Skip to content

build(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates - #3704

Merged
kyle-sexton merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-b46d6fa992
Sep 7, 2026
Merged

kyle-sexton merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-b46d6fa992

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-minor-patch group with 2 updates in the / directory: @anthropic-ai/claude-code and @biomejs/biome.

Updates @anthropic-ai/claude-code from 2.1.258 to 2.1.260

Release notes

Sourced from @​anthropic-ai/claude-code's releases.

v2.1.260

What's changed

  • Added a diff panel that opens beside the conversation in fullscreen mode and shows your uncommitted changes as Claude edits; toggle it with /diff
  • Added a likely cause for prompt-cache misses (e.g. tool definitions or system prompt changed, idle past the TTL) to /cost and the status line's prompt_cache field
  • Added /reload-plugins to headless sessions, so it appears in the Claude Code Desktop and SDK command lists
  • Added a text form of /advisor (/advisor, /advisor <model>, /advisor off) for the desktop app, Remote Control, and other headless (-p/Agent SDK) sessions
  • Added oidc.scope_on_refresh to the Claude apps gateway for IdPs that return an id_token on refresh only when asked for openid again
  • Added Claude apps gateway support for newer Claude Desktop keys in desktop policy blocks, including userPluginMarketplacesEnabled and userPluginUploadsEnabled
  • Fixed Edit/Write/Read permission rules whose path contains parentheses being dropped as invalid or ignored by the Bash sandbox, which left "read-only" folders writable
  • Fixed one file permission rule with an uncompilable pattern (e.g. an unclosed [) making every file edit fail with Invalid regular expression; such a deny rule now guards the literal path it spells
  • Fixed Bash permission checks auto-approving zsh commands that hide a command substitution in a REPORTTIME, REPORTMEMORY or DIRSTACKSIZE assignment; these now prompt for approval
  • Fixed Bedrock model discovery, token counting and AWS SSO/STS credential calls failing with "unable to get local issuer certificate" when the corporate root CA is only in the OS certificate store
  • Fixed permissions.blockReadsOutsideWorkingDirectories on macOS hiding the user's git config from sandboxed git and hiding a worktree-isolated sub-agent's own checkout
  • Fixed managed settings not loading for claude.ai Enterprise/Team users who also had a leftover API key from an earlier /login
  • Fixed /status listing a signed-in claude.ai account and a configured API key as if both were in effect; the credential not in use is now marked
  • Fixed managed skillOverrides entries keyed on a bundled skill's alias (e.g. checkup for /doctor) not applying, and Skill(name) deny rules not covering a nested skill listed as <dir>:name
  • Fixed model: fable agents ignoring the [1m] tag on an ANTHROPIC_DEFAULT_FABLE_MODEL pin and silently running with a 200K context window
  • Fixed the /model picker not showing Fable 5.1 for organizations that can use it, which was only accepted when typed as /model claude-fable-5-1
  • Fixed prompt caching on Claude Fable 5.1 not covering the context attached after tool results, so it was re-sent as uncached input on every tool-call turn
  • Fixed model switching staying blocked for the rest of the session after a plugin hook load failure; each switch now re-checks and the refusal names the cause
  • Fixed model switching being blocked for the session when an organization-managed plugin's marketplace could not be loaded
  • Fixed SDK-provided MCP servers (e.g. Desktop connectors) sometimes missing from the first turn and only appearing on the next one
  • Fixed Claude in Chrome tools failing with "Not connected" mid-task in cloud-hosted claude.ai sessions when a connector was added or removed
  • Fixed flags, joined emoji and accented letters splitting across wrapped lines, and stale text staying on screen when a flag or joined emoji falls in the terminal's last two columns (now shown as …)
  • Fixed Remote Control accepting a model pick that is not a valid model name; it is now refused with an error instead of failing on the next message
  • Fixed /rewind and --rewind-files reporting success when checkpoint backup files were missing and nothing was actually restored
  • Fixed /rewind leaving stale file-read tracking from the rewound-away turns, which caused "File unchanged since last read" stubs and full-file re-injection after external edits
  • Fixed -p --resume/--continue (as used by the desktop app) failing on every retry once a session's worktree directory lost its git metadata; it now fails once, then resumes without the worktree
  • Fixed a subagent that resumed another agent via SendMessage never being woken by that agent's completion (the notification went to the main conversation instead)
  • Fixed agent teams: an in-process teammate's transcript losing messages, or going blank, during long API retry waits (e.g. under CLAUDE_CODE_RETRY_WATCHDOG) as retry notices evicted real messages
  • Fixed a session that moved to the background appearing twice in ListAgents (once as a phantom "interactive" twin with the same name) and receiving SendMessage deliveries in the viewer
  • Fixed intermittent "task output swap refused" errors when many sessions share a project directory
  • Fixed Ctrl+Z in fullscreen leaving the shell on the alternate screen, drawn over the paused interface
  • Fixed Workflow tool subagents being restarted as stalled while a long context compaction was still in progress
  • Fixed plugins from a URL marketplace failing to install with "marketplace entry path does not stay inside the marketplace directory" when a host app (e.g. Claude Desktop) stores it as a directory
  • Fixed an extra browser tab opening when an artifact is published in a session you're driving from claude.ai, the desktop app, or mobile (Remote Control)
  • Fixed the Artifact tool's first call failing with an "Invalid tool parameters" validation error in some Cowork sessions
  • Fixed IDE line selections being dropped when running a skill or slash command (the "N lines selected" context now reaches Claude)
  • Fixed repository detection for GitLab projects in nested subgroups (e.g. gitlab.com/group/subgroup/project)
  • Fixed owner/repo#123 issue references in rendered output linking to github.com when working in a GitLab repository; they now link to the gitlab.com issue
  • Glob/Grep: Fixed the search path being probed on disk before the permission check; a missing path is now reported after permission is decided, as Read does
  • Reverted the 2.1.259 change applying Read() deny rules to Bash arguments; it denied npm run build under a Read(./**/build/**) rule in every mode and made cd … && grep prompt even in auto mode
  • Improved structured output: Workflow agent({schema}) rejects a JSON Schema that can never be satisfied up front, and retry-cap errors now include the last validation failure
  • Improved deleting a background session whose worktree has unpushed commits: the message now names the branch and commit count, and deleting again discards the worktree
  • Improved the Claude apps gateway's refresh-failure log to name the step that failed
  • Improved idle CPU usage of non-interactive (-p / SDK) sessions
  • Improved the Claude apps gateway on Amazon Bedrock: input tokens for an aborted request are now counted with AWS's free CountTokens API (grant bedrock:CountTokens) instead of a one-token request
  • Improved the settings error for rules such as Edit(C:\dir\(name)\**), where \( is read as an escaped parenthesis rather than a path separator, to suggest an unambiguous spelling
  • Improved auto-compact for 1M-context models: Opus and Fable sessions now compact shortly before the 1M-token limit, and recovery compaction on very large contexts no longer times out at 10 minutes

... (truncated)

Changelog

Sourced from @​anthropic-ai/claude-code's changelog.

2.1.260

  • Added a diff panel that opens beside the conversation in fullscreen mode and shows your uncommitted changes as Claude edits; toggle it with /diff
  • Added a likely cause for prompt-cache misses (e.g. tool definitions or system prompt changed, idle past the TTL) to /cost and the status line's prompt_cache field
  • Added /reload-plugins to headless sessions, so it appears in the Claude Code Desktop and SDK command lists
  • Added a text form of /advisor (/advisor, /advisor <model>, /advisor off) for the desktop app, Remote Control, and other headless (-p/Agent SDK) sessions
  • Added oidc.scope_on_refresh to the Claude apps gateway for IdPs that return an id_token on refresh only when asked for openid again
  • Added Claude apps gateway support for newer Claude Desktop keys in desktop policy blocks, including userPluginMarketplacesEnabled and userPluginUploadsEnabled
  • Fixed Edit/Write/Read permission rules whose path contains parentheses being dropped as invalid or ignored by the Bash sandbox, which left "read-only" folders writable
  • Fixed one file permission rule with an uncompilable pattern (e.g. an unclosed [) making every file edit fail with Invalid regular expression; such a deny rule now guards the literal path it spells
  • Fixed Bash permission checks auto-approving zsh commands that hide a command substitution in a REPORTTIME, REPORTMEMORY or DIRSTACKSIZE assignment; these now prompt for approval
  • Fixed Bedrock model discovery, token counting and AWS SSO/STS credential calls failing with "unable to get local issuer certificate" when the corporate root CA is only in the OS certificate store
  • Fixed permissions.blockReadsOutsideWorkingDirectories on macOS hiding the user's git config from sandboxed git and hiding a worktree-isolated sub-agent's own checkout
  • Fixed managed settings not loading for claude.ai Enterprise/Team users who also had a leftover API key from an earlier /login
  • Fixed /status listing a signed-in claude.ai account and a configured API key as if both were in effect; the credential not in use is now marked
  • Fixed managed skillOverrides entries keyed on a bundled skill's alias (e.g. checkup for /doctor) not applying, and Skill(name) deny rules not covering a nested skill listed as <dir>:name
  • Fixed model: fable agents ignoring the [1m] tag on an ANTHROPIC_DEFAULT_FABLE_MODEL pin and silently running with a 200K context window
  • Fixed the /model picker not showing Fable 5.1 for organizations that can use it, which was only accepted when typed as /model claude-fable-5-1
  • Fixed prompt caching on Claude Fable 5.1 not covering the context attached after tool results, so it was re-sent as uncached input on every tool-call turn
  • Fixed model switching staying blocked for the rest of the session after a plugin hook load failure; each switch now re-checks and the refusal names the cause
  • Fixed model switching being blocked for the session when an organization-managed plugin's marketplace could not be loaded
  • Fixed SDK-provided MCP servers (e.g. Desktop connectors) sometimes missing from the first turn and only appearing on the next one
  • Fixed Claude in Chrome tools failing with "Not connected" mid-task in cloud-hosted claude.ai sessions when a connector was added or removed
  • Fixed flags, joined emoji and accented letters splitting across wrapped lines, and stale text staying on screen when a flag or joined emoji falls in the terminal's last two columns (now shown as …)
  • Fixed Remote Control accepting a model pick that is not a valid model name; it is now refused with an error instead of failing on the next message
  • Fixed /rewind and --rewind-files reporting success when checkpoint backup files were missing and nothing was actually restored
  • Fixed /rewind leaving stale file-read tracking from the rewound-away turns, which caused "File unchanged since last read" stubs and full-file re-injection after external edits
  • Fixed -p --resume/--continue (as used by the desktop app) failing on every retry once a session's worktree directory lost its git metadata; it now fails once, then resumes without the worktree
  • Fixed a subagent that resumed another agent via SendMessage never being woken by that agent's completion (the notification went to the main conversation instead)
  • Fixed agent teams: an in-process teammate's transcript losing messages, or going blank, during long API retry waits (e.g. under CLAUDE_CODE_RETRY_WATCHDOG) as retry notices evicted real messages
  • Fixed a session that moved to the background appearing twice in ListAgents (once as a phantom "interactive" twin with the same name) and receiving SendMessage deliveries in the viewer
  • Fixed intermittent "task output swap refused" errors when many sessions share a project directory
  • Fixed Ctrl+Z in fullscreen leaving the shell on the alternate screen, drawn over the paused interface
  • Fixed Workflow tool subagents being restarted as stalled while a long context compaction was still in progress
  • Fixed plugins from a URL marketplace failing to install with "marketplace entry path does not stay inside the marketplace directory" when a host app (e.g. Claude Desktop) stores it as a directory
  • Fixed an extra browser tab opening when an artifact is published in a session you're driving from claude.ai, the desktop app, or mobile (Remote Control)
  • Fixed the Artifact tool's first call failing with an "Invalid tool parameters" validation error in some Cowork sessions
  • Fixed IDE line selections being dropped when running a skill or slash command (the "N lines selected" context now reaches Claude)
  • Fixed repository detection for GitLab projects in nested subgroups (e.g. gitlab.com/group/subgroup/project)
  • Fixed owner/repo#123 issue references in rendered output linking to github.com when working in a GitLab repository; they now link to the gitlab.com issue
  • Glob/Grep: Fixed the search path being probed on disk before the permission check; a missing path is now reported after permission is decided, as Read does
  • Reverted the 2.1.259 change applying Read() deny rules to Bash arguments; it denied npm run build under a Read(./**/build/**) rule in every mode and made cd … && grep prompt even in auto mode
  • Improved structured output: Workflow agent({schema}) rejects a JSON Schema that can never be satisfied up front, and retry-cap errors now include the last validation failure
  • Improved deleting a background session whose worktree has unpushed commits: the message now names the branch and commit count, and deleting again discards the worktree
  • Improved the Claude apps gateway's refresh-failure log to name the step that failed
  • Improved idle CPU usage of non-interactive (-p / SDK) sessions
  • Improved the Claude apps gateway on Amazon Bedrock: input tokens for an aborted request are now counted with AWS's free CountTokens API (grant bedrock:CountTokens) instead of a one-token request
  • Improved the settings error for rules such as Edit(C:\dir\(name)\**), where \( is read as an escaped parenthesis rather than a path separator, to suggest an unambiguous spelling
  • Improved auto-compact for 1M-context models: Opus and Fable sessions now compact shortly before the 1M-token limit, and recovery compaction on very large contexts no longer times out at 10 minutes
  • Improved /ultrareview and claude ultrareview to wait up to 45 minutes (previously 30) for long-running cloud reviews

... (truncated)

Commits
  • b3f0e50 chore: Update CHANGELOG.md and feed.xml
  • ee2a058 Merge pull request #91894 from williamqian12/frontend-design-skill-update
  • f173a69 chore: Update CHANGELOG.md and feed.xml
  • dbdd79c Update /frontend-design SKILL.md
  • See full diff in compare view

Updates @biomejs/biome from 2.5.10 to 2.5.11

Release notes

Sourced from @​biomejs/biome's releases.

Biome CLI v2.5.11

2.5.11

Patch Changes

  • #11499 9743d0c Thanks @​scs0209! - Fixed #11496: useValidAnchor now treats Astro JSX shorthand attributes like <a {href}> as a valid href.

  • #11437 88f805e Thanks @​Princesseuh! - Fixed #9944: adjacent elements inside an Astro expression now parse as an implicit fragment instead of raising an error.

    {options.map(() =>
      <div />
      <div />
    )}
  • #11437 88f805e Thanks @​Princesseuh! - Fixed Astro templates rejecting unclosed HTML void elements, such as {cond && <br>}.

  • #11507 e2fc036 Thanks @​dyc3! - Fixed #11157: noUnusedVariables no longer reports Vue <script setup> bindings used by CSS v-bind() as unused.

  • #11398 afc4615 Thanks @​dyc3! - Fixed #11389: Files passed through --stdin-file-path now use full HTML support for Astro, Svelte, and Vue when it is enabled.

  • #11526 372cd68 Thanks @​dyc3! - Fixed noVueRefAsOperand to track Vue refs through declaration aliases and toRefs() properties, and to recognize useTemplateRef() results. The rule no longer reports false positives such as plain ref transfers, plain toRefs() property access, defineModel() modifiers, or the supported .effect member as operands.

    The refactor enabling these fixes also improves the performance of the rule.

  • #11458 a7cd286 Thanks @​dyc3! - Fixed #11436: GritQL snippets such as export { $specifiers } from $source now match named re-exports with aliases, inline type modifiers, and multiple specifiers.

  • #11515 382b15d Thanks @​dyc3! - Fixed #11390, where noFloatingPromises performed expensive full type inference for calls to non-Promise methods declared on third-party TypeScript classes. The rule now classifies those calls using targeted type information.

  • #11516 6f40e82 Thanks @​levrik! - Fixed noVueRefAsOperand so it no longer reports a callback parameter (e.g. from .find(), .map()) as an unwrapped ref value just because it's nested inside a ref(), computed(), or similar call.

    const result = computed(() => list.find((item) => item.label === "a"));

    Previously, item here was incorrectly treated as a ref value because the rule attributed it to the outer computed() call.

  • #11495 496268d Thanks @​Netail! - Fixed useGraphqlNamingConvention so it no longer reports GraphQL enum value definitions with comments & descriptions and now displays a more accurate diagnostic range.

  • #11407 6ef52b0 Thanks @​1678092075! - Fixed #11214: noUnusedVariables no longer reports type parameters declared by non-default function overload signatures that have an implementation.

  • #11322 5c353e6 Thanks @​jp-knj! - Added a new nursery rule noAstroSetHtmlDirective, which disallows Astro's set:html directive because untrusted content can introduce cross-site scripting vulnerabilities.

    For example, the following snippet triggers the rule:

    <div set:html={content} />

... (truncated)

Changelog

Sourced from @​biomejs/biome's changelog.

2.5.11

Patch Changes

  • #11499 9743d0c Thanks @​scs0209! - Fixed #11496: useValidAnchor now treats Astro JSX shorthand attributes like <a {href}> as a valid href.

  • #11437 88f805e Thanks @​Princesseuh! - Fixed #9944: adjacent elements inside an Astro expression now parse as an implicit fragment instead of raising an error.

    {options.map(() =>
      <div />
      <div />
    )}
  • #11437 88f805e Thanks @​Princesseuh! - Fixed Astro templates rejecting unclosed HTML void elements, such as {cond && <br>}.

  • #11507 e2fc036 Thanks @​dyc3! - Fixed #11157: noUnusedVariables no longer reports Vue <script setup> bindings used by CSS v-bind() as unused.

  • #11398 afc4615 Thanks @​dyc3! - Fixed #11389: Files passed through --stdin-file-path now use full HTML support for Astro, Svelte, and Vue when it is enabled.

  • #11526 372cd68 Thanks @​dyc3! - Fixed noVueRefAsOperand to track Vue refs through declaration aliases and toRefs() properties, and to recognize useTemplateRef() results. The rule no longer reports false positives such as plain ref transfers, plain toRefs() property access, defineModel() modifiers, or the supported .effect member as operands.

    The refactor enabling these fixes also improves the performance of the rule.

  • #11458 a7cd286 Thanks @​dyc3! - Fixed #11436: GritQL snippets such as export { $specifiers } from $source now match named re-exports with aliases, inline type modifiers, and multiple specifiers.

  • #11515 382b15d Thanks @​dyc3! - Fixed #11390, where noFloatingPromises performed expensive full type inference for calls to non-Promise methods declared on third-party TypeScript classes. The rule now classifies those calls using targeted type information.

  • #11516 6f40e82 Thanks @​levrik! - Fixed noVueRefAsOperand so it no longer reports a callback parameter (e.g. from .find(), .map()) as an unwrapped ref value just because it's nested inside a ref(), computed(), or similar call.

    const result = computed(() => list.find((item) => item.label === "a"));

    Previously, item here was incorrectly treated as a ref value because the rule attributed it to the outer computed() call.

  • #11495 496268d Thanks @​Netail! - Fixed useGraphqlNamingConvention so it no longer reports GraphQL enum value definitions with comments & descriptions and now displays a more accurate diagnostic range.

  • #11407 6ef52b0 Thanks @​1678092075! - Fixed #11214: noUnusedVariables no longer reports type parameters declared by non-default function overload signatures that have an implementation.

  • #11322 5c353e6 Thanks @​jp-knj! - Added a new nursery rule noAstroSetHtmlDirective, which disallows Astro's set:html directive because untrusted content can introduce cross-site scripting vulnerabilities.

    For example, the following snippet triggers the rule:

    <div set:html={content} />
  • #11462 18883b7 Thanks @​dyc3! - Fixed #10776: useVueHyphenatedAttributes no longer reports lowercase attribute names containing punctuation, such as pt:header:data-test-id and some_attr.

... (truncated)

Commits

@dependabot dependabot Bot added the dependencies Dependency updates (Dependabot / Renovate). label Sep 4, 2026
…th 2 updates

Bumps the npm-minor-patch group with 2 updates in the / directory: [@anthropic-ai/claude-code](https://github.com/anthropics/claude-code) and [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome).


Updates `@anthropic-ai/claude-code` from 2.1.258 to 2.1.260
- [Release notes](https://github.com/anthropics/claude-code/releases)
- [Changelog](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-code@v2.1.258...v2.1.260)

Updates `@biomejs/biome` from 2.5.10 to 2.5.11
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.11/packages/@biomejs/biome)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/claude-code"
  dependency-version: 2.1.260
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-minor-patch-b46d6fa992 branch from 5a92bea to a98248a Compare September 4, 2026 09:54

Copy link
Copy Markdown
Contributor

Babysit lane claim pinned to head a98248ac9a710ab1aa98ef5baf4552a1aa8e9bd3.

Observed at claim time: mergeable: true, mergeable_state: blocked, 11/11 check runs success (ci-status, lint, test-linux, test-windows, hook-utils, changes, pr-issue-linkage, pr-title, managed-files-guard, do-not-merge, GitGuardian), zero reviews, auto-merge not enabled.

Investigating the residual blocked state and advancing under this repo's tracked merge authority (.claude/source-control.md: tier worker, merge c3-autonomous). Claim expires at the timestamp above; I will release it when the cycle ends.


Generated by Claude Code

Copy link
Copy Markdown
Contributor

Diagnosis: behind-base, not review-blocked — escalating, no merge attempted

Lane babysit-loop, instance ccr-session-babysit-loop-20260905. Head still a98248ac, unchanged since the claim.

Why it is blocked despite 11/11 green

Not a missing review. The branch is 10 commits behind main — GET /compare/main...dependabot/npm_and_yarn/npm-minor-patch-b46d6fa992 returns status: diverged, ahead_by: 1, behind_by: 10 — while mergeable: true (no textual conflict).

This is the documented MergeStateStatus precedence trap: when a PR is simultaneously behind its base and blocked by another gate, GitHub reports BLOCKED and the BEHIND signal is lost. The babysit skill's own reference/freshness.md describes exactly this case and closes it with a compare-API fallback.

The concrete missing piece is the required-check set. This head was pushed 2026-09-04T02:28Z and its checks ran at 09:54Z, before the current lane layout landed on main. Comparing against merged bot PR #3737, this head is missing every review-lane context:

Context #3737 (merged) #3704 head
review / review skipped absent
review-skill-evidence success absent
security-review / security-review skipped absent
security-review / changes success absent
security-review-evidence success absent
skip-actors success absent

dependabot[bot] is the first entry in .github/claude-skip-actors, so those lanes skip for it but still emit their contexts — as they did for melodic-standards-sync[bot] on #3737, also a ratified skip actor. Refreshing this branch onto current main should therefore run the current workflow set and emit the six missing contexts, clearing the blocked state without any content change.

Why this lane did not do that, or merge

Three independent holds, none of which I routed around:

  1. Dependency hold-merge. A dependency-manager-authored PR is never merged autonomously in any tier, including autopilot; the merge gate refuses it absent --allow-dependency, which is passed only on an explicit human instruction to merge this specific PR. That instruction does not exist here.
  2. The merge gate could not run. This session ships gh 2.45.0, which predates pr view --json closingIssuesReferences, and the session's GraphQL surface is restricted to a pinned set of PR-review operations. The gate aborts with Unknown JSON field: "closingIssuesReferences". Per the skill's safety contract, a gate that never ran means readiness is UNPROVEN, and live gh state is explicitly not a substitute verdict — so nothing here should be read as "this PR is merge-ready".
  3. The guarded refresh helper could not run either. refresh_pr_branch.py requires a stored snapshot, and pr_queue_snapshot.py --write-state fails on the same toolchain gap (Unknown JSON field: "baseRefOid"). Refreshing the branch outside that helper would drop its optimistic-locking and refresh-ledger guards, so I did not improvise one.

What a human or a properly-toolchained lane should do

Refresh the branch, then let the emitted contexts settle. Either:

  • comment ·@·d·ependabot r·ebase (dependabot owns this branch), or
  • run the guarded helper from an environment with gh ≥ 2.55 and full GraphQL access:
python "${CLAUDE_PLUGIN_ROOT}/skills/babysit-prs/scripts/pr_queue_snapshot.py" --pr melodic-software/claude-code-plugins#3704 --owners melodic-software --state-dir <state-dir> --write-state
python "${CLAUDE_PLUGIN_ROOT}/skills/babysit-prs/scripts/refresh_pr_branch.py" --pr melodic-software/claude-code-plugins#3704 --expected-head-sha a98248ac9a710ab1aa98ef5baf4552a1aa8e9bd3 --lease-token <worker-token> --state-dir <state-dir> --apply

The merge itself remains a human decision regardless, per hold 1.

Lane claim released.


Generated by Claude Code

kyle-sexton added a commit that referenced this pull request Sep 7, 2026
…nted relay exception (#3481) (#3911)

Refs: #3481

No linked issue

Both linkage lines are present on purpose. This is a partial delivery of
#3481, which records five open limits and stays open with three of them,
so a closing keyword would be wrong. CI's `pr-contract` action accepts
`Refs:` in advisory mode, while the local `pr-linkage-mcp-gate.sh`
PreToolUse hook still enforces the shape of the `pr-issue-linkage.yml`
workflow deleted in `6b6989d9a` (#3746) and requires `Closes #N` or the
literal `No linked issue`.

## Summary

#3481 records five limits the relay-boundary hardening in #3473
deliberately left open. Two are actionable defects in published text;
three are deliberate no-action records that this PR leaves open, with
the reasoning re-checked against the code as it stands today rather than
inherited.

**Closed here (2 of 5):**

- **Limit 3, the tier-name divergence.** `SKILL.md`'s frontmatter
published the neutral tier as `source-not-identified` while every other
prose surface of the plugin says `not-found`. `SKILL.md` now says
`not-found` too, per the triage decision that defaulted to the majority
spelling. The reader's dual-spelling tolerance is untouched and now
documented as covering a retired name.
- **Limit 6, the miscounted exception** (filed as a comment on #3481, so
six recorded items with limit 5 since fixed under 0.5.3). The comment
introducing the stamp-rule relay exception in `emit-findings.sh` claimed
"ONE exception" where the classification chain has two. Corrected in the
comment, in its prose mirror in `context/persist-findings.md`, and
pinned by a test.

**Left open (3 of 5),** with reasons restated and confirmed against
current code:

- **Limit 1, an ambiguous tier list is withheld and can refuse the
sidecar.** Left. The original reason holds: the value half of `{"tier":
["fingerprint-confirmed", "not-found"]}` cannot be distinguished from
the `["not-found"]` evasion an earlier round closed, so any rule for
what a two-tier declaration *means* is a spec decision about the
sidecar's schema, not a reader change. It is already asserted as a
stated limit (`survive-ambiguous`), so it is visible rather than silent.
**Above this lane:** it needs a schema decision.
- **Limit 2, letter homoglyphs beyond the dash class.** Left. Confirmed
still bounded: the classification chain routes a record with an
unreadable declared `tier` to `## Unparsed` or the not-relay-eligible
count on every rule including the stamp rules, both visible and counted,
and `review:fanout` never auto-classifies `## Unparsed`. Closing it
means shipping a confusables table `jq` cannot reach, which reintroduces
the enumerate-what-someone-thought-of failure mode the class-based
normalization exists to escape. The *optional* wording refinement the
issue attached to this limit is adopted: `context/persist-findings.md`
now states the mechanism first and names rendering-equivalence as the
motive it approximates. The limit itself is unchanged and still stated.
- **Limit 4, duplicate case-folded keys.** Left. Confirmed not a
boundary hole: `jq` is last-wins and the reader's case-folded key
matching means both `{"tier": "a", "Tier": "b"}` spellings are read as
candidates, so the boundary sees both names and withholds if either is a
verdict. The residual risk is a *third-party* consumer reading the raw
sidecar first-wins and disagreeing with this reader. **Above this
lane:** closing it means either constraining the sidecar's schema or
asserting a canonical-key rule on producers, both cross-cutting.
- (**Limit 5** is already fixed under provenance 0.5.3 per the triage
addendum. Nothing to do; verified the suite's skip no longer routes
through `pass()`.)

Nothing here widens what crosses the relay boundary. The classification
chain is byte-identical to `origin/main`; every change is to published
text, plus one added test.

## Fix

- `skills/audit/SKILL.md`: frontmatter tier list says `not-found`.
One-field edit, the only published surface carrying the divergent
spelling.
- `skills/audit/scripts/emit-findings.sh`: two comment corrections. The
comment beside `is_verdict_name`/`is_neutral_name` now says `not-found`
is the published name and `source-not-identified` the retired one the
reader still accepts, with an explicit "do not narrow this to one name".
The comment above `own_tier_unreadable` now names **two** exceptions,
states that `withheld_verdict` is evaluated first and never lets a
judgment-verdict record reach the tier predicate, and keeps the correct
scoping paragraph about a benign `verdict` sibling.
- `skills/audit/context/persist-findings.md`: the relay-boundary section
drops the "under both the names this skill uses" framing for a paragraph
saying `not-found` is the published name and `source-not-identified` a
permanently tolerated retired one; the homoglyph section gains the
two-condition correction, since it framed the same claim as a single
exception; the normalization paragraph states the mechanism before the
motive.
- `skills/audit/scripts/emit-findings.test.sh`: one new case, four
assertions, pinning the second withholding condition. Its section
comment for the retired-spelling cases is updated to match.
- Version 0.5.7 with a CHANGELOG entry.

**Not done, and visible in a repository search.** The retired spelling
still appears in `plugins/provenance/CHANGELOG.md` (two historical
entries, which `--check-preserved` requires be kept) and in
`docs/specs/prompt-audit-skills-2026-09.md` line 647, a dated
prompt-audit record whose F20 entry describes the divergence as deferred
and also cites a `reference/rubric.md:297` occurrence that no longer
exists. I left that record alone as history rather than editing a dated
audit artifact; if the maintainer wants F20 marked resolved, that is a
one-line follow-up.

## Verification

All runs are local and in the foreground, from `/home/user/wt-3481` at
`6db96637d` (current `origin/main` at branch time and still current at
PR time).

- `bash scripts/affected-tests.sh --run` — **exit 0**, "All 5 selected
suites passed or were skipped": provenance `emit-findings.test.sh`, plus
`ai-slop/detect.test.sh`,
`claude-config/audit-instructions/emit-findings.test.sh`,
`docs-hygiene/audit-noise/emit-findings.test.sh`,
`testing/cant-fail-scan.test.sh`. `--explain` shows every changed file
mapped to a suite or to a recorded no-suite class; nothing fell through.
- `plugins/provenance/skills/audit/scripts/emit-findings.test.sh`
directly: **Passed: 388, Failed: 0, Host skips: 1**, up from 384/0/1 on
`origin/main` (the 4 new assertions).
- Changelog parity, all four modes, exit 0 each: `--check`,
`--check-order`, `--check-bump origin/main`, `--check-preserved
origin/main` ("All 1 changed changelog(s) preserve every version heading
they carried at `6db96637d`", 17 headings compared).
- Version collision check: fetched all 37 open PR heads and read
`plugins/provenance/.claude-plugin/plugin.json` on each. 35 at 0.5.6,
one at 0.5.4 (#3772), one at 0.5.3 (#3704). Nothing else takes 0.5.7.
Re-run immediately before opening this PR against a re-fetched
`origin/main` (still `6db96637d`).
- `shellcheck -x` and `shfmt -d` clean on both changed scripts. No new
files, so no exec-bit change; `git ls-tree` confirms both scripts stay
`100755`.

**The new assertions are non-vacuous, proved by three mutations of
`emit-findings.sh`, each reverted after measurement:**

1. Moving the stamp-rule branch ahead of `withheld_verdict` in the chain
(the exact defect the corrected comment describes): 12 failures,
including the new *"a stamp rule whose verdict names a judgment verdict
emits no relay row"* and *"and it is counted as withheld, not as
ineligible"*.
2. Routing `withheld_verdict` to `"X"` instead of `"W"`: 51 failures,
including the new *"counted as withheld, not as ineligible"* and *"takes
the withheld path, not the unreadable-tier path"* — these two are what
distinguish the withheld path from the not-relay-eligible path, so the
assertions discriminate rather than merely pass.
3. Routing `withheld_verdict` to `"U"`: 56 failures, including the new
*"and it leaks no payload"* (the `SVJCANARY` excerpt prints verbatim
into `## Unparsed`).

Every one of the four new assertions is killed by at least one mutation.
`git status` is clean of all three; the committed chain is unchanged
from `origin/main`.

**Reproduced before and after**, confirming no behavior change:
`{"findings":[{"rule":"rule-stamp-expired","file":"a.md","line":1,"verdict":"not-found","searched":["x"]}]}`
gives exit 0, 0 relay rows, and `Withheld from the relay: 1 judgment
findings` — identical on `origin/main` and on this branch.

**Not claimed.** Draft CI is not evidence here: `test-linux`
short-circuits on a draft and reports success without running. The
evidence above is the local foreground runs only. I did not run the full
suite, only the affected selection plus the provenance suite directly.
The one host skip in the provenance suite (`chmod a-w` not biting under
this uid) is pre-existing and self-labeling, and is limit 5, already
fixed in 0.5.3 so that it counts as a skip rather than a pass.

## Related

- Refs: #3481 — the five recorded limits, three of which this PR leaves
open by design
- #3473 — the relay-boundary hardening these were excluded from
- #3465 — the sweep sub-topic Brief
- #3746 / `6b6989d9a` — deleted `pr-issue-linkage.yml`, the reason both
linkage lines appear above

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01ViPsHkL3ng9xWt2GjEQJob

---
_Generated by [Claude
Code](https://claude.ai/code/session_01ViPsHkL3ng9xWt2GjEQJob)_

Co-authored-by: Claude <noreply@anthropic.com>
@kyle-sexton
kyle-sexton merged commit e45aee6 into main Sep 7, 2026
8 checks passed
@kyle-sexton
kyle-sexton deleted the dependabot/npm_and_yarn/npm-minor-patch-b46d6fa992 branch September 7, 2026 08:43
kyle-sexton added a commit that referenced this pull request Sep 7, 2026
…e views (#3607) (#3909)

Closes #3607

## Summary

Adds the rendered-views convention's second sanctioned shared piece,
`plugins/visualization/reference/html-loop-closure.html`, carried beside
the chrome reference and on the same sharing terms; adds the
convention's `## Loop closure and the export obligation` doctrine
section; and adds a fourth security-baseline bullet for the positions
HTML escaping does not reach.

Nothing adopts the snippets. `visualize` is unchanged apart from the
plugin's version and changelog, and adoption stays a per-lane change, as
the issue scopes it.

**Extracted versus invented, stated plainly.** I checked
`visualization:visualize` first, as instructed, and it carries no
loop-closure or export code: the plugin's only reference asset was
`html-chrome.html`, which has no `<script>` at all, and a repo-wide grep
for `writeText`, `execCommand`, and `clipboard` across
`plugins/*/skills` and `plugins/*/reference` returns only `playgrounds`
and `playwright`, both unrelated. There was nothing working to extract.
The pattern *family* is taken verbatim from the convention's own corpus
distillate (item 3, plus the clipboard boilerplate at item 4); the
helpers and demos are written for this repository, and the file's header
comment says so rather than implying corpus provenance.

## Fix

**The snippet reference.** One self-contained page, no external
requests, that both documents and runs the patterns. Four shared helpers
plus one export helper:

| Helper | What it covers |
|---|---|
| `esc` | The convention's escape set, `&` `<` `>` `"` `'`, `&` replaced
first so an entity is not double-decoded. One path for text and
quoted-attribute positions alike. |
| `copyText` | The clipboard boilerplate every interactive corpus page
duplicates: `navigator.clipboard.writeText`, the `execCommand` fallback,
a brief flash. Written once here. |
| `safeHref` | URL position. Scheme allowlist checked BEFORE escaping. |
| `safeFilename` | The `download` attribute, reduced to an allowlisted
character set. |
| `downloadText` | Export through a `Blob` and an object URL, revoked
after the click. |

Then one section per payload shape, each with a live demo that runs from
the file alone and a copyable snippet block: numbered resonate tokens,
chip-assembled replies, generated follow-up prompts, accept-and-correct
sign-off, live-state export (`buildMarkdown` over state, offered as both
clipboard and file download). The five helper snippet blocks are printed
from the live functions via `Function.prototype.toString()`, so the text
a reader copies is the text the page executes and the two cannot drift.

**How each snippet handles the five-character escape.** Every pattern
routes through the single `esc` above, or avoids interpolation entirely
by assigning `textContent` (patterns 2, 3, 4, and 5 do the latter for
whole text nodes; pattern 1 interpolates a label into `innerHTML` and
calls `esc` on it, and its demo data deliberately contains `<timeout>`,
a double quote, and an apostrophe so the escape is exercised on load).
The page declares no inline handler attribute anywhere and interpolates
nothing into `<script>` or `<style>`; every control is wired with
`addEventListener`. All three properties are asserted by the test suite
below.

**URL-position and scheme hazards, which the five-character rule does
not cover.** `javascript:alert(1)` contains none of the five characters,
so it survives `esc` unchanged and still runs on click. `safeHref`
therefore parses the value and allowlists `https:`, `http:`, and
`mailto:` (a bare `#fragment` passes through); `javascript:`, `data:`,
`vbscript:`, `file:`, and relative URLs all resolve to `#`. Exports
never build a `data:` URL, because a data URL puts the payload in URL
position where percent-encoding rather than HTML escaping applies, and
`data:text/html` runs script; `downloadText` uses a `Blob` and
`URL.createObjectURL`, so no input reaches the URL string at all. The
`download` filename is reader-reachable, so `safeFilename` reduces it to
`[A-Za-z0-9._-]`, strips a leading dot run, and caps the length.

**Restatement, and what is new rather than restated.** I did NOT
register a clause. The snippet file does not restate the security
baseline's rules: it names the convention as their owner and
demonstrates them, which is the pointer-not-copy exit
`check-contract-clause-coverage.py` says is the stronger fix. Note for
the reviewer: #3896 is still OPEN, so its
`rendered-views-security-baseline` clause is not on `main`; adding a
same-id entry here would have collided with it. The clause gate passes
unchanged on this branch (`4 canonical surface(s), 14 tagged
restatement(s), 16 surface(s) that point rather than restate`), the same
counts as `main`.

The URL-position and scheme rule is genuinely NEW, not a restatement,
and I put it in the convention rather than only in the snippet, per the
brief: `docs/conventions/rendered-views/README.md`, "Security baseline",
fourth bullet. It sits after the existing third bullet, outside where
#3896's span markers land on the first two, so the two changes should
not collide textually.

**Doctrine section.** `## Loop closure and the export obligation`: when
a view owes an export (a custom editor always ends with one; a view that
asks the reader to choose, rank, accept, or correct owes a payload; a
view that only presents owes neither), that the family is excluded from
the writeup and report genre by design with the reason given, that
payloads stay terse because the artifact stays visible, and the five
shapes named cheapest-first. A second short section names the snippet
file's canonical path and its sharing terms.

**Registry mechanics.** Registration in
`scripts/cross-plugin-source-registry.txt` is deliberately absent,
matching how the chrome reference is carried: the drift checker rejects
a registration while only one plugin holds the file, so the first
adoption ships unregistered by design. The convention's new section
states that explicitly. `scripts/check-cross-plugin-source-drift.sh
--check` passes.

**What catches a future regression, since this is mostly prose.** Three
things, and I want to be precise about which covers what:

1. `scripts/check-html-assets.sh` gains the asset in its manifest. That
is markup lint (pinned htmlhint) plus the registration check. It catches
syntax and an unregistered sibling. It says NOTHING about escaping.
2. `scripts/check-loop-closure-helpers.test.sh` (new, `100755`, wired
into ci.yml next to the html-assets steps) is the behavioral gate. It
extracts the helper block from the shipped asset between the two comment
markers the file uses to bound it, executes `esc`, `safeHref`, and
`safeFilename`, and asserts 42 properties: each of the five escape
characters, the `&`-first ordering, no raw quote of either kind
surviving, every rejected scheme above, the filename cases, and
source-level assertions on the two DOM helpers (`copyText` keeps both
the async write and the `execCommand` fallback and never uses
`innerHTML`; `downloadText` uses Blob/createObjectURL/revokeObjectURL,
sanitizes the filename, and contains no `data:`). It also asserts the
asset's self-containment: no absolute http(s) URL, no `<link>`, no
`src=`, no `@import`, no inline handler attribute.
3. The doctrine prose itself has NO gate. Markdownlint and the ai-slop
detector check style, not content. If a later editor deletes the
writeup-and-report exclusion or the export obligation, nothing
mechanical catches it. I considered registering the doctrine as a
contract clause, but a clause registry entry only holds RESTATEMENTS in
agreement with a canonical; with exactly one copy of this doctrine there
is nothing to hold together yet. The right moment for a clause is the
first lane that restates it, which is out of scope here.

## Verification

Three commits. The third, `d1f3c973a`, is a CI fix and nothing else: the
first CI run went red on `shell-portability-lint` because that gate
reads the whole shell file including the heredoc, so the JavaScript
driver's `\b` and `\s` shorthands read as GNU-only grep constructs. The
three self-containment patterns now spell their character classes out or
use a plain substring test, and the backslash case builds its character
from a code point. Same 42 assertions, all still passing, and `bash
scripts/check-shell-portability.sh origin/main` now reports `No
unexcused GNU-only constructs in 2 shell file(s)`.

Everything below was run in the foreground in the worktree. Base
`ddb3ab347`; the suite runs below were on `53965a001` and re-verified on
the final head `d1f3c973a` where the change touched them.

- **Discriminating proof for the new suite.** With `.replace(/'/g,
"&#39;")` deleted from `esc` and nothing else changed,
`check-html-assets.sh` still reported `All registered rendered-view HTML
assets lint clean` (exit 0) while `check-loop-closure-helpers.test.sh`
failed with `PASS=40 FAIL=2` naming `esc escapes "'" to &#39;` and `esc
leaves no raw single quote that could close a single-quoted attribute`
(exit 1). Restored, it is `PASS=42 FAIL=0`. That is the gap this suite
exists to close, demonstrated rather than asserted.
- `bash scripts/affected-tests.sh --explain`: the three markdown/JSON
files resolve to recorded no-suite classes; the new suite is selected by
the reference rule (`references html-loop-closure.html`) and
`check-html-assets.test.sh` by co-location. The ci.yml edit fans the
selection out to 165 suites, so `--run` was sharded 6 ways rather than
risking the timeout.
- `bash scripts/affected-tests.sh --run --shard <i>/6`, all six legs:
legs 0, 3, 4, 5 exit 3 (shell suites all passed, other-ecosystem suites
listed as NOT RUN); leg 1 exit 0; leg 2 exit 1 from
`plugins/claude-ops/skills/plugins/scripts/cache-content-check.test.sh`
alone, failing its two process-budget assertions, which is the known
pre-existing 2-of-24 failure and touches nothing in this change. No
other suite failed in any leg. `PASS:
scripts/check-loop-closure-helpers.test.sh` and `PASS:
scripts/check-html-assets.test.sh` both appear in leg 1.
- `bash scripts/check-changelog-parity.sh` in all four modes: `--check`
0, `--check-order` 0 (92 changelogs), `--check-bump origin/main` 0,
`--check-preserved origin/main` 0 (1 changed changelog, 18 headings
compared).
- `bash scripts/check-html-assets.sh`: exit 0. `bash
scripts/check-cross-plugin-source-drift.sh --check`: exit 0. `bash
scripts/check-lane-coverage.sh --check`: exit 0, 4 lanes reachable (the
new CI entry is a step in an existing job, not a new job). `python3
scripts/check-contract-clause-coverage.py`: exit 0. `shellcheck
scripts/check-loop-closure-helpers.test.sh`: exit 0.
- `actionlint .github/workflows/ci.yml`: exit 0. The workflow also
parses under `yaml.safe_load`.
- `markdownlint-cli2` over the two changed markdown files: 0 issues.
ai-slop `detect.sh` over the same two: 0 findings across all rules. Note
the repo config disables the em-dash rule, so that run says nothing
about em dashes; a direct check of added lines in `git diff origin/main`
shows 0 em dashes. No formatting was taken from
`plugins/*/skills/*/vendor/**`.
- `git ls-tree`: `scripts/check-loop-closure-helpers.test.sh` is
`100755`; the asset is `100644`.
- **Version collision re-check, done twice.** `visualization` 0.5.1 to
0.5.2 with a matching changelog entry. Checked against `origin/main`
(0.5.1) and every open PR head fetched via `refs/pull/*/head`: no head
carries 0.5.2 (the only non-0.5.1 heads are #3772 at 0.5.0 and #3704 at
0.4.2). Re-fetched and re-scanned immediately before opening this PR;
still clear.
- **CI on the final head `d1f3c973a`: `ci-status: success`**, 11 checks
complete, none failing (`lint`, `hook-utils`, `changes`,
`managed-files-guard`, `GitGuardian`, the four `test-linux` shards,
`test-windows` skipped).

**Unmet or partial, stated plainly.**

- Because this PR is a DRAFT, the `test-linux` lanes short-circuit with
"this is a draft pull request ... reporting success" and run no suites.
So CI has **not** actually executed `check-loop-closure-helpers.test.sh`
yet; it runs on the flip to ready. Every claim about that suite above
rests on the local runs, not on a CI observation.
- The doctrine prose has no mechanical gate, as set out above.
- The snippet file is not registered in the cross-plugin source
registry, which is correct today but means the byte-identical guarantee
only begins at the second adopter.
- `copyText` is asserted at source level rather than executed, because
it needs a DOM and a clipboard; its `execCommand` fallback is therefore
never run by CI.
- I did not verify the demos in a real browser: the container has no
browser, so "every demo runs from this file alone" rests on the code and
the helper suite, not on an observed render.

## Related

- Closes #3607
- Relates to: #3896 (still open at the time of writing; it registers the
`rendered-views-security-baseline` clause and moves both retrofit lanes
onto the baseline. This PR deliberately adds no clause entry so the two
do not collide, and its new baseline bullet sits outside where #3896's
span markers land)
- Relates to: #3605 (the deterministic escape helper with a generator
marker. The helpers here are instruction-level snippets under the wave-1
skeleton, not that helper, and nothing here is gated on it)
- Relates to: #3606 (the reports and research genre lanes, which the
exclusion rule in the new doctrine section explicitly keeps out of this
family)
- `docs/conventions/rendered-views/README.md`, "Security baseline",
"Loop closure and the export obligation", "The loop-closure and export
snippet reference"

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01ViPsHkL3ng9xWt2GjEQJob

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: ksextonmelodic <ksextonmelodic@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates (Dependabot / Renovate).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant