$ cat anthropics/week/2026-09-28.log
the week in review · Sep 28 – Oct 4, 2026
Sonnet 5.5 becomes the default model
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
Claude Code v2.1.284 ships the switch at 1M context and $2/$10 per Mtok, and CI pipelines pin their models in response.
v2.1.284 anthropics/claude-code
Sonnet 5.5 is now the default Sonnet on the Anthropic API at 1M context and $2/$10 per Mtok with $0.20/Mtok cache reads, so any pipeline that never named a model is now running it. Auto mode also gains a "Yes, but ask again next time" answer for reads outside the working directories. The release notes carry no Sonnet 4.5 sunset detail here; the end date landed separately.
ci: pin the model for issue triage (#1328) anthropics/claude-agent-sdk-python
Issue triage failed on every run since Sep 24 because the Claude step names no model and inherits Claude Code's default; Claude Code 2.1.280, picked up in claude-code-action v1.0.232 on Sep 23, moved that default to Opus 5. The fix is one line: name the model.
Update claude-api skill: Claude Opus 5.5 default, Claude Sonnet 5.5, build-eval and hillclimb guides anthropics/skills
The claude-api skill moves to claude-opus-5-5 as the default across SKILL.md, models.md and every language example, with build-eval and hillclimb guides added. Anyone copying a model id out of the skill should re-read it rather than their pinned snapshot.
ci: security hardening for GitHub Actions workflows that call Claude anthropics/claude-code
The three workflows that call Claude now run on an egress-firewall runner and reference their actions by commit. If your own CI calls Claude on a public runner, the pinning is the part worth copying.
sec-default: a settings deny rule holds over an allow or ask from a plugin the person installed anthropics/claude-code
A plugin you installed can no longer overturn a settings deny rule where the security default is seated; a user-tier plugin that answers allow or ask loses to the deny verdict on tool.check. Organizations can opt out in managed settings, so the change is visible in policy, not just behavior.
diff: the pane reads every file's hunks with one git process, where it started one per file anthropics/claude-code
The diff pane now reads a change's hunks with a single git process where it previously started one per file, up to fifty per tool call. The gain is largest where process startup is slow, Windows in particular; the old design could fail or time out on any one of those fifty.
ci: pin GitHub Actions and the conformance tools image to specific commits (#479) anthropics/buffa
Buffa's CI now pins GitHub Actions and the conformance tools image to specific commits, closing two vulnerabilities where the workflow referenced other people's code by a short name that could be repointed later. Nothing in the generated Rust changes; the diff is in workflow files.
linux: exit status under zsh, and import zod/v3 anthropics/sandbox-runtime
On Linux, a network-restricting wrap running binShell zsh now reports the command's own exit status, where a failing command could report 0. The config schemas import zod/v3, so they keep the API they were written against when a consumer's dependency tree resolves zod to 4.
$ ls anthropics/week/ # the briefings behind this review
Keep up with Anthropic in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.