Skip to content

fix(deps): update anthropics/claude-code-action action to v1.0.72#38

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/anthropics-claude-code-action-1.x
Open

fix(deps): update anthropics/claude-code-action action to v1.0.72#38
renovate[bot] wants to merge 1 commit intomainfrom
renovate/anthropics-claude-code-action-1.x

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jan 25, 2026

This PR contains the following updates:

Package Type Update Change
anthropics/claude-code-action action patch v1.0.33v1.0.72

Release Notes

anthropics/claude-code-action (anthropics/claude-code-action)

v1.0.72

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.72

v1.0.71

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.71

v1.0.70

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.70

v1.0.69

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.69

v1.0.68

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.68

v1.0.67

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.67

v1.0.66

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.66

v1.0.65

Compare Source

What's Changed

  • Change the default display_report option to false to restrict exposed data by @​ddworken in #​992

Full Changelog: anthropics/claude-code-action@v1...v1.0.65

v1.0.64

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.64

v1.0.63

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.63

v1.0.62

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.62

v1.0.61

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.61

v1.0.60

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.60

v1.0.59

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.59

v1.0.58

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.58

v1.0.57

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.57

v1.0.56

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.56

v1.0.55

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.55

v1.0.54

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.54

v1.0.53

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.53

v1.0.52

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.52

v1.0.51

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.51

v1.0.50

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.50

v1.0.49

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.49

v1.0.48

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.48

v1.0.47

Compare Source

What's Changed
New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.47

v1.0.46

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.46

v1.0.45

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.45

v1.0.44

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.44

v1.0.43

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.43

v1.0.42

Compare Source

What's Changed
New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.42

v1.0.41

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.41

v1.0.40

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.40

v1.0.39

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.39

v1.0.38

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.38

v1.0.37

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.37

v1.0.36

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.36

v1.0.35

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.35

v1.0.34

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.34


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions
Copy link
Contributor

github-actions bot commented Jan 25, 2026

Renovate PR Review Results

⚖️ Safety Assessment: ✅ Safe

🔍 Release Content Analysis

This PR updates anthropics/claude-code-action from v1.0.33 to v1.0.72, spanning 39 versions and 70 commits over approximately 2 months of development (January-March 2026). Key changes include:

Security Improvements:

  • v1.0.72: Hardened tag mode tool permissions against prompt injection (PR #1002)
  • v1.0.71: Added inline-comment confirmed parameter with probe-pattern safety net (PR #1048)
  • v1.0.71: Documentation warning that allowed_bots can expose action to external triggers (PR #1039)
  • v1.0.66: Restricted permission_denials count exposure in sanitized output (PR #993)
  • v1.0.65: Changed display_report default from true to false to restrict exposed data (PR #992)

Feature Additions:

  • v1.0.67: Improved gh.sh wrapper with stricter validation and better error messages (PR #996)
  • v1.0.62: Added gh.sh wrapper for gh CLI commands in issue triage workflows (PR #975)
  • v1.0.58: Added non-write users check workflow (PR #973)
  • v1.0.56: Wrapper script for label operations in issue triage (PR #968)
  • v1.0.53: Added display_report option to disable step summary (PR #952)

Bug Fixes & Reverts:

  • v1.0.52: Reverted to colon-based wildcard syntax for git permissions (PR #949)
  • v1.0.50: Reverted PR checkout fork support and unique branch naming (PR #937)
  • v1.0.49: Replaced deprecated :* with modern * wildcard in git permissions (PR #929)
  • v1.0.49: Skip CI MCP server installation when actions:read permission missing (PR #933)
  • v1.0.48/v1.0.49/v1.0.31: Multiple attempts to fix PR checkout for fork PRs
  • v1.0.47: Skip dev dependencies in CI install step (PR #919)
  • v1.0.45: Use original body from webhook payload for TOCTOU hardening (PR #904)
  • v1.0.42: Pass OpenTelemetry environment variables to Claude Code subprocess (PR #886)
  • v1.0.42: Pass GitHub token to setup-bun to avoid rate limits (PR #861)

Architectural Changes:

  • v1.0.44: Unified action into single composite step with run.ts entrypoint (PR #898)
  • v1.0.45: Simplified mode system by removing Mode interface and registry (PR #899)

No Breaking Changes Affecting This Codebase:

  • The display_report default change (v1.0.65) does NOT affect this action because it uses structured_output instead of relying on display_report
  • All changes are backward compatible for the usage pattern in this repository

🎯 Impact Scope Investigation

Usage Location Identification:

  • Primary usage: action.yml:109 - Uses anthropics/claude-code-action/base-action@cd77b50d2b0808657f8e6774085c8bf54484351c
  • The action references the base-action with pinned commit SHA: cd77b50d2b0808657f8e6774085c8bf54484351c (v1.0.72)

Codebase Analysis:

  • This repository uses the base-action as a dependency to execute Claude Code
  • The action provides its own prompt and schema configuration
  • Uses structured_output from base-action (action.yml:189), which remains compatible
  • Does NOT use display_report parameter, so the default change has no impact
  • Authentication via anthropic_api_key or claude_code_oauth_token remains unchanged
  • Tool permissions (--allowedTools) remain compatible
  • JSON schema output mechanism (--json-schema) remains unchanged

Dependency Impact:

  • No other dependencies affected
  • No configuration file changes required
  • Current workflow in .github/workflows/claude-renovate-review.yml remains fully compatible

Security Benefits:

  • Enhanced protection against prompt injection attacks
  • Better tool permission controls
  • Improved data exposure restrictions
  • Hardened webhook payload handling (TOCTOU protection)

💡 Recommended Actions

Immediate Actions:

  • Safe to merge immediately - No code changes required
  • ✅ Approve and merge this PR to benefit from security improvements

Post-Merge Validation:

  • Monitor the next Renovate PR review to confirm the action continues functioning correctly
  • Verify that structured output is properly extracted from the updated base-action
  • Check that the safety assessment and report generation work as expected

No Migration Required:

  • No code modifications needed
  • No configuration changes required
  • No workflow adjustments necessary
  • The action's usage pattern is fully compatible with all changes from v1.0.33 to v1.0.72

🔗 Reference Links

Generated by koki-develop/claude-renovate-review

@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from c19b46b to 5920814 Compare January 29, 2026 01:57
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.34 fix(deps): update anthropics/claude-code-action action to v1.0.35 Jan 29, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from 5920814 to abdb689 Compare January 29, 2026 06:08
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.35 fix(deps): update anthropics/claude-code-action action to v1.0.36 Jan 29, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from abdb689 to 363e62a Compare January 30, 2026 08:49
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.36 fix(deps): update anthropics/claude-code-action action to v1.0.37 Jan 30, 2026
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.37 fix(deps): update anthropics/claude-code-action action to v1.0.38 Jan 31, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from 363e62a to e2ac981 Compare January 31, 2026 04:38
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from e2ac981 to d838fa5 Compare January 31, 2026 21:13
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.38 fix(deps): update anthropics/claude-code-action action to v1.0.39 Jan 31, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from d838fa5 to 2dc923e Compare February 2, 2026 00:32
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.39 fix(deps): update anthropics/claude-code-action action to v1.0.40 Feb 2, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from 2dc923e to e069455 Compare February 3, 2026 00:58
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.40 fix(deps): update anthropics/claude-code-action action to v1.0.41 Feb 3, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from 39ee94f to 83e83d0 Compare February 27, 2026 05:35
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.59 fix(deps): update anthropics/claude-code-action action to v1.0.60 Feb 27, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from 83e83d0 to 43f030f Compare February 27, 2026 09:52
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.60 fix(deps): update anthropics/claude-code-action action to v1.0.61 Feb 27, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from 43f030f to b36344b Compare February 27, 2026 20:59
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from b36344b to bf6aa90 Compare February 28, 2026 06:01
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.61 fix(deps): update anthropics/claude-code-action action to v1.0.62 Feb 28, 2026
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.62 fix(deps): update anthropics/claude-code-action action to v1.0.63 Mar 1, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from bf6aa90 to 99fdc5a Compare March 1, 2026 01:32
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.63 fix(deps): update anthropics/claude-code-action action to v1.0.64 Mar 2, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from 99fdc5a to 92ac706 Compare March 2, 2026 10:13
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.64 fix(deps): update anthropics/claude-code-action action to v1.0.70 Mar 8, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from 92ac706 to d7bb3eb Compare March 8, 2026 11:14
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.70 fix(deps): update anthropics/claude-code-action action to v1.0.71 Mar 15, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from d7bb3eb to 999d724 Compare March 15, 2026 01:48
@renovate renovate bot changed the title fix(deps): update anthropics/claude-code-action action to v1.0.71 fix(deps): update anthropics/claude-code-action action to v1.0.72 Mar 16, 2026
@renovate renovate bot force-pushed the renovate/anthropics-claude-code-action-1.x branch from 999d724 to c5924e5 Compare March 16, 2026 04:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants