141 wires and counting

$ follow Anthropic

Keep up with Anthropic in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-10-06
stories 15

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

Claude Code symlink TOCTOU allows arbitrary file write

By RepoJournal · Filed · About Anthropic · Composed from the cited sources · methodology

A write-time symlink following flaw in Claude Code headlines a day otherwise made of version syncs across the action, base-action, and Python SDK, plus a new Lean 4 formalization in the math repo.

Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code anthropics/claude-code

Claude Code's file writes follow symlinks at write time, a TOCTOU race that lets an attacker redirected write land outside the intended path. Anyone running Claude Code against a repo where another process or contributor can create symlinks should treat this as the day's only actionable item.

Add 3sum-apsp: formalization of "Truly Subquadratic 3SUM and Truly Subcubic APSP via Triangles in Sparse Lopsided Graphs" anthropics/formal-math

by ecprice-ant

The formal-math repo gains 3sum-apsp, a Lean 4 project accompanying the paper on truly subquadratic 3SUM and truly subcubic APSP via triangles in sparse lopsided graphs. It is self-contained on Lean and Mathlib v4.33.1 with no other dependency, and EndStatement.lean imports nothing, stating five headline claims about word RAM programs.

Add 3sum-apsp: formalization of "Truly Subquadratic 3SUM and Truly Subcubic APSP via Triangles in Sparse Lopsided Graphs" (#28) anthropics/formal-math

by ecprice-ant

The accompanying CI change adjusts lean4export pinning: a project on stable patch release vX.Y.Z with Z > 0 now takes the vX.Y.0 tag when no tag for the exact patch exists, building it with the project's toolchain. Release candidates get no fallback, and projects whose exact tag exists are checked as before.

chore: Update CHANGELOG.md and feed.xml anthropics/claude-code

by GitHub Actions

The generated CHANGELOG.md and feed.xml were refreshed for Claude Code.

chore: bump Claude Code to 2.1.291 and Agent SDK to 0.3.291 anthropics/claude-code-action

by GitHub Actions

The action, base-action, and Python SDK all moved to Claude Code 2.1.291 and Agent SDK 0.3.291 in lockstep, with base-action picking up the 2.1.290 sync in the same window and the Python SDK bumping only its bundled CLI.

Quick answers

What shipped in Anthropic on October 6, 2026?
A write-time symlink following flaw in Claude Code headlines a day otherwise made of version syncs across the action, base-action, and Python SDK, plus a new Lean 4 formalization in the math repo. In total, 9 commits, 1 pull requests, 4 releases, and 1 security advisories landed.
Who contributed to Anthropic on October 6, 2026?
2 developers shipped this update, including GitHub Actions and ecprice-ant.
What were the notable Anthropic updates?
Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code, Add 3sum-apsp: formalization of "Truly Subquadratic 3SUM and Truly Subcubic APSP via Triangles in Sparse Lopsided Graphs", and Add 3sum-apsp: formalization of "Truly Subquadratic 3SUM and Truly Subcubic APSP via Triangles in Sparse Lopsided Graphs" (#28).