141 wires and counting

$ follow Anthropic

Keep up with Anthropic in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-10-07
stories 111

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

sandbox-runtime drops connections on invalid upstream status, buffa tightens its parsers

By RepoJournal · Filed · About Anthropic · Composed from the cited sources · methodology

sandbox-runtime 0.0.78 crashes its proxy on a malformed upstream response head, while buffa lands three strictness fixes that reject input its parsers previously accepted.

Answer 502 when an upstream sends an invalid status code anthropics/sandbox-runtime

by ant-kurt

In 0.0.78, an upstream response head that Node's res.writeHead refuses, such as "HTTP/1.1 099 x", makes writeHead throw inside the proxy's response callback. Nothing catches it, the proxy process exits, and every in-flight connection drops, so the sandboxed command loses network access; any upstream the sandbox can reach can trigger it. The fix routes all four relay sites (direct, parent-proxy,...

descriptor: reject unrecognized file syntax and editions files without an edition anthropics/buffa

by fallintoplace

DescriptorPool used to link a file whose syntax was any string other than proto2, proto3, or editions with proto2 semantics, so a typo like prot3 silently changed field presence, enum openness, and packing; it also linked an editions file with no edition using the 2023 defaults. Both now raise PoolError::UnrecognizedSyntax and PoolError::MissingEdition, matching protoc and protobuf-go. An absen...

json: reject unset Value during serialization anthropics/buffa

by fallintoplace

Serializing a google.protobuf.Value with no kind set used to write null, which read back as a Value holding NullValue, so the round trip changed the message; it now returns an error. This is a breaking change: Value::default() no longer serializes, and Value::null() is the JSON null. A Value decoded from binary with an empty payload fails too.

remote-derive: add a serde key to the storage derives anthropics/buffa

by zayedu

A generate_json(true) build needs serde impls on newtypes that the storage derives previously left to hand-written code, and a custom string type with explicit presence in a repeated field, oneof, or map failed to compile without them. A bare #[buffa(serde)] key on any of the five derives now emits serde::Serialize and serde::Deserialize.

test(e2e): fix thinking-deltas test for CLI 2.1.287+ to unblock releases anthropics/claude-agent-sdk-python

by qing-ant

Test has been red on every CLI bump since 2.1.287, so Auto Release skipped 2.1.287 through 2.1.291, because an e2e assertion expecting thinking content over 10 characters kept getting an empty string on Linux, macOS, and Docker jobs. The companion CI change adds a Slack alert to the SDK channel for blocked and failed releases so the next silent skip is visible. PyPI's per-file limit rose from 1...

Quick answers

What shipped in Anthropic on October 7, 2026?
sandbox-runtime 0.0.78 crashes its proxy on a malformed upstream response head, while buffa lands three strictness fixes that reject input its parsers previously accepted. In total, 56 commits, 54 pull requests, and 1 releases landed.
Who contributed to Anthropic on October 7, 2026?
5 developers shipped this update, including zayedu, fallintoplace, qing-ant, ant-kurt, and Claude.
What were the notable Anthropic updates?
Answer 502 when an upstream sends an invalid status code, descriptor: reject unrecognized file syntax and editions files without an edition, and json: reject unset Value during serialization.