Skip to content

fix: replace deprecated :* with modern * wildcard in git permissions#929

Merged
ashwin-ant merged 1 commit intoanthropics:mainfrom
Dave-London:fix/deprecated-git-permission-syntax
Feb 11, 2026
Merged

fix: replace deprecated :* with modern * wildcard in git permissions#929
ashwin-ant merged 1 commit intoanthropics:mainfrom
Dave-London:fix/deprecated-git-permission-syntax

Conversation

@Dave-London
Copy link
Contributor

Summary

Replace deprecated Bash(git add:*) colon-prefixed wildcard syntax with the modern Bash(git add *) space-separated syntax in default git tool permissions. The old syntax causes SDK validation errors when triggering the action via @claude.

Closes #856

Changes

  • src/modes/tag/index.ts — 7 permission strings updated
  • src/create-prompt/index.ts — 7 permission strings updated
  • test/create-prompt.test.ts — test assertions updated to match

The base-action/test/parse-sdk-options.test.ts was intentionally left unchanged as it tests parsing of user-provided claude_args input (backwards compatibility).

Test plan

  • bun test test/create-prompt.test.ts — 40/40 pass
  • Full test suite — all pre-existing passes still pass (20 failures are pre-existing Windows symlink/path issues)
  • No new dependencies

🤖 Generated with Claude Code

Replace `Bash(git add:*)` syntax with `Bash(git add *)` in default
tool permissions for tag mode and create-prompt. The colon-prefixed
wildcard syntax is deprecated and causes SDK validation errors.

Closes anthropics#856

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@ashwin-ant ashwin-ant merged commit 1bb0e74 into anthropics:main Feb 11, 2026
7 of 36 checks passed
@Dave-London Dave-London deleted the fix/deprecated-git-permission-syntax branch February 11, 2026 06:01
@maxired
Copy link

maxired commented Feb 12, 2026

I have isssue since this was merge, I now have This command requires approval got git commit -m... while before it was working. Installed claude version is 2.1.31

@Dave-London
Copy link
Contributor Author

Hi @maxired, sorry to hear that. Could you clarify — are you seeing this when using the @claude GitHub Action, or when running Claude Code CLI locally?

This PR only modifies the default tool permissions within the GitHub Action, so it shouldn't affect local CLI behavior. If you're seeing this locally, the timing may be coincidental (possibly related to a CLI update).

If you're seeing this in the GitHub Action, could you share your workflow config and the action version you're pinned to? That would help narrow down whether the permission pattern change is the cause.

@maxired
Copy link

maxired commented Feb 12, 2026

@Dave-London thanks for your answer - this is when using claude code action on the github ci - we ar enot using custom prompt

I opened an issue #934 and was wondering wether this PR would fix it

edit: pr link was updated it was incorrect

@Dave-London
Copy link
Contributor Author

Thanks for digging into this @maxired. It looks like you've identified the root cause in #934 — the action isn't installing the correct Claude Code version when using the create prompt entrypoint, so the older version doesn't understand the updated wildcard syntax. That tracks with what you were seeing here.

@maxired
Copy link

maxired commented Feb 12, 2026

@Dave-London for the records it actually does seems to work when the commit message is single line

git commit -m "single line" works
git commit -m "first line\nsecond line" does not works

mergify bot added a commit to ArcadeData/arcadedb that referenced this pull request Feb 15, 2026
Bumps the github-actions group with 2 updates: [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) and [github/codeql-action](https://github.com/github/codeql-action).
Updates `anthropics/claude-code-action` from 1.0.46 to 1.0.51
Release notes

*Sourced from [anthropics/claude-code-action's releases](https://github.com/anthropics/claude-code-action/releases).*

> v1.0.51
> -------
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.51>
>
> v1.0.50
> -------
>
> What's Changed
> --------------
>
> * revert: undo PR checkout fork support and unique branch naming by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#937](https://redirect.github.com/anthropics/claude-code-action/pull/937)
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.50>
>
> v1.0.49
> -------
>
> What's Changed
> --------------
>
> * fix: replace deprecated :\* with modern \* wildcard in git permissions by [`@​Dave-London`](https://github.com/Dave-London) in [anthropics/claude-code-action#929](https://redirect.github.com/anthropics/claude-code-action/pull/929)
> * fix: skip CI MCP server installation when actions:read permission is missing by [`@​OctavianGuzu`](https://github.com/OctavianGuzu) in [anthropics/claude-code-action#933](https://redirect.github.com/anthropics/claude-code-action/pull/933)
> * Fix/PR checkout branch name conflicts by [`@​kirisame-wang`](https://github.com/kirisame-wang) in [anthropics/claude-code-action#931](https://redirect.github.com/anthropics/claude-code-action/pull/931)
>
> New Contributors
> ----------------
>
> * [`@​OctavianGuzu`](https://github.com/OctavianGuzu) made their first contribution in [anthropics/claude-code-action#933](https://redirect.github.com/anthropics/claude-code-action/pull/933)
> * [`@​kirisame-wang`](https://github.com/kirisame-wang) made their first contribution in [anthropics/claude-code-action#931](https://redirect.github.com/anthropics/claude-code-action/pull/931)
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.49>
>
> v1.0.48
> -------
>
> What's Changed
> --------------
>
> * Fix PR checkout to support fork PRs by [`@​Tsuesun`](https://github.com/Tsuesun) in [anthropics/claude-code-action#851](https://redirect.github.com/anthropics/claude-code-action/pull/851)
>
> New Contributors
> ----------------
>
> * [`@​Tsuesun`](https://github.com/Tsuesun) made their first contribution in [anthropics/claude-code-action#851](https://redirect.github.com/anthropics/claude-code-action/pull/851)
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.48>
>
> v1.0.47
> -------
>
> What's Changed
> --------------
>
> * Update claude-opus-4-5 to claude-opus-4-6 in workflow by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#909](https://redirect.github.com/anthropics/claude-code-action/pull/909)
> * fix: skip dev dependencies in CI install step by [`@​Dave-London`](https://github.com/Dave-London) in [anthropics/claude-code-action#919](https://redirect.github.com/anthropics/claude-code-action/pull/919)
>
> New Contributors
> ----------------
>
> * [`@​Dave-London`](https://github.com/Dave-London) made their first contribution in [anthropics/claude-code-action#919](https://redirect.github.com/anthropics/claude-code-action/pull/919)
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.47>


Commits

* [`ea36d6a`](anthropics/claude-code-action@ea36d6a) chore: bump Claude Code to 2.1.42 and Agent SDK to 0.2.42
* [`c22f7c3`](anthropics/claude-code-action@c22f7c3) revert: undo PR checkout fork support and unique branch naming ([#937](https://redirect.github.com/anthropics/claude-code-action/issues/937))
* [`f669191`](anthropics/claude-code-action@f669191) fix: use unique local branch names for PR checkout to avoid conflicts ([#931](https://redirect.github.com/anthropics/claude-code-action/issues/931))
* [`8c383c5`](anthropics/claude-code-action@8c383c5) fix: skip CI MCP server installation when actions:read permission is missing ...
* [`1bb0e74`](anthropics/claude-code-action@1bb0e74) fix: replace deprecated :\* with modern \* wildcard in git permissions ([#929](https://redirect.github.com/anthropics/claude-code-action/issues/929))
* [`23ed4cb`](anthropics/claude-code-action@23ed4cb) chore: bump Claude Code to 2.1.39 and Agent SDK to 0.2.39
* [`21e3fe0`](anthropics/claude-code-action@21e3fe0) Fix PR checkout to support fork PRs ([#851](https://redirect.github.com/anthropics/claude-code-action/issues/851))
* [`b433f16`](anthropics/claude-code-action@b433f16) chore: bump Claude Code to 2.1.38 and Agent SDK to 0.2.38
* [`7695f78`](anthropics/claude-code-action@7695f78) fix: skip dev dependencies in CI install step ([#919](https://redirect.github.com/anthropics/claude-code-action/issues/919))
* [`d5b01b6`](anthropics/claude-code-action@d5b01b6) Update claude-opus-4-5 to claude-opus-4-6 in workflow ([#909](https://redirect.github.com/anthropics/claude-code-action/issues/909))
* See full diff in [compare view](anthropics/claude-code-action@6c61301...ea36d6a)
  
Updates `github/codeql-action` from 4.32.2 to 4.32.3
Release notes

*Sourced from [github/codeql-action's releases](https://github.com/github/codeql-action/releases).*

> v4.32.3
> -------
>
> * Added experimental support for testing connections to [private package registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries). This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. [#3466](https://redirect.github.com/github/codeql-action/pull/3466)


Changelog

*Sourced from [github/codeql-action's changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md).*

> CodeQL Action Changelog
> =======================
>
> See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
>
> [UNRELEASED]
> ------------
>
> No user facing changes.
>
> 4.32.3 - 13 Feb 2026
> --------------------
>
> * Added experimental support for testing connections to [private package registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries). This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. [#3466](https://redirect.github.com/github/codeql-action/pull/3466)
>
> 4.32.2 - 05 Feb 2026
> --------------------
>
> * Update default CodeQL bundle version to [2.24.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.1). [#3460](https://redirect.github.com/github/codeql-action/pull/3460)
>
> 4.32.1 - 02 Feb 2026
> --------------------
>
> * A warning is now shown in Default Setup workflow logs if a [private package registry is configured](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) using a GitHub Personal Access Token (PAT), but no username is configured. [#3422](https://redirect.github.com/github/codeql-action/pull/3422)
> * Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. [#3421](https://redirect.github.com/github/codeql-action/pull/3421)
>
> 4.32.0 - 26 Jan 2026
> --------------------
>
> * Update default CodeQL bundle version to [2.24.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.0). [#3425](https://redirect.github.com/github/codeql-action/pull/3425)
>
> 4.31.11 - 23 Jan 2026
> ---------------------
>
> * When running a Default Setup workflow with [Actions debugging enabled](https://docs.github.com/en/actions/how-tos/monitor-workflows/enable-debug-logging), the CodeQL Action will now use more unique names when uploading logs from the Dependabot authentication proxy as workflow artifacts. This ensures that the artifact names do not clash between multiple jobs in a build matrix. [#3409](https://redirect.github.com/github/codeql-action/pull/3409)
> * Improved error handling throughout the CodeQL Action. [#3415](https://redirect.github.com/github/codeql-action/pull/3415)
> * Added experimental support for automatically excluding [generated files](https://docs.github.com/en/repositories/working-with-files/managing-files/customizing-how-changed-files-appear-on-github) from the analysis. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for some GitHub-managed analyses. [#3318](https://redirect.github.com/github/codeql-action/pull/3318)
> * The changelog extracts that are included with releases of the CodeQL Action are now shorter to avoid duplicated information from appearing in Dependabot PRs. [#3403](https://redirect.github.com/github/codeql-action/pull/3403)
>
> 4.31.10 - 12 Jan 2026
> ---------------------
>
> * Update default CodeQL bundle version to 2.23.9. [#3393](https://redirect.github.com/github/codeql-action/pull/3393)
>
> 4.31.9 - 16 Dec 2025
> --------------------
>
> No user facing changes.
>
> 4.31.8 - 11 Dec 2025
> --------------------
>
> * Update default CodeQL bundle version to 2.23.8. [#3354](https://redirect.github.com/github/codeql-action/pull/3354)
>
> 4.31.7 - 05 Dec 2025
> --------------------
>
> * Update default CodeQL bundle version to 2.23.7. [#3343](https://redirect.github.com/github/codeql-action/pull/3343)
>
> 4.31.6 - 01 Dec 2025
> --------------------

... (truncated)


Commits

* [`9e907b5`](github/codeql-action@9e907b5) Merge pull request [#3479](https://redirect.github.com/github/codeql-action/issues/3479) from github/update-v4.32.3-4bf6fa4e2
* [`1814c9f`](github/codeql-action@1814c9f) Update changelog for v4.32.3
* [`4bf6fa4`](github/codeql-action@4bf6fa4) Merge pull request [#3478](https://redirect.github.com/github/codeql-action/issues/3478) from github/mbg/changelog/add-connection-test-entry
* [`9658e23`](github/codeql-action@9658e23) Merge pull request [#3476](https://redirect.github.com/github/codeql-action/issues/3476) from github/henrymercer/retry-auth-errors
* [`be75dd9`](github/codeql-action@be75dd9) Add changelog entry for [#3466](https://redirect.github.com/github/codeql-action/issues/3466)
* [`05bca54`](github/codeql-action@05bca54) Apply suggestion from [`@​Copilot`](https://github.com/Copilot)
* [`2d6b98c`](github/codeql-action@2d6b98c) Merge pull request [#3475](https://redirect.github.com/github/codeql-action/issues/3475) from github/henrymercer/retry-auth-errors
* [`876cecb`](github/codeql-action@876cecb) Avoid requesting features in CCR
* [`43b46a1`](github/codeql-action@43b46a1) Retry API authentication errors since these can be transient
* [`8ad4b6e`](github/codeql-action@8ad4b6e) Merge pull request [#3472](https://redirect.github.com/github/codeql-action/issues/3472) from github/dependabot/github\_actions/dot-github/wor...
* Additional commits viewable in [compare view](github/codeql-action@45cbd0c...9e907b5)
  
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore  major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore  minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore  ` will remove the ignore condition of the specified dependency and ignore conditions
ashwin-ant added a commit that referenced this pull request Feb 15, 2026
ashwin-ant added a commit that referenced this pull request Feb 15, 2026
@niebloomj
Copy link

Is this only a fix for git? Do I need to still keep putting the : for other bash commands?

pleb pushed a commit to Kipp-Sandbox/kipp-claude-action that referenced this pull request Feb 25, 2026
pleb pushed a commit to Kipp-Sandbox/kipp-claude-action that referenced this pull request Feb 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: Default git permissions use deprecated :* syntax causing SDK errors

4 participants