$ the-wire · showcase
Claude CI moves behind the egress firewall, permission mode goes auto"
By RepoJournal · Filed · About Anthropic · Composed from the cited sources · methodology
A coordinated hardening pass moved every Anthropic workflow that calls Claude onto an egress-firewall runner with an explicit network allow list, while claude-code ships two security-default PRs that stop user-tier plugins from loosening the system prompt and permission denies.
ci: security hardening for GitHub Actions workflows that call Claude anthropics/claude-code
All three Claude-calling workflows (claude-issue-triage.yml, claude-dedupe-issues.yml, claude.yml) move from ubuntu-latest to ubuntu-24.04-firewall, with a new .github/egress-firewall.yaml in mode: enforce naming each host the jobs need and what uses it. The same pattern landed across claude-code-action (17 jobs in 8 workflow files), the TypeScript SDK, and claude-code-action: run in auto permi...
sec-default: a settings deny rule holds over an allow or ask from a plugin the person installed anthropics/claude-code
On tool.check, a settings deny rule's verdict now wins when a user-tier plugin answered allow or ask over it; organizations can opt out in managed settings. As the PR summary puts it, "a mod you install can no longer switch off a permission deny rule where the security default is seated."
sec-default: the system prompt's sections continue past the user tier anthropics/claude-code
prompt.compose, whose hooks return the system prompt as an ordered list of sections, now joins prompt.section and prompt.context in continuing past the user tier (next.to(e, "append")). Where an organization seats sec-default, a person's plugins no longer shape the system prompt's sections.
ci: pin the model for issue triage (#1328) anthropics/claude-agent-sdk-python
Issue triage has failed on every run since Sep 24 because the Claude step names no model and picked up Claude Code 2.1.280's new default, claude-opus-5-5, which the API rejects with a 400 for the org CI signs in as. Pinning the model is the fix; the surrounding jobs were bumped to Claude Code 2.1.285 and Agent SDK 0.3.285.
ci: pin workflow inputs, use npm trusted publishing, pack on pull requests (#632) anthropics/sandbox-runtime
Every action in the CI and release workflows is now referenced by commit with its release tag in a trailing comment, the Rust toolchain comes from a new rust-toolchain.toml (1.98.1), the release job publishes via npm trusted publishing, and each pull request builds the tarball a release would publish. Nothing changes version: each pinned commit is what the v4/v2 tags resolve to today.