS path from a malicious file to host command execution, and the first tagged release of the Access Transparency log verifier.

Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host anthropics/claude-code

Opening a malicious file from a Cowork folder in Claude Desktop on macOS could run commands on the host. Treat Cowork folders as untrusted input until a fix lands.

axt-verify v0.1.0 anthropics/axt-verify

by eperrine-ant

axt-verify is now tagged at v0.1.0 and installs with `go install github.com/anthropics/axt-verify/cmd/axt-verify@v0.1.0` on Go 1.26 or newer. The release carries a single log key for origin prefix axt.anthropic.com with SHA-256 fingerprint 1dff5fe420d49743fe444a04fc17f818eea856699dec2ebbc24df15602c74a58, and the README states both what it checks and what it cannot.

code-modernization: guided workflow with independent proof anthropics/claude-plugins-official

by morganl-ant

The code-modernization plugin collapses into one guided workflow with a `/modernize` front door, a same-stack `uplift` path, and a rule-review step. Its `verify` step computes PROVEN / PARTLY PROVEN / NOT PROVEN per module from result files, where a rule counts as tested only if a test that ran backs it.

code-modernization: a rule is tested only if a test that ran backs it anthropics/claude-plugins-official

by Morgan Lunt

Under that proof rule, a rule named only by a skipped or pending test no longer counts as covered: it is listed as "named, not run" and fails the rules check. Test-only folders are listed as tooling with no verdict, and the report now parses rule headings and fields in linear time.

Claude Security Plugin - v0.12.0 (#6310) anthropics/claude-plugins-official

by Michael Moore

The long tail is routine: Claude Security Plugin v0.12.0, machine-side failure classification and per-version usage pings for code-modernization, a pinned model for issue triage in the agent SDK, and changelog or feed regeneration in both repositories.

Quick answers

What shipped in Anthropic on September 26, 2026?
The day's two consequential items both concern trust boundaries: a Claude Desktop on macOS path from a malicious file to host command execution, and the first tagged release of the Access Transparency log verifier. In total, 10 commits, 4 pull requests, 3 releases, and 1 security advisories landed.
Who contributed to Anthropic on September 26, 2026?
6 developers shipped this update, including poteat, GitHub Actions, eperrine-ant, Michael Moore, morganl-ant, and Qing Wang.
What were the notable Anthropic updates?
Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host, axt-verify v0.1.0, and code-modernization: guided workflow with independent proof.