Skip to content

[ca] Update agentic CLI and MCP default version pins #66465

Description

@github-actions

Overview

Version changes were detected during CLI Version Checker run §37576962346. I updated the local version constants and related generated install fallback for the eligible stable releases, then ran formatting, recompilation, and unit checks.

Proposed pin updates

Tool Current Latest Source Risk
Claude Code 2.1.288 2.1.292 npm @anthropic-ai/claude-code Low
GitHub Copilot CLI 1.0.90 1.0.92 npm @github/copilot and GitHub release Medium
OpenAI Codex 0.159.3 0.160.1 npm @openai/codex and GitHub release rust-v0.160.1 Low
Pi 1.0.0 1.0.4 npm @earendil-works/pi-coding-agent Low/Medium
Playwright CLI 0.1.21 0.1.22 npm @playwright/cli and GitHub release Low
GitHub MCP Server v1.12.2 v2.0.0 GitHub latest release Medium/High

Updated local files:

  • pkg/constants/version_constants.go
  • pkg/constants/version_constants_test.go
  • actions/setup/sh/install_copilot_cli.sh (via make recompile)
  • generated workflow lock files and .github/aw/compat.json changed during required foreground make recompile

Key metrics and validation

  • npm metadata fetched for all npm-sourced tools.
  • GitHub releases fetched for Copilot CLI, Codex, Playwright CLI, GitHub MCP Server, MCP Gateway, threat-detect, and Docker scanner image projects.
  • CLI help comparison performed for updated npm tools.
  • Docker scanner image digests were resolved for every currently pinned tag; no digest-only changes were detected.
  • Validation completed:
    • make fmt
    • make recompile
    • make test-unit
    • go test ./pkg/constants

Change analysis

Claude Code 2.1.288 → 2.1.292

Release timeline: latest npm version published 2026-10-06T17:10:31.715Z.

  • Breaking: none identified from npm metadata/help comparison.
  • Features/Fixes: CLI help now documents background-session commands accepting partial session names for attach/logs.
  • Security: none identified.
  • Performance: none identified.
  • Impact on gh-aw: low; default engine pin update only. Existing top-level help remains otherwise compatible.

GitHub Copilot CLI 1.0.90 → 1.0.92

Release timeline: v1.0.91 on 2026-10-01; v1.0.92 on 2026-10-05. Latest npm version published 2026-10-05T19:42:06.555Z.

Release links:

  • https://github.com/github/copilot-cli/releases/tag/v1.0.92

  • https://github.com/github/copilot-cli/releases/tag/v1.0.91

  • Breaking: no explicit breaking change identified.

  • Features: new copilot config command group; new sandbox command group; pre-conversation Ctrl+E environment picker; canvas actions can return images to invoke_canvas_action.

  • Fixes: MCP token renewal, HTTP+SSE MCP timeout handling, remote session resume auth, shell streaming reliability, large-file session slowdown, OAuth/MCP recovery, Windows sandbox temp handling, startup responsiveness.

  • Security: sandboxed shells now withhold ambient GITHUB_TOKEN unless explicitly configured; sandbox CA commands now respect --config-dir.

  • Performance: improved first-run startup and connection to many MCP servers.

  • Impact on gh-aw: medium. New sandbox behavior and token withholding are positive but should be checked against existing Copilot sandbox workflows and auth assumptions.

  • Help output delta: main help adds config and sandbox commands. copilot config --help documents list/read/set/remove behavior and JSON output. copilot environment --help is not a direct subcommand and returned the prompt-mode suggestion, so no environment subcommand help comparison was available.

  • Documentation review: README continues to describe terminal-native Copilot CLI, npm installation, experimental mode, LSP configuration, and feedback paths. Changelog entry for 1.0.92 was available by code search; repository changelog is large, so targeted search was used.

Copilot CLI v1.0.92 release highlights
  • Add copilot config subcommands to list, read, set, and remove settings.
  • Add a pre-conversation Ctrl+E environment picker to switch between local and cloud runs.
  • Entra-protected MCP servers can silently renew access-token-only credentials.
  • Legacy HTTP+SSE MCP connections no longer hang indefinitely when a message POST is never acknowledged.
  • Shell tool calls stream live stdout and stderr reliably in the timeline.
  • Sessions no longer slow to a crawl for minutes after the agent writes a very large file in one step.
  • Sandboxed shells now withhold ambient GITHUB_TOKEN unless explicitly configured.
  • Search commands avoid sandbox bypass prompts when access is already granted.
  • MCP tools recover within the same turn when server instructions change.
  • Canvas actions can now return images to the model in invoke_canvas_action.
  • Remove retired models from the model picker and supported CLI selections.

Full release: https://github.com/github/copilot-cli/releases/tag/v1.0.92

OpenAI Codex 0.159.3 → 0.160.1

Release timeline: rust-v0.160.1 published 2026-10-05T18:29:37Z. Latest npm version published 2026-10-05T18:33:51.980Z.

Release link: https://github.com/openai/codex/releases/tag/rust-v0.160.1

  • Breaking: none identified.
  • Features: none identified in 0.160.1 release notes.
  • Fixes: preserves SYSTEMROOT, TEMP, and TMP when launching remote stdio MCP servers with explicitly configured remote environment variables, allowing Unix hosts to retain the Windows executor startup environment.
  • Security: none identified.
  • Performance: none identified.
  • Impact on gh-aw: low; relevant to remote MCP server execution on Windows/Unix boundary scenarios.
  • Help output delta: no top-level help changes detected between 0.159.3 and 0.160.1.
Codex rust-v0.160.1 changelog

Full release: https://github.com/openai/codex/releases/tag/rust-v0.160.1

Pi 1.0.0 → 1.0.4

Release timeline: latest npm version published 2026-10-05T21:51:59.920Z.

  • Breaking: none explicitly identified from npm metadata/help comparison.
  • Features/Fixes: tool allow/deny lists now accept patterns; --tools preserves MCP tools unless an entry starts with mcp__; --exclude-tools applies to all tools including MCP; new --no-mcp disables built-in MCP support; examples include MCP tool wildcard usage.
  • Security: more explicit MCP tool scoping behavior may reduce accidental over/under-inclusion.
  • Performance: none identified.
  • Impact on gh-aw: low/medium. Workflows depending on Pi tool filtering should account for changed MCP inclusion semantics.

Playwright CLI 0.1.21 → 0.1.22

Release timeline: v0.1.22 published 2026-09-28T23:23:13Z; npm latest published 2026-09-28T23:24:31.286Z. This is outside the 3-day npm release-age cooldown enforced by the repository test.

Release link: https://github.com/microsoft/playwright-cli/releases/tag/v0.1.22

  • Breaking: none identified.
  • Features: find --filename=results.md saves matches to a file when a query produces too many results.
  • Fixes: run-code scripts can use timers, fetch, URL, Buffer, crypto, AbortController, TextEncoder/TextDecoder; goto/reload dialog reporting; download close crash; install-browser --no-shell accepted; webmcp-call stale tab/frame and Chromium 155+ fixes; snapshot quoting for regex-like accessible names; bundled skill preapproves only Playwright commands instead of any npm/npx command.
  • Security: bundled skill preapproval narrowing reduces command over-approval risk.
  • Performance: none identified.
  • Impact on gh-aw: low; improves Playwright agent safety and reliability.
  • Help output delta: no top-level help changes detected between 0.1.21 and 0.1.22.

GitHub MCP Server v1.12.2 → v2.0.0

Release timeline: latest release published 2026-10-06T23:34:00Z.

Release link: https://github.com/github/github-mcp-server/releases/tag/v2.0.0

  • Breaking: potential protocol compatibility risk due major version. Release notes say typed structured outputs/output schemas are only advertised to clients advertising MCP 2026-07-28 or later; compound tools needed allowed output schema updates that are invalid for older clients and are withheld from them.
  • Features: structured outputs and output schemas; typed MCP tool registration foundation; typed tool schemas and outputs across context, comments, search, security, discussions/notifications, repos, issues, PRs, actions.
  • Fixes: typed output compatibility gaps addressed.
  • Security: GitHub Actions pinned to commit SHAs.
  • Performance: tools/list schema encoding cache.
  • Impact on gh-aw: medium/high. Validate client protocol negotiation and typed output handling before relying on the new default broadly.
GitHub MCP Server v2.0.0 selected changes

Full release: https://github.com/github/github-mcp-server/releases/tag/v2.0.0

Docker image check

No Docker scanner image constants changed.

Constant Current tag Registry digest result Action
ActionlintImage rhysd/actionlint:1.7.12 unchanged sha256:b1934ee5f1c509618f2508e6eb47ee0d3520686341fec936f3b79331f9315667 none
SyftImage anchore/syft:v1.52.0 unchanged sha256:500e2d872ac019436926e8322b4fc1f39441d94d21f6f4046c6ff29b30e8cb02 latest v1.54.1 skipped; release was less than 3 days old
GrypeImage anchore/grype:v0.119.0 unchanged sha256:8c2c9234a345577a6d321a4753aa3ee1276d8975c8452d2344a56b57733ecad3 latest v0.120.1 skipped; release was less than 3 days old
GrantImage anchore/grant:v0.6.8 unchanged sha256:172463611795f43b77302cdfbd7b3f81295492a7330e0820cfe41c3674920237 none
ZizmorImage ghcr.io/zizmorcore/zizmor:1.30.1 unchanged sha256:a2eb396d886c053073405c7a980f2139ba2248ec172243cfa3841e57196e8101 none
PoutineImage ghcr.io/boostsecurityio/poutine:1.1.6 unchanged sha256:722a8e0999b583c1540fe2974e691032b2d9d21b9256a17965132b6bfd0081b0 none
RunnerGuardImage ghcr.io/vigilant-llc/runner-guard:3.1.5 unchanged sha256:2df426ef96d21f1622e05b21329f26bd263fc46110609cefb6afe43457613ac0 none
YamllintImage pipelinecomponents/yamllint:latest unchanged sha256:5ab5eb7da0ed5e606b07c1723fc8b275e925189f70ac259b26b7329cb5f8f44d GitHub latest release endpoint returned 404; registry digest unchanged

MCP Gateway and threat-detect were already current:

Next actions

  • Review and open a PR carrying the local constant updates plus generated artifacts expected by repository policy.
  • Pay special attention to GitHub MCP Server v2.0.0 protocol-gated typed outputs before rollout.
  • Re-check Syft and Grype after the 3-day Docker release cooldown passes.

References:

Generated by 🔢 CLI Version Checker · pi · gpt55 · 269.2 AIC · ⌖ 18.4 AIC · ⊞ 11K · ◷

  • expires on Oct 8, 2026, 9:43 PM UTC-08:00

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    automationcookieIssue Monster Loves Cookies!dependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions