141 wires and counting

$ follow Anthropic

Keep up with Anthropic in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-10-05
stories 6

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

Sandbox path entries stop silently dropping bracketed directories

By RepoJournal · Filed · About Anthropic · Composed from the cited sources · methodology

Three stacked pull requests in anthropics/sandbox-runtime fix a glob-dialect hole that let deny rules slip when a path component contained `*`, `?`, `[` or `]`.

Read a path entry as the path it spells, where that exists anthropics/sandbox-runtime

by ronleizrowice-ant

Entries under a folder whose name holds `*`, `?`, `[` or `]` were read as patterns alone, so with `/w` writable a `denyWrite` on a file in `/w/[WIP] project` left that file writable. An entry is now also read as the path it spells where the character-bearing part exists, and as its tail pattern beneath an existing directory, while the pattern reading stays.

Let a caller mark a path entry literal: `{ path, literal: true }` anthropics/sandbox-runtime

by ronleizrowice-ant

`denyRead`, `allowRead`, `allowWrite` and `denyWrite` accept `{ "path": "...", "literal": true }` alongside a plain string, meaning a path that is never treated as a pattern whether or not it exists. `FilesystemPathEntry` is exported, and `getFsReadConfig()` and `getFsWriteConfig()` carry marked entries in four `literal...` lists.

Glob walk: an `anchor` option, a directory taken as the name it is anthropics/sandbox-runtime

by ronleizrowice-ant

The glob dialect has no escape, so `/w/[WIP] project/**/.env` read `[WIP]` as a character class and matched nothing. `walkGlobPattern` and `expandGlobPattern` now take an `anchor`, a leading run of the path that is a name on disk, with only the remainder compiled as a pattern.

Merge pull request #621 from anthropics/feat/literal-path-marker anthropics/sandbox-runtime

by ronleizrowice-ant

Merge commit for the `{ path, literal: true }` marker, the second of the stack; it lands before the entry-resolution change so the third PR can express the paths it finds as marked entries.

Merge pull request #622 from anthropics/fix/path-entries-read-as-paths anthropics/sandbox-runtime

by ronleizrowice-ant

Merge commit that carries the path-reading change to the default branch, completing the replacement of #608 after the marker and anchor groundwork.

Quick answers

What shipped in Anthropic on October 5, 2026?
Three stacked pull requests in anthropics/sandbox-runtime fix a glob-dialect hole that let deny rules slip when a path component contained `*`, `?`, `[` or `]`. In total, 3 commits and 3 pull requests landed.
Who contributed to Anthropic on October 5, 2026?
1 developer shipped this update, including ronleizrowice-ant.
What were the notable Anthropic updates?
Read a path entry as the path it spells, where that exists, Let a caller mark a path entry literal: `{ path, literal: true }`, and Glob walk: an `anchor` option, a directory taken as the name it is.