Overview
Version changes were detected during CLI Version Checker run §37576962346. I updated the local version constants and related generated install fallback for the eligible stable releases, then ran formatting, recompilation, and unit checks.
Proposed pin updates
| Tool |
Current |
Latest |
Source |
Risk |
| Claude Code |
2.1.288 |
2.1.292 |
npm @anthropic-ai/claude-code |
Low |
| GitHub Copilot CLI |
1.0.90 |
1.0.92 |
npm @github/copilot and GitHub release |
Medium |
| OpenAI Codex |
0.159.3 |
0.160.1 |
npm @openai/codex and GitHub release rust-v0.160.1 |
Low |
| Pi |
1.0.0 |
1.0.4 |
npm @earendil-works/pi-coding-agent |
Low/Medium |
| Playwright CLI |
0.1.21 |
0.1.22 |
npm @playwright/cli and GitHub release |
Low |
| GitHub MCP Server |
v1.12.2 |
v2.0.0 |
GitHub latest release |
Medium/High |
Updated local files:
- pkg/constants/version_constants.go
- pkg/constants/version_constants_test.go
- actions/setup/sh/install_copilot_cli.sh (via make recompile)
- generated workflow lock files and .github/aw/compat.json changed during required foreground make recompile
Key metrics and validation
- npm metadata fetched for all npm-sourced tools.
- GitHub releases fetched for Copilot CLI, Codex, Playwright CLI, GitHub MCP Server, MCP Gateway, threat-detect, and Docker scanner image projects.
- CLI help comparison performed for updated npm tools.
- Docker scanner image digests were resolved for every currently pinned tag; no digest-only changes were detected.
- Validation completed:
- make fmt
- make recompile
- make test-unit
- go test ./pkg/constants
Change analysis
Claude Code 2.1.288 → 2.1.292
Release timeline: latest npm version published 2026-10-06T17:10:31.715Z.
- Breaking: none identified from npm metadata/help comparison.
- Features/Fixes: CLI help now documents background-session commands accepting partial session names for attach/logs.
- Security: none identified.
- Performance: none identified.
- Impact on gh-aw: low; default engine pin update only. Existing top-level help remains otherwise compatible.
GitHub Copilot CLI 1.0.90 → 1.0.92
Release timeline: v1.0.91 on 2026-10-01; v1.0.92 on 2026-10-05. Latest npm version published 2026-10-05T19:42:06.555Z.
Release links:
-
https://github.com/github/copilot-cli/releases/tag/v1.0.92
-
https://github.com/github/copilot-cli/releases/tag/v1.0.91
-
Breaking: no explicit breaking change identified.
-
Features: new copilot config command group; new sandbox command group; pre-conversation Ctrl+E environment picker; canvas actions can return images to invoke_canvas_action.
-
Fixes: MCP token renewal, HTTP+SSE MCP timeout handling, remote session resume auth, shell streaming reliability, large-file session slowdown, OAuth/MCP recovery, Windows sandbox temp handling, startup responsiveness.
-
Security: sandboxed shells now withhold ambient GITHUB_TOKEN unless explicitly configured; sandbox CA commands now respect --config-dir.
-
Performance: improved first-run startup and connection to many MCP servers.
-
Impact on gh-aw: medium. New sandbox behavior and token withholding are positive but should be checked against existing Copilot sandbox workflows and auth assumptions.
-
Help output delta: main help adds config and sandbox commands. copilot config --help documents list/read/set/remove behavior and JSON output. copilot environment --help is not a direct subcommand and returned the prompt-mode suggestion, so no environment subcommand help comparison was available.
-
Documentation review: README continues to describe terminal-native Copilot CLI, npm installation, experimental mode, LSP configuration, and feedback paths. Changelog entry for 1.0.92 was available by code search; repository changelog is large, so targeted search was used.
Copilot CLI v1.0.92 release highlights
- Add copilot config subcommands to list, read, set, and remove settings.
- Add a pre-conversation Ctrl+E environment picker to switch between local and cloud runs.
- Entra-protected MCP servers can silently renew access-token-only credentials.
- Legacy HTTP+SSE MCP connections no longer hang indefinitely when a message POST is never acknowledged.
- Shell tool calls stream live stdout and stderr reliably in the timeline.
- Sessions no longer slow to a crawl for minutes after the agent writes a very large file in one step.
- Sandboxed shells now withhold ambient GITHUB_TOKEN unless explicitly configured.
- Search commands avoid sandbox bypass prompts when access is already granted.
- MCP tools recover within the same turn when server instructions change.
- Canvas actions can now return images to the model in invoke_canvas_action.
- Remove retired models from the model picker and supported CLI selections.
Full release: https://github.com/github/copilot-cli/releases/tag/v1.0.92
OpenAI Codex 0.159.3 → 0.160.1
Release timeline: rust-v0.160.1 published 2026-10-05T18:29:37Z. Latest npm version published 2026-10-05T18:33:51.980Z.
Release link: https://github.com/openai/codex/releases/tag/rust-v0.160.1
- Breaking: none identified.
- Features: none identified in 0.160.1 release notes.
- Fixes: preserves SYSTEMROOT, TEMP, and TMP when launching remote stdio MCP servers with explicitly configured remote environment variables, allowing Unix hosts to retain the Windows executor startup environment.
- Security: none identified.
- Performance: none identified.
- Impact on gh-aw: low; relevant to remote MCP server execution on Windows/Unix boundary scenarios.
- Help output delta: no top-level help changes detected between 0.159.3 and 0.160.1.
Codex rust-v0.160.1 changelog
Full release: https://github.com/openai/codex/releases/tag/rust-v0.160.1
Pi 1.0.0 → 1.0.4
Release timeline: latest npm version published 2026-10-05T21:51:59.920Z.
- Breaking: none explicitly identified from npm metadata/help comparison.
- Features/Fixes: tool allow/deny lists now accept patterns; --tools preserves MCP tools unless an entry starts with mcp__; --exclude-tools applies to all tools including MCP; new --no-mcp disables built-in MCP support; examples include MCP tool wildcard usage.
- Security: more explicit MCP tool scoping behavior may reduce accidental over/under-inclusion.
- Performance: none identified.
- Impact on gh-aw: low/medium. Workflows depending on Pi tool filtering should account for changed MCP inclusion semantics.
Playwright CLI 0.1.21 → 0.1.22
Release timeline: v0.1.22 published 2026-09-28T23:23:13Z; npm latest published 2026-09-28T23:24:31.286Z. This is outside the 3-day npm release-age cooldown enforced by the repository test.
Release link: https://github.com/microsoft/playwright-cli/releases/tag/v0.1.22
- Breaking: none identified.
- Features: find --filename=results.md saves matches to a file when a query produces too many results.
- Fixes: run-code scripts can use timers, fetch, URL, Buffer, crypto, AbortController, TextEncoder/TextDecoder; goto/reload dialog reporting; download close crash; install-browser --no-shell accepted; webmcp-call stale tab/frame and Chromium 155+ fixes; snapshot quoting for regex-like accessible names; bundled skill preapproves only Playwright commands instead of any npm/npx command.
- Security: bundled skill preapproval narrowing reduces command over-approval risk.
- Performance: none identified.
- Impact on gh-aw: low; improves Playwright agent safety and reliability.
- Help output delta: no top-level help changes detected between 0.1.21 and 0.1.22.
GitHub MCP Server v1.12.2 → v2.0.0
Release timeline: latest release published 2026-10-06T23:34:00Z.
Release link: https://github.com/github/github-mcp-server/releases/tag/v2.0.0
- Breaking: potential protocol compatibility risk due major version. Release notes say typed structured outputs/output schemas are only advertised to clients advertising MCP 2026-07-28 or later; compound tools needed allowed output schema updates that are invalid for older clients and are withheld from them.
- Features: structured outputs and output schemas; typed MCP tool registration foundation; typed tool schemas and outputs across context, comments, search, security, discussions/notifications, repos, issues, PRs, actions.
- Fixes: typed output compatibility gaps addressed.
- Security: GitHub Actions pinned to commit SHAs.
- Performance: tools/list schema encoding cache.
- Impact on gh-aw: medium/high. Validate client protocol negotiation and typed output handling before relying on the new default broadly.
GitHub MCP Server v2.0.0 selected changes
Full release: https://github.com/github/github-mcp-server/releases/tag/v2.0.0
Docker image check
No Docker scanner image constants changed.
| Constant |
Current tag |
Registry digest result |
Action |
| ActionlintImage |
rhysd/actionlint:1.7.12 |
unchanged sha256:b1934ee5f1c509618f2508e6eb47ee0d3520686341fec936f3b79331f9315667 |
none |
| SyftImage |
anchore/syft:v1.52.0 |
unchanged sha256:500e2d872ac019436926e8322b4fc1f39441d94d21f6f4046c6ff29b30e8cb02 |
latest v1.54.1 skipped; release was less than 3 days old |
| GrypeImage |
anchore/grype:v0.119.0 |
unchanged sha256:8c2c9234a345577a6d321a4753aa3ee1276d8975c8452d2344a56b57733ecad3 |
latest v0.120.1 skipped; release was less than 3 days old |
| GrantImage |
anchore/grant:v0.6.8 |
unchanged sha256:172463611795f43b77302cdfbd7b3f81295492a7330e0820cfe41c3674920237 |
none |
| ZizmorImage |
ghcr.io/zizmorcore/zizmor:1.30.1 |
unchanged sha256:a2eb396d886c053073405c7a980f2139ba2248ec172243cfa3841e57196e8101 |
none |
| PoutineImage |
ghcr.io/boostsecurityio/poutine:1.1.6 |
unchanged sha256:722a8e0999b583c1540fe2974e691032b2d9d21b9256a17965132b6bfd0081b0 |
none |
| RunnerGuardImage |
ghcr.io/vigilant-llc/runner-guard:3.1.5 |
unchanged sha256:2df426ef96d21f1622e05b21329f26bd263fc46110609cefb6afe43457613ac0 |
none |
| YamllintImage |
pipelinecomponents/yamllint:latest |
unchanged sha256:5ab5eb7da0ed5e606b07c1723fc8b275e925189f70ac259b26b7329cb5f8f44d |
GitHub latest release endpoint returned 404; registry digest unchanged |
MCP Gateway and threat-detect were already current:
Next actions
- Review and open a PR carrying the local constant updates plus generated artifacts expected by repository policy.
- Pay special attention to GitHub MCP Server v2.0.0 protocol-gated typed outputs before rollout.
- Re-check Syft and Grype after the 3-day Docker release cooldown passes.
References:
Generated by 🔢 CLI Version Checker · pi · gpt55 · 269.2 AIC · ⌖ 18.4 AIC · ⊞ 11K · ◷
Overview
Version changes were detected during CLI Version Checker run §37576962346. I updated the local version constants and related generated install fallback for the eligible stable releases, then ran formatting, recompilation, and unit checks.
Proposed pin updates
@anthropic-ai/claude-code@github/copilotand GitHub release@openai/codexand GitHub release rust-v0.160.1@earendil-works/pi-coding-agent@playwright/cliand GitHub releaseUpdated local files:
Key metrics and validation
Change analysis
Claude Code 2.1.288 → 2.1.292
Release timeline: latest npm version published 2026-10-06T17:10:31.715Z.
GitHub Copilot CLI 1.0.90 → 1.0.92
Release timeline: v1.0.91 on 2026-10-01; v1.0.92 on 2026-10-05. Latest npm version published 2026-10-05T19:42:06.555Z.
Release links:
https://github.com/github/copilot-cli/releases/tag/v1.0.92
https://github.com/github/copilot-cli/releases/tag/v1.0.91
Breaking: no explicit breaking change identified.
Features: new copilot config command group; new sandbox command group; pre-conversation Ctrl+E environment picker; canvas actions can return images to invoke_canvas_action.
Fixes: MCP token renewal, HTTP+SSE MCP timeout handling, remote session resume auth, shell streaming reliability, large-file session slowdown, OAuth/MCP recovery, Windows sandbox temp handling, startup responsiveness.
Security: sandboxed shells now withhold ambient GITHUB_TOKEN unless explicitly configured; sandbox CA commands now respect --config-dir.
Performance: improved first-run startup and connection to many MCP servers.
Impact on gh-aw: medium. New sandbox behavior and token withholding are positive but should be checked against existing Copilot sandbox workflows and auth assumptions.
Help output delta: main help adds config and sandbox commands. copilot config --help documents list/read/set/remove behavior and JSON output. copilot environment --help is not a direct subcommand and returned the prompt-mode suggestion, so no environment subcommand help comparison was available.
Documentation review: README continues to describe terminal-native Copilot CLI, npm installation, experimental mode, LSP configuration, and feedback paths. Changelog entry for 1.0.92 was available by code search; repository changelog is large, so targeted search was used.
Copilot CLI v1.0.92 release highlights
Full release: https://github.com/github/copilot-cli/releases/tag/v1.0.92
OpenAI Codex 0.159.3 → 0.160.1
Release timeline: rust-v0.160.1 published 2026-10-05T18:29:37Z. Latest npm version published 2026-10-05T18:33:51.980Z.
Release link: https://github.com/openai/codex/releases/tag/rust-v0.160.1
Codex rust-v0.160.1 changelog
Full release: https://github.com/openai/codex/releases/tag/rust-v0.160.1
Pi 1.0.0 → 1.0.4
Release timeline: latest npm version published 2026-10-05T21:51:59.920Z.
Playwright CLI 0.1.21 → 0.1.22
Release timeline: v0.1.22 published 2026-09-28T23:23:13Z; npm latest published 2026-09-28T23:24:31.286Z. This is outside the 3-day npm release-age cooldown enforced by the repository test.
Release link: https://github.com/microsoft/playwright-cli/releases/tag/v0.1.22
GitHub MCP Server v1.12.2 → v2.0.0
Release timeline: latest release published 2026-10-06T23:34:00Z.
Release link: https://github.com/github/github-mcp-server/releases/tag/v2.0.0
GitHub MCP Server v2.0.0 selected changes
Full release: https://github.com/github/github-mcp-server/releases/tag/v2.0.0
Docker image check
No Docker scanner image constants changed.
MCP Gateway and threat-detect were already current:
Next actions
References: