Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: anthropics/claude-code-action
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: c9ec2b02b40ac0444c6716e51d5e19ef2e0b8d00
Choose a base ref
...
head repository: anthropics/claude-code-action
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 1b8ee3b94104046d71fde52ec3557651ad8c0d71
Choose a head ref
  • 7 commits
  • 23 files changed
  • 7 contributors

Commits on Jan 7, 2026

  1. fix: resolve high vulnerability CVE-2025-66414 (#792)

    Automatically generated security fix
    
    Co-authored-by: orbisai0security <orbisai0security@users.noreply.github.com>
    orbisai0security and orbisai0security authored Jan 7, 2026
    Configuration menu
    Copy the full SHA
    c83d67a View commit details
    Browse the repository at this point in the history
  2. fix: use original title from webhook payload instead of fetched title (…

    …#793)
    
    * fix: use original title from webhook payload instead of fetched title
    
    - Add extractOriginalTitle() helper to extract title from webhook payload
    - Add originalTitle parameter to fetchGitHubData()
    - Update tag mode to pass original title from webhook context
    - Add tests for extractOriginalTitle and originalTitle parameter
    
    This ensures the title used in prompts is the one that existed when the
    trigger event occurred, rather than a potentially modified title fetched
    later via GraphQL.
    
    * fix: add title sanitization and explicit TOCTOU test
    
    - Apply sanitizeContent() to titles in formatContext() for defense-in-depth
    - Add explicit test documenting TOCTOU prevention for title handling
    ashwin-ant authored Jan 7, 2026
    Configuration menu
    Copy the full SHA
    964b835 View commit details
    Browse the repository at this point in the history
  3. feat: add path validation for commit_files MCP tool (#796)

    Add validatePathWithinRepo helper to ensure file paths resolve within the repository root directory. This hardens the commit_files tool by validating paths before file operations.
    
    Changes:
    - Add src/mcp/path-validation.ts with async path validation using realpath
    - Update commit_files to validate all paths before reading files
    - Prevent symlink-based path escapes by resolving real paths
    - Add comprehensive test coverage including symlink attack scenarios
    
    🤖 Generated with [Claude Code](https://claude.com/claude-code)
    
    Co-authored-by: Claude <noreply@anthropic.com>
    ddworken and claude authored Jan 7, 2026
    Configuration menu
    Copy the full SHA
    5da7ba5 View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    7a708f6 View commit details
    Browse the repository at this point in the history
  5. Configuration menu
    Copy the full SHA
    cefa600 View commit details
    Browse the repository at this point in the history

Commits on Jan 8, 2026

  1. feat: custom branch name templates (#571)

    * Add branch-name-template config option
    
    * Logging
    
    * Use branch name template
    
    * Add label to template variables
    
    * Add description template variable
    
    * More concise description for branch_name_template
    
    * Remove more granular time template variables
    
    * Only fetch first label
    
    * Add check for empty template-generated name
    
    * Clean up comments, docstrings
    
    * Merge createBranchTemplateVariables into generateBranchName
    
    * Still replace undefined values
    
    * Fall back to default on duplicate branch
    
    * Parameterize description wordcount
    
    * Remove some over-explanatory comments
    
    * NUM_DESCRIPTION_WORDS: 3 -> 5
    dylancdavis authored Jan 8, 2026
    Configuration menu
    Copy the full SHA
    c247cb1 View commit details
    Browse the repository at this point in the history
  2. fix: add missing import and update tests for branch template feature (#…

    …799)
    
    * fix: add missing import and update tests for branch template feature
    
    - Add missing `import { $ } from 'bun'` in branch.ts
    - Add missing `labels` property to pull-request-target.test.ts fixture
    - Update branch-template tests to expect 5-word descriptions
    
    * address review feedback: update comment and add truncation test
    ashwin-ant authored Jan 8, 2026
    Configuration menu
    Copy the full SHA
    1b8ee3b View commit details
    Browse the repository at this point in the history
Loading