Skip to content

[ca] CLI version checker: update CLI/MCP defaults for 2026-10-09 #67125

Description

@github-actions

Overview

CLI Version Checker found stable upstream updates for agentic CLI/MCP defaults in github/gh-aw during run §37889306696.

Prepared local updates:

  • pkg/constants/version_constants.go
  • pkg/constants/version_constants_test.go
  • actions/setup/sh/install_copilot_cli.sh
  • .github/aw/compat.json
  • generated .github/workflows/*.lock.yml files were refreshed by make recompile as required, but should not be committed directly unless the repository policy for this update permits regenerated locks.

Version updates detected

Tool Current Latest stable Action
Claude Code 2.1.288 2.1.295 Updated DefaultClaudeCodeVersion
GitHub Copilot CLI 1.0.90 1.0.94 Updated DefaultCopilotVersion, setup fallback, compat max-agent
OpenAI Codex 0.159.3 0.162.0 Updated DefaultCodexVersion
Pi 1.0.0 1.1.0 Updated DefaultPiVersion
GitHub MCP Server v1.12.2 v2.0.2 Updated DefaultGitHubMCPServerVersion
MCP Gateway v0.4.30 v0.4.30 No change
Threat-detect v0.5.2 v0.5.2 No change
Playwright CLI no repo constant found 0.1.22 No tracked constant changed

Release analysis

Claude Code 2.1.288 → 2.1.295

  • Source: npm metadata for @anthropic-ai/claude-code
  • Release metadata: https://www.npmjs.com/package/``@anthropic-ai/claude-code``
  • Risk: Low/Medium. No public GitHub changelog was available; upgrade is based on the latest npm stable package metadata and CLI help compatibility.
  • Breaking changes: None identified from npm metadata or help output.
  • Features/Fixes/Security/Performance: Not publicly itemized.
  • CLI help comparison: no substantive --help changes vs cached 2.1.293 output.

GitHub Copilot CLI 1.0.90 → 1.0.94

  • Source: npm metadata for @github/copilot and GitHub release notes.
  • Release: https://github.com/github/copilot-cli/releases/tag/v1.0.94
  • Release date: 2026-10-08
  • Risk: Medium. The update touches MCP startup/discovery, managed settings, assisted permissions, and model selection.
  • Breaking changes: None called out in the release notes.
  • Features:
    • Adds Claude Haiku 5.5 to model selection and --model completions.
    • Shows update guidance when managed settings request a newer CLI version without blocking normal prompts.
  • Fixes:
    • copilot mcp add recovers cleanly after interrupted MCP config initialization.
    • MCP enable/disable works before server discovery without starting MCP servers.
    • Clicking a Sessions sidebar row reliably switches sessions during split-view reconciliation.
  • Security/Policy:
    • Assisted permissions send visible shell code to the permission judge instead of requiring unnecessary manual approval.
    • Startup bypass-permission flags suppressed by managed settings now produce a policy warning.
    • Managed policy can disable Assisted Permissions and keep sessions in Manual Approval mode.
  • README review: README still documents npm, Homebrew, WinGet and install-script installation, PAT auth, default model behavior, experimental mode, MCP support, and LSP configuration.
  • CLI help comparison: no substantive main/config help changes vs cached 1.0.93 output; copilot environment --help remains invalid.

OpenAI Codex 0.159.3 → 0.162.0

Pi 1.0.0 → 1.1.0

  • Source: npm metadata for @earendil-works/pi-coding-agent.
  • Package: https://www.npmjs.com/package/``@earendil-works/pi-coding-agent``
  • Risk: Low/Medium. No public release notes were available through the repository instructions; upgrade was based on npm metadata and cached help output.
  • Breaking changes: None identified.
  • CLI help comparison: 1.1.0 help is already cached from the previous run and remains the latest observed output.

GitHub MCP Server v1.12.2 → v2.0.2

Docker image checks

Image Current Latest release Digest status Action
ActionlintImage 1.7.12 1.7.12 unchanged sha256:b1934ee5f1c509618f2508e6eb47ee0d3520686341fec936f3b79331f9315667 No change
SyftImage v1.52.0 v1.54.1 current digest unchanged; latest release published 2026-10-06 15:35 UTC (<3 days at check time) Skipped by 3-day cooldown
GrypeImage v0.119.0 v0.120.1 current digest unchanged; latest release published 2026-10-06 20:46 UTC (<3 days at check time) Skipped by 3-day cooldown
GrantImage v0.6.8 v0.6.8 unchanged sha256:172463611795f43b77302cdfbd7b3f81295492a7330e0820cfe41c3674920237 No change
ZizmorImage 1.30.1 v1.30.1 unchanged sha256:a2eb396d886c053073405c7a980f2139ba2248ec172243cfa3841e57196e8101 No change
PoutineImage 1.1.6 v1.1.6 unchanged sha256:722a8e0999b583c1540fe2974e691032b2d9d21b9256a17965132b6bfd0081b0 No change
RunnerGuardImage 3.1.5 v3.1.5 unchanged sha256:2df426ef96d21f1622e05b21329f26bd263fc46110609cefb6afe43457613ac0 No change
YamllintImage latest release endpoint returned 404 latest digest unchanged sha256:5ab5eb7da0ed5e606b07c1723fc8b275e925189f70ac259b26b7329cb5f8f44d No change

GitHub MCP Server container digest for v2.0.2 was resolved as sha256:ffced0d76e77428532a2ced185516992d77fd146d69eec2f244e6237d1a97796, but the existing action-pins data still contains ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6 after recompile. Follow-up may be needed if action pin data should be updated for the new default server image.

Validation

  • make fmt: passed.
  • make recompile: passed in the foreground; 333/333 workflow files compiled with existing warnings.
  • make agent-report-progress: partially passed; build, sync checks, action shell lint, schema freshness, custom Go linters, and impacted Go tests for ./pkg/constants passed. The target failed because golangci-lint is not installed in this runner (make deps-dev would be required to install it).

Next actions

  1. Review the v2 GitHub MCP Server compatibility impact, especially typed output behavior for older MCP clients.
  2. Decide whether regenerated .lock.yml files should be committed for this constants update, noting the workflow instruction not to commit lock files directly.
  3. Install golangci-lint (or run in the standard dev image) and rerun make agent-report-progress.
  4. Revisit Syft and Grype after their latest releases pass the 3-day cooldown.

References:

Generated by 🔢 CLI Version Checker · pi · gpt55 · 314.6 AIC · ⌖ 18 AIC · ⊞ 11.1K · ◷

  • expires on Oct 10, 2026, 9:44 PM UTC-08:00

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    automationcookieIssue Monster Loves Cookies!dependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions