Skip to content

fix: update @anthropic-ai/claude-code to fix securities report#25

Merged
joesaby merged 2 commits intojoesaby:mainfrom
area44-labs:fix-securities-report
Jan 2, 2026
Merged

fix: update @anthropic-ai/claude-code to fix securities report#25
joesaby merged 2 commits intojoesaby:mainfrom
area44-labs:fix-securities-report

Conversation

@torn4dom4n
Copy link
Copy Markdown
Contributor

@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes. The earliest fixed version is 2.0.31.

screenshot_github com

@netlify
Copy link
Copy Markdown

netlify Bot commented Dec 17, 2025

Deploy Preview for starlight-mermaid-demo canceled.

Name Link
🔨 Latest commit d380e43
🔍 Latest deploy log https://app.netlify.com/projects/starlight-mermaid-demo/deploys/69567c3c6f545300088f9db2

@netlify
Copy link
Copy Markdown

netlify Bot commented Dec 17, 2025

Deploy Preview for astro-mermaid-demo canceled.

Name Link
🔨 Latest commit d380e43
🔍 Latest deploy log https://app.netlify.com/projects/astro-mermaid-demo/deploys/69567c3c6f545300088f9db0

@torn4dom4n torn4dom4n changed the title fix: update @anthropic-ai/claude-to fix securities report fix: update @anthropic-ai/claude-code to fix securities report Dec 17, 2025
Copy link
Copy Markdown

@cooperj cooperj left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @torn4dom4n and @joesaby, This PR looks promising to resolve many issues myself and others have noticed from running an npm audit.

This would resolve #26 fully and would work towards #23

Comment thread package.json
Comment thread .devcontainer/devcontainer.json Outdated
Removed installation of @anthropic-ai/claude-code from onCreateCommand.
@joesaby
Copy link
Copy Markdown
Owner

joesaby commented Jan 1, 2026

Thanks for the pr. have been away from my laptop for a week. Shall take a look at the pr tomorrow.

@joesaby
Copy link
Copy Markdown
Owner

joesaby commented Jan 2, 2026

Thanks for the PR. Much appreciated

@joesaby joesaby merged commit 08bbf09 into joesaby:main Jan 2, 2026
8 checks passed
@torn4dom4n torn4dom4n deleted the fix-securities-report branch January 2, 2026 09:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants