141 wires and counting

$ follow Anthropic

Keep up with Anthropic in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-10-03
stories 14

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

security-guidance follows the newest Opus, bubblewrap 0.4 sandboxes start again

By RepoJournal · Filed · About Anthropic · Composed from the cited sources · methodology

Two plugins stopped going stale on their own: security-guidance no longer hardcodes a review model, and sandbox-runtime fixed the file-mask collision that kept bubblewrap 0.4.0 and 0.4.1 from starting on RHEL 8 and 9.

security-guidance: follow the newest Opus instead of a pinned release anthropics/claude-plugins-official

by mhegazy

The security-guidance plugin was hardcoded to claude-opus-4-7, so every new Opus release left it reviewing with an older model until someone bumped it by hand. Diff review now asks the configured endpoint's GET /v1/models for the newest Opus it serves (cached for a day, falling back to claude-opus-5-5), while agentic commit review and all Bedrock, Vertex, and Foundry reviews use Claude Code's o...

linux: one mount per destination, so bubblewrap 0.4 starts anthropics/sandbox-runtime

by ronleizrowice-ant

Distinct spellings of the same file (a trailing slash, a symlinked directory, a denyRead entry that is also a credential mask) each placed a file mask at the same destination, and on bubblewrap before 0.5.0 the leftover /dev/null made 0.4.0 and 0.4.1 refuse to start with "Can't create file at <dest>: Permission denied". Each destination now gets exactly one mask, which unblocks sandboxed comman...

linux: a wrap that starts over keeps what it has walked, and ends anthropics/sandbox-runtime

by ronleizrowice-ant

Since the wrap logic began walking read patterns in turns, a configuration replacement mid-wrap restarted the walk from nothing, so a host refreshing its config often could keep a command from ever starting. A wrap now keeps the directories it listed and each pattern's findings instead of discarding them when it starts over.

v2.1.288 anthropics/claude-code

by ashwin-ant

Claude Code v2.1.288 adds $.ui.selection() for mods, which returns your last fullscreen selection plus the transcript row when the selection sits within one row, and brings back a Ctrl+C-cleared prompt (pasted text and images included) when you press Up on the empty prompt. Cloud sessions without a GitHub CLI now get a built-in gh api.

chore: bump Claude Code to 2.1.288 and Agent SDK to 0.3.288 anthropics/claude-code-action

by GitHub Actions

The GitHub Action moved to Claude Code 2.1.288 and Agent SDK 0.3.288, and claude-code-base-action picked up the same bump through a base-action sync. Elsewhere it was routine: AWS plugin bumps in claude-plugins-official and changelog housekeeping in claude-code.

Quick answers

What shipped in Anthropic on October 3, 2026?
Two plugins stopped going stale on their own: security-guidance no longer hardcodes a review model, and sandbox-runtime fixed the file-mask collision that kept bubblewrap 0.4.0 and 0.4.1 from starting on RHEL 8 and 9. In total, 8 commits, 4 pull requests, and 2 releases landed.
Who contributed to Anthropic on October 3, 2026?
5 developers shipped this update, including GitHub Actions, ashwin-ant, Mohamed Hegazy, jordanecker-ant, and ronleizrowice-ant.
What were the notable Anthropic updates?
security-guidance: follow the newest Opus instead of a pinned release, linux: one mount per destination, so bubblewrap 0.4 starts, and linux: a wrap that starts over keeps what it has walked, and ends.