Repository navigation
v2.34.0
·
1535 commits
to main
since this release
[2.34.0] — 2026-08-24
Security
- Provider
envmap keys are now name-filtered before export. The cloud "Inject provider
endpoint" step already validated eachproviders.<name>.envkey's shape; it now also
refuses the run (fail loud,::error::naming the offending key, before any$GITHUB_ENV
write) when a key's name is a credential (ANTHROPIC_API_KEY,ANTHROPIC_AUTH_TOKEN,
CLAUDE_CODE_OAUTH_TOKEN,AWS_ACCESS_KEY_ID,AWS_SECRET_ACCESS_KEY,AWS_SESSION_TOKEN,
AWS_BEARER_TOKEN_BEDROCK), a name that would shadow the job environment or its Actions
plumbing (PATH,GITHUB_TOKEN,GH_TOKEN,GITHUB_ENV,GITHUB_OUTPUT,GITHUB_PATH),
an interpreter or loader hook that can make every later job step load code you did not intend (BASH_ENV,ENV,
LD_PRELOAD,LD_LIBRARY_PATH,DYLD_INSERT_LIBRARIES,NODE_OPTIONS,PYTHONPATH), or
CLAUDE_CODE_SUBAGENT_MODEL(which overrides the model of every subagent and so flattens the
agent_overridesreview roster to one model). The match is case-insensitive. The config schema no longer suggests
CLAUDE_CODE_SUBAGENT_MODELas an example key. Action required on upgrade: a
providers.<name>.envmap naming any of the above — includingCLAUDE_CODE_SUBAGENT_MODEL,
which the schema recommended until this release — now fails the run until the key is removed;
useANTHROPIC_DEFAULT_HAIKU_MODELto map only the background model. (#1781)