Skip to content

ci: bump anthropics/claude-code-action from 1.0.238 to 1.0.240 - #164

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/anthropics/claude-code-action-1.0.240
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/anthropics/claude-code-action-1.0.240

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps anthropics/claude-code-action from 1.0.238 to 1.0.240.

Release notes

Sourced from anthropics/claude-code-action's releases.

v1.0.240

Full Changelog: anthropics/claude-code-action@v1.0.239...v1.0.240

v1.0.239

Full Changelog: anthropics/claude-code-action@v1.0.238...v1.0.239

Commits
  • ed670b4 chore: bump Claude Code to 2.1.288 and Agent SDK to 0.3.288
  • 97c5347 chore: bump Claude Code to 2.1.287 and Agent SDK to 0.3.287
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) from 1.0.238 to 1.0.240.
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](anthropics/claude-code-action@12dd8d7...ed670b4)

---
updated-dependencies:
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.240
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 5, 2026
@claude

claude Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Claude finished @dependabot[bot]'s task in 20s —— View job


Review: approved ✅

  • Read the pinned diff (39c2256...53609e5)
  • Check the bump
  • Submit the verdict, bound to 53609e5

Change: Both anthropics/claude-code-action uses in .github/workflows/claude-review.yml (lines 1002 and 1068) move from 12dd8d7 (v1.0.238) to ed670b4 (v1.0.240). The new value is still a full commit SHA, and it matches the top commit in Dependabot's release notes. No logic, permission or secret handling changes.

P3 nit (non-blocking): The comment after each uses: line still says # v1.0.238 (CLI 2.1.286). It should say # v1.0.240 (CLI 2.1.288). Dependabot probably didn't update it because of the (CLI …) suffix.

Not checked: I couldn't confirm that ed670b4 is the v1.0.240 tag, because git ls-remote against the upstream repo needs approval in this run.

Findings: 0 P1 / 0 P2 / 1 P3. The approval is bound to commit 53609e50dda62afdfddd5a21cec39f5c131284dc.

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pinned-SHA dependency bump of claude-code-action (1.0.238 → 1.0.240), no logic change. Nit: trailing version comments on both lines still say v1.0.238 (CLI 2.1.286); should be v1.0.240 (CLI 2.1.288).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants