chore(deps): bump bundled agents to latest - #945
Conversation
Update bundled coding agents to their latest stable releases: - Claude Code 2.1.219 -> 2.1.220 (claude-agent-sdk 0.3.219 -> 0.3.220, lockstep) - OpenCode 1.18.4 -> 1.18.5 (sdk + cli) Cursor SDK (1.0.24), Codex (0.145.0) and Kimi (0.29.1) already current. Gates passed: bun install (lockstep verified 0.3.220 <-> claudeCodeVersion 2.1.220), typecheck, bun test (418 pass), cargo pipeline tests (scenarios/fixtures/streams all green). Claude-Session: https://claude.ai/code/session_01R2BguwSr4EeZeUXWYokSxs
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
Add OpenCode 1.18.7 (SDK + CLI lockstep, arm64+x64 SHA256) and Kimi 0.29.2 (four-platform SHA256) on top of the existing Claude 2.1.220 bump in this rolling automation PR. Claude-Session: https://claude.ai/code/session_01A5pmMN6R6tJVV6JJpiTZeB
Latest stable moved 1.18.7 -> 1.18.8 (SDK + CLI lockstep). Gates: typecheck, sidecar tests (418 pass), pipeline snapshots (119+1) all green. Claude-Session: https://claude.ai/code/session_014Txgp4czxAj13Cf6d9qKAV
Codex 0.145.0 -> 0.146.0, Cursor SDK 1.0.24 -> 1.0.26, OpenCode 1.18.8 -> 1.18.10 (SDK+CLI), Kimi 0.29.2 -> 0.31.0. Claude Code 2.1.220 / agent-sdk 0.3.220 already current. Claude-Session: https://claude.ai/code/session_01RzWH6K1fqayn8N2hpXL4M9
Latest stable Kimi release (npm `@moonshot-ai/kimi-code@latest` = 0.31.1). SHA256 for all four platform assets sourced from the release `.zip.sha256` sidecars. Other in-scope agents already at latest on this branch. Claude-Session: https://claude.ai/code/session_016DqQHMMpzbJot3SMqhEGBk
Advance the rolling vendor bump to the newest stable upstream since the last update: - @anthropic-ai/claude-code 2.1.220 -> 2.1.221 (+ SHA256 arm64/x64) - @anthropic-ai/claude-agent-sdk 0.3.220 -> 0.3.221 (lockstep, claudeCodeVersion 2.1.221) - @opencode-ai/sdk + opencode-ai 1.18.10 -> 1.18.12 (+ SHA256 arm64/x64) Codex 0.146.0, Cursor SDK 1.0.26, Kimi 0.31.1 already at latest. Claude-Session: https://claude.ai/code/session_01H8JFeY2NSVN4BkQoqi9RKE
Kimi 0.31.1 -> 0.32.0 (latest stable). SHA256 for all four platforms (darwin/win32 x arm64/x64) sourced from the release .zip.sha256 sidecars and verified by direct download + shasum. Claude-Session: https://claude.ai/code/session_01JbhKQPG7VXmeuNb2VSnLQz
…ode 1.18.14, kimi 0.34.0 Claude-Session: https://claude.ai/code/session_01Qdwg5qT653YSwyHMbz12Zq
All other in-scope vendors already current (codex 0.147.0, cursor 1.0.27, opencode 1.18.14, kimi 0.34.0). Claude-Session: https://claude.ai/code/session_01MG9L5MgQhvBvNtHmM2oKuP
All in-scope vendors already at latest stable; previous CI run was cancelled. Empty commit to re-run the pipeline to green. Claude-Session: https://claude.ai/code/session_01TGVD6FL12ixvZYJrSf5UYv
OpenCode SDK + CLI moved to 1.18.15 (latest stable) since the last PR revision. Adds OPENCODE_SHA256["1.18.15"] (arm64+x64) and regenerates the lockfile. All other in-scope bundled agents already at latest. Gates: bun install (frozen ok), typecheck (0), bun test (418 pass), cargo pipeline_scenarios/fixtures/streams (all green). Claude-Session: https://claude.ai/code/session_014PWhntNeqN8yor4Bq9vKdR
Claude Code + agent-sdk moved to 2.1.226 / 0.3.226 (latest stable) since the last PR revision. Adds CLAUDE_CODE_SHA256["2.1.226"] (arm64+x64) and regenerates the lockfile. Lockstep verified (agent-sdk 0.3.226 carries claudeCodeVersion 2.1.226). All other in-scope bundled agents already at latest (codex 0.147.0, cursor 1.0.27, opencode 1.18.15, kimi 0.34.0). Gates: bun install (frozen ok), typecheck (0), bun test (418 pass); cargo pipeline gate pending. Claude-Session: https://claude.ai/code/session_01JZ9iuzJ7v6ibJhrtbusRK5
Previous CI run for a9e36ec was cancelled by the concurrency group (no superseding run followed), leaving it stuck. Branch content is unchanged and at latest for all in-scope vendors (claude-code 2.1.226 / agent-sdk 0.3.226, codex 0.147.0, cursor 1.0.27, opencode 1.18.15, kimi 0.34.0); frozen lockfile verified. Empty commit to trigger a fresh, uninterrupted CI run. Claude-Session: https://claude.ai/code/session_015s643TnSZyAeNgBMxMBqUo
Latest stable opencode-ai + @opencode-ai/sdk moved 1.18.15 -> 1.18.16. Add OPENCODE_SHA256[1.18.16] (arm64+x64) and refresh the rolling changeset. Claude-Session: https://claude.ai/code/session_019oPaKxonDLDS4YzurPozRu
…8, kimi 0.35.0 Claude-Session: https://claude.ai/code/session_019svcpaH9rwWQeHFQPXjv12
Kimi is now behind latest stable (@moonshot-ai/kimi-code npm latest = 0.36.0). Update KIMI_VERSION and add the 0.36.0 SHA256 table (darwin + win32, arm64 + x64), verified against the exact release download URLs. Archive layout unchanged (single `kimi` binary at root). Claude-Session: https://claude.ai/code/session_01Ts5JysFHQeSbD4NH3rhzHh
…kimi 0.37.2 Advance the rolling bundled-agent sweep to the newest stable upstreams: claude-code/agent-sdk 2.1.233→2.1.235 (lockstep, claudeCodeVersion 2.1.235), codex 0.147.0→0.148.0, kimi 0.36.1→0.37.2. Cursor 1.0.28 and OpenCode 1.18.18 already at latest. SHA256 tables extended (arm64+x64 for claude/codex; darwin+ win32 × arm64+x64 for kimi). Gates: typecheck, bun test (418), cargo pipeline (122) all green. Claude-Session: https://claude.ai/code/session_01YAZSKUN55iDDyiCmNfZNCb
Previous CI run (473, 048197c) was cancelled by the concurrency group with no superseding run, leaving two required checks (Typecheck, Windows Rust Test) stuck in a cancelled state while every completed job passed (Biome, Clippy, Rust Test, Sidecar Test, Windows Sidecar Test, Windows Typecheck). Branch content is unchanged and at latest for all in-scope vendors (claude-code 2.1.235 / agent-sdk 0.3.235 lockstep, codex 0.148.0, cursor 1.0.28, opencode 1.18.18, kimi 0.37.2); frozen lockfile verified. Empty commit to trigger a fresh, uninterrupted CI run. Claude-Session: https://claude.ai/code/session_019gsrJ8TPYURZXDn8mvsX5p
…opencode 1.18.21, kimi 0.38.0 Claude-Session: https://claude.ai/code/session_01EzyCtLuzyFAsa3MjqVAsz2
CI's clippy toolchain (rustc 1.98) enabled chunks_exact_to_as_chunks, which fails -D warnings on pre-existing code shared with main. Apply the compiler-suggested as_chunks::<2>() rewrite; behavior is identical. Claude-Session: https://claude.ai/code/session_01EzyCtLuzyFAsa3MjqVAsz2
Daily bundled-agent check — 2026-08-22No new upstream versions today. Re-checked all in-scope vendors live; every one is already pinned to its latest stable release in this PR:
CI status (head One non-green check: I could not clear it automatically: re-running the job returns Needs you: either re-run the Generated by Claude Code |
Automated daily bundled-agent version sweep. Brings the in-scope bundled coding agents up to their latest stable upstream releases. This is the rolling automation PR — bumps accumulate here until merged.
Vendor bumps (vs
main)@anthropic-ai/claude-code@anthropic-ai/claude-agent-sdkclaudeCodeVersion: 2.1.239✓)@openai/codexlayoutVersion: 1unchanged@cursor/sdk@connectrpc/connect-noderesolves ✓; already latest@opencode-ai/sdkopencode-aiAll in-scope vendors are at their latest stable upstream release (re-checked live 2026-08-22: claude-code/agent-sdk
latest= 2.1.239 / 0.3.239, codex 0.149.0, cursor 1.0.28, opencode 1.18.21, Kimi via@moonshot-ai/kimi-codenpmlatest= 0.38.0).CI toolchain fix (unrelated to the bumps — flagged for visibility)
CI's Clippy runner advanced to rustc 1.98.0, which enables the
clippy::chunks_exact_to_as_chunkslint. Under-D warningsit now hard-fails on pre-existing code insrc/slack/desktop_scrape.rs:359(.chunks_exact(2)) — a file byte-identical tomainand untouched by this PR (last changed in #882). This lint fails onmaintoo under the same updated toolchain, so it is not caused by the vendor bumps. Rather than leave this rolling PR red indefinitely, I applied the exact compiler-suggested, behavior-identical rewrite (as_chunks::<2>().0.iter()) in commitb1d239e.as_chunksis stable since Rust 1.88; CI uses 1.98. You may prefer a dedicated fix onmain— happy to drop this commit if you land that separately.Files touched
sidecar/package.json— version pins (claude 2.1.239 / 0.3.239, codex 0.149.0, opencode 1.18.21)sidecar/scripts/vendor-platform.ts—CLAUDE_CODE_SHA256["2.1.239"],CODEX_SHA256["0.149.0"],OPENCODE_SHA256["1.18.21"](arm64+x64),KIMI_VERSION→ 0.38.0 +KIMI_SHA256["0.38.0"](4 platforms). Cursor is class-A (no SHA table).sidecar/bun.lock— regenerated.changeset/bump-bundled-agents.md— single rolling patch changesetsrc-tauri/src/slack/desktop_scrape.rs— clippyas_chunksfix (see CI toolchain fix above)Local verification gates (latest revision — claude 2.1.239 / codex 0.149.0 / opencode 1.18.21 / Kimi 0.38.0)
bun installclaudeCodeVersion2.1.239); cursor Node ≥22.13 floor met by bundled Node 24;@connectrpc/connect-nodepresent;--frozen-lockfilecleanbun run typecheckbun testcargo test --test pipeline_scenarios --test pipeline_fixtures --test pipeline_streamscargo clippy --libas_chunksfix compiles cleanly (verified locally on Linux; the exact failing lint is toolchain-1.98-only, but the rewrite is the compiler's own suggestion and behavior-identical)npm_vendor_sha.sh); Kimi 0.38.0 computed by downloading the exact release-zip URLs (arm64+x64 × darwin/win32)Breaking-change assessment
All vendor bumps are patch/minor increments.
typecheck(SDK export/type break detector) and the Rust pipeline snapshot tests (stdout event-shape contract) pass, so no Helmor-affecting breaking changes detected in the npm vendors. Codex stays within the 0.14x line (patch 0.148 → 0.149); layout descriptor expected to remainlayoutVersion: 1(verified on CI's cross-arch build). Kimi is a staged GitHub-release binary (not an npm dep), affecting only the staging/SHA path; its hard-enforced ACP protocol version (ACP_PROTOCOL_VERSION) has historically been stable across patch/minor releases and cannot be runtime-smoke-tested in this Linux sandbox (Kimi ships darwin/win32 binaries only). If it changed, the ACP handshake would throw at connect time rather than corrupt silently — worth a manualkimi acpsmoke-test before merge.