Releases Index

Coding Agents

AI pair programmers and autonomous coding agents — IDE-integrated assistants and cloud agents that read, edit, and ship code.

This week's digestSep 28 – Oct 4, 2026

Strong models land across the coding agents

OpenAI's GPT-6.1 Sol became the default engine for Codex, Claude Sonnet 5.5 arrived with a 1M context window, and Devin pushed deeper into Jira and cross-device workflows — while a heavy week of fixes hardened every agent's terminal and sandbox.

Read the digest16 releases covered
Week of Sep 2816 releases
DigestStrong models land across the coding agentsRead →
SatOct 3, 20261 release
Anthropic
Daily summary

Claude Code hardens sandbox rule enforcement

Claude Code closed sandbox deny-rule bypasses that could let approved mods or environment-variable prefixes override Bash and Read restrictions, and fixed terminal freezes on malformed code blocks.

  • Deny and ask rules on nested parts of compound shell commands now hold even when a user-installed mod approves the command, and Bash deny/ask rules are no longer skipped under sandbox auto-allow when an env-var prefix precedes the command
  • Read deny rules now apply to files @-mentioned, changed, or opened through the IDE via a symlink
  • Terminal freezes on short code blocks with many unclosed script tags or deeply nested substitutions are fixed
  • Claude Code reverted the auth status change behind more frequent sign-outs in the prior release
Claude Code

Sandbox deny-rule bypasses closed; terminal freezes fixed

v2.1.289

Several fixes harden sandbox rule enforcement: deny or ask rules on nested parts of compound shell commands no longer get overridden by a user-installed mod's approval, and Bash deny/ask rules are no longer skipped under sandbox auto-allow when an environment variable prefix or bare variable assignment precedes the command. Also fixed terminal freezes on short code blocks with many unclosed script tags or nested substitutions, and reverted the 2.1.288 claude auth status change that may have made sign-outs more frequent.

Details
FriOct 2, 20262 releases
CognitionAnthropic
Daily summary

Claude Code closes a dangerous rm bypass as Devin lands in Jira

Claude Code stopped a dangerous rm from running unprompted in bypassPermissions mode and now re-prompts for OAuth scope when an MCP server requests more during a tool call, while Devin became a native Jira agent and stopped losing messages dropped mid-connection.

  • Claude Code no longer runs a dangerous rm, such as one on / or the home directory, inside bash -c or sh -c without a prompt in bypassPermissions mode or under a shell allow rule.
  • Claude Code prompts to re-authenticate when an MCP server asks for additional OAuth scope mid-tool-call, and recovers a draft cleared with Ctrl+C by pressing Up on the empty prompt.
  • Devin is now a native agent inside Jira, starting sessions when a work item is assigned or mentioned, with automations able to run a preflight script after each trigger.
  • Devin now saves messages sent right before a connection drop instead of losing them, and routes its own PR review findings back into the running session for auto-fix before posting comments.
Devin

Devin lands in Jira; messages survive dropped connections

Devin is now available as a native agent inside Jira, starting sessions when a work item is assigned or mentioned, and automations can run a preflight script after each trigger before the agent starts. Messages sent right before a connection drop are now saved by the server instead of being lost, and Devin Review findings on PRs opened by a running session go to that session for auto-fix before being posted as review comments.

Details
Claude Code

Dangerous rm no longer bypasses prompts; MCP OAuth re-auth prompted

v2.1.288

Fixed a dangerous rm (such as one on / or the home directory) inside a bash -c or sh -c script running without a prompt in bypassPermissions mode or under a shell allow rule, and added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call. Also added draft recovery after Ctrl+C via Up on the empty prompt, and fixed resume dropping context restored by compaction or cutting transcripts short.

Details
ThuOct 1, 20261 release
Anthropic
Daily summary

Claude Code opens plugins to deeper behavior with Claude Mods

Claude Code introduced Claude Mods, letting plugins alter deeper behavior, alongside a built-in "You should know" side agent that flags things you or Claude might miss.

  • Claude Code's new Claude Mods system lets plugins modify deeper agent behavior beyond the existing plugin surface
  • The built-in "You should know" mod runs a side agent that flags things you or Claude might overlook, enabled via /plugin enable for first-party sessions with telemetry on
  • MCP servers can now send URL prompts under the 2025-11-25 protocol, and fixes address Remote Control reconnects, repeated model fallback in claude -p sessions, and MCP connectors double-running calls
  • The agents view gained an n: filter matching session names and tasks, with matches surfaced in collapsed sections and Enter jumping to the first hit
Claude Code

Claude Mods plugins ship; MCP URL prompts may break servers

v2.1.287

Claude Mods let plugins modify deeper behavior, with a built-in mod "You should know" where a side agent flags things you or Claude might miss. Added URL prompts from MCP servers on the 2025-11-25 protocol, plus fixes for Remote Control reconnects, repeated model fallback in claude -p sessions, and MCP connectors double-running calls.

Details
WedSep 30, 20262 releases
OpenAIAnthropic
Daily summary

Claude Code fixes session-resume data loss and secret leaks

Claude Code patched two serious flaws — sessions losing all turns after parallel tool calls when a prior session crashed, and several redaction gaps that could expose credentials in MCP errors, logs, and URLs — alongside smaller permission-prompt and fullscreen list improvements.

  • Claude Code now preserves all turns when resuming or continuing a session that previously crashed or was killed mid-way through parallel tool calls, which had silently discarded the conversation history.
  • Claude Code closed secret-redaction gaps where MCP error messages, percent-encoded Bearer tokens, redacted logs, and URL passwords could leak credential values.
  • Claude Code stops spawning a separate login browser per process and IDE extension when gcpAuthRefresh or awsAuthRefresh credentials expire, and fixes API 400 errors after a tool returns a non-text value.
  • Permission prompts now show a "2 of 5" counter when requests stack up, and fullscreen lists gained clickable "N more" rows with hover and pressed states.
Codex

Terminal UI keeps provider settings; Windows sandbox fixed

v0.160.0

The terminal UI now preserves server provider, reasoning-summary, and verbosity settings and shows correct sessions in resume and fork history, and queued messages resume after reconnection without duplicate sends. Also added opt-in Guardian review context retrieval and a keyboard-accessible "Show more" action for browsing older tasks.

Details
Claude Code

Resume no longer drops turns; credential leaks in logs fixed

v2.1.286

Fixed claude --resume and --continue sometimes losing every turn after a batch of parallel tool calls when the earlier session crashed or was killed, and closed several secret-redaction gaps where MCP error messages, percent-encoded Bearer tokens, redacted logs, and URL passwords could expose credential values. Also fixed repeated login browser windows when gcpAuthRefresh or awsAuthRefresh credentials expire, API 400 errors after a tool returned a non-text value, and stale Remote Control sessions, plus permission-prompt counter and fullscreen list improvements.

Details
TueSep 29, 20263 releases
xAIOpenAIAnthropic
Daily summary

Claude Code adds desktop handoff and provider allowlists

Claude Code shipped a --desktop flag for opening the desktop app on a directory or resumed session, an allowedProviders managed setting restricting which API providers a machine may use, plus fixes for late cloud-session replies and an Artifact allow rule that permitted publishes outside working directories.

  • Claude Code's claude --desktop opens the Claude desktop app on the current directory or a resumed session, and a new allowedProviders managed setting lets admins limit which API providers a machine may use.
  • WebFetch can be turned off per machine via the CLAUDE_CODE_DISABLE_WEB_FETCH environment variable.
  • Plugin setup gained claude plugin configure to inspect and set a plugin's options, and bundled .mcpb MCP server settings can now be passed at install time so it starts without a Configure visit.
Grok Build

Permission rules apply under symlinks; video cards no longer stall

v1.0.46

Permission rules with relative paths now apply when the working directory contains symlinks, and video cards no longer get stuck extracting posters without ffmpeg. Also faster session startup when loading skills from large directories, plus fixes to MCP server source reporting, client rule preservation on system prompt rebuilds, and slow list_dir subtree counts on network filesystems.

Details
Claude Code

Desktop app launching; allowedProviders setting added

v2.1.285

Added claude --desktop to open the Claude desktop app on the current directory or a resumed session, plus a CLAUDE_CODE_DISABLE_WEB_FETCH variable and an allowedProviders managed setting that limits which API providers a machine may use. Fixed a regression causing cloud-session first replies to arrive late, an Artifact allow rule permitting publishes outside working directories, and a rare auth failure when two sessions recover a login refresh lock left by a crashed process.

Details
MonSep 28, 20267 releases
xAIOpenAIAnthropicCognition
Daily summary

Claude Code ships Sonnet 5.5 with 1M context as default

Claude Code made Claude Sonnet 5.5 its default model with 1M context at $2/$10 per Mtok and hardened stream and MCP failure handling, while Devin synced view preferences across devices and added keyboard session navigation.

  • Claude Code now defaults to Claude Sonnet 5.5 with 1M context and $2/$10 per Mtok pricing ($0.20/Mtok cache reads).
  • Claude Code retries damaged response streams or reports them as interrupted instead of surfacing raw JSON parse errors or writing "undefined" into answers.
  • Claude Code waits up to 10 seconds for a still-connecting MCP server in resumed sessions rather than failing with "No such tool available".
  • Devin syncs view preferences — search mode, changed-files tree layout, sidebar filters, and wiki view choices — across browsers and devices, and adds Option+J/Option+K session navigation.
  • Devin's sidebar status grouping now separates Working, Ready, Blocked, and Inactive sessions, with Bitbucket Data Center and Azure DevOps pipeline log support added.
Grok Build

Custom agents selectable via spawn_subagent; MCP token files re-read per request

v1.0.45

Custom agents from plugins or config can now be chosen directly with spawn_subagent, and MCP servers can use a token file that is re-read on every request so rotating credentials stay fresh. Also added colored notice banners above the prompt for selected models and a "Waiting for N subagents…" status when the parent turn is blocked.

Details

Codex

4 updates

Suppressed console windows flashing on Windows when Codex launches background processes and sandboxed commands.

Details

GPT-6.1 Sol is now the default model in the bundled catalog, and the Amazon Bedrock Mantle and Runtime catalogs add it via a backport.

Details

GPT-6.1 Sol is available via gpt-6.1-sol, offering near-Astra performance for complex, long-running work across code, apps, and documents at lower cost than Astra. Availability depends on plan, client, and workspace settings.

Details

Automatic follow-up prompt suggestions and the tui.prompt_suggestions setting were removed, and the bundled plugin-creator skill is gone. Opt-in instant_interrupt lets new input steer Codex during model responses or long-running code-mode calls, with fixes for Windows console windows, transcript copy formatting, and macOS TLS in network-enabled sandboxes.

Details
Claude Code

Sonnet 5.5 default; malformed streams no longer write "undefined"

v2.1.284

Claude Sonnet 5.5 (claude-sonnet-5-5) is now the default Sonnet model on the Anthropic API, with 1M context and $2/$10 per Mtok pricing. Damaged response streams are now retried or reported as interrupted instead of surfacing raw JSON parse errors or writing "undefined" into an answer, and MCP tool calls in resumed sessions wait up to 10 seconds for a still-connecting server instead of failing with "No such tool available".

Details
Devin

View prefs sync across devices; child sessions inherit parent context

View preferences — search mode, changed-files tree layout, sidebar Review/Ask filters, and wiki language/view choices — now sync across browsers and devices instead of staying on one machine. Also added Option+J/Option+K session navigation, interactive HTML reports, child sessions that carry a summary of their parent, and Bitbucket Data Center and Azure DevOps pipeline log support.

Details
Week of Sep 214 releases
SunSep 27, 20262 releases
xAIOpenAI
Daily summary

Codex CLI hardens approvals for elevated commands

Codex CLI now requires terminal input approval by default for commands running with elevated permissions, while gaining MCP OAuth client secrets, exec-server bearer-token auth, and TUI clipboard improvements.

  • Codex CLI enables terminal input approval by default for commands running with elevated permissions, and runtime-only grants no longer trigger extra reviews
  • Codex CLI can connect to MCP servers requiring pre-registered OAuth client secrets, configurable via codex mcp add
  • Codex CLI secures direct exec-server WebSocket connections with bearer tokens and adds copy-on-select and right-click paste in the fullscreen TUI
  • Codex CLI fixed sandbox failures on Windows and Linux
Grok Build

Context window picker for sessions; Windows paste crash fixed

v1.0.44

A new /context-window slash command lets you pick a context window size for the current session when the model offers choices, and /model selection now offers context window choices before effort level. Pasting on Windows no longer crashes from overlapping clipboard operations, and parallel tool calls that edit the same file now run in sequence.

Details
Codex

Elevated commands now require terminal input approval by default

v0.158.0

Terminal input approval is now enabled by default for commands running with elevated permissions, and runtime-only grants no longer trigger unnecessary reviews. Also added MCP server support for pre-registered OAuth client secrets, bearer-token auth for exec-server WebSockets, copy-on-select and right-click paste in the fullscreen TUI, and fixes for Windows and Linux sandbox failures.

Details
SatSep 26, 20261 release
xAI
FriSep 25, 20261 release
xAI
Daily summary

Claude Code adds model governance and a prompt-audit command

Claude Code shipped managed settings that let admins pin allowed model versions and deny specific models outright, alongside a /doctor prompt audit for stale CLAUDE.md and skill files, plus fixes for SDK sessions dropping deferred tool calls and a PowerShell escape that could delete drive roots.

  • Claude Code's new availableModelsMatch "exact" mode and deniedModels managed settings give admins version-level control over which Claude models developers can use
  • A new /doctor prompt-audit command flags CLAUDE.md, skills, agents, and commands written for older models
  • Claude Code fixed SDK sessions that lost deferred tool calls or held approvals, stateless MCP servers unusable for a session after a brief 404, and installed_plugins.json being rewritten with lost records
  • The Windows PowerShell tool no longer permits cmd /c rd against drive roots or the home folder
  • LLM gateways can now group requests by prompt via opt-in x-claude-code-prompt-id headers, and tool output can be attached to OpenTelemetry spans
Grok Build

grok worktree create added; plugin hooks run without reload

v1.0.42

New grok worktree create command creates a managed worktree without launching an interactive session, and plugin hooks now run on a fresh session without an explicit reload. Fixed bracketed pastes attaching leftover images, grok -p not exiting cleanly on interrupt, inline images appearing blank after repaint, and Ctrl+C twice while writing a plan comment getting stuck.

Details