AI Dev Pulse – 2026-09-06

At a glance

  • Artificial Analysis Index v4.2 keeps Claude Fable 5.1 first and GPT-6 Astra second after doubling private held-out weight to 40%.
  • Claude Code 2.1.260 adds a live /diff panel and fixes permission paths with parentheses that left read-only folders writable.
  • GitHub CLI's old Linux APT/RPM signing key expired September 5; new packages sign with the replacement key only.
  • GitHub is gradually reopening Copilot Business and Enterprise card/PayPal signups, with prepaid seat charges starting October 1.

September 6 is a quiet Sunday after Friday’s Astra distribution wave. The useful drops sit in evals, agent safety, and install plumbing rather than another flagship model launch. Sources are thinner than a launch morning, so this brief stays on verified hygiene and comparison work instead of padding a quiet weekend.

Treat today as a hygiene and comparison day. Re-score Fable versus Astra on your own tasks under the new Index rules, patch Claude Code if you pin permission rules with parentheses, and confirm Linux gh keyrings before the next CLI release breaks apt update.

Top Stories

Artificial Analysis Intelligence Index v4.2 keeps Fable ahead of Astra
Practical dev impact: Do not treat OpenAI’s launch-day “most intelligent” framing as settled for team defaults; under Index v4.2, Claude Fable 5.1 still leads overall and Astra sits second with a 4-point gain over GPT-5.6 Sol. Artificial Analysis published the interim update on September 4, doubling private held-out weight from 20% to 40%, adding AA-Briefcase (agentic knowledge work) and Surge’s GDP.pdf (4,592 pages across 100 PDFs), and retiring saturated GPQA Diamond. Astra leads GDP.pdf at 33.2% all-pass versus Fable 5.1 at 26.2%, and AA says Astra dominates the output-token frontier near the intelligence curve. Cost-per-task Pareto is shared by Anthropic, OpenAI, Meta, and Z.AI. Use that split: PDF-heavy and token-tight jobs lean Astra; multi-week knowledge-work agents still need a Fable bake-off on your harness.

Claude Code 2.1.260 ships live /diff and a permission-path security fix
Practical dev impact: Upgrade before you trust path-scoped deny rules that include parentheses. Release notes for 2.1.260 (September 3) add a fullscreen /diff panel that shows uncommitted changes beside the conversation as Claude edits, and they fix Edit/Write/Read rules whose paths contain parentheses being dropped as invalid or ignored by the Bash sandbox, which left “read-only” folders writable. The same build reverts the 2.1.259 change that applied Read() deny rules to Bash arguments (that had blocked npm run build under Read(.//build/) and prompted on cd ... && grep even in auto mode). Fable 5.1 cache coverage now includes context attached after tool results, so tool-heavy turns stop burning uncached input. Pin @anthropic-ai/claude-code@2.1.260 if you enforce parenthetical paths or deny-on-build patterns.

GitHub CLI Linux PGP signing key expired September 5
Practical dev impact: If you install gh from the official APT or RPM repos, verify the archive keyring trusts the replacement key before the next CLI package lands, or apt update / dnf will fail signature checks. GitHub’s September 3 changelog says the prior key expired September 5, 2026, and that beginning with the first release after that date, APT/RPM metadata and new RPMs sign with the replacement key only. The dual-key keyring has been published since April 8 at https://cli.github.com/packages/githubcli-archive-keyring.gpg. Expected fingerprints: 2C6106201985B60E6C7AC87323F3D4EA75716059 and 7F38BBB59D064DBCB3D84D725612B36462313325. Unaffected paths: Windows/macOS, Homebrew, Conda, source builds, and direct .deb or archive binaries from GitHub Releases. Image builders and fleet install scripts that pinned the old keyring need a refresh today.

Copilot Business/Enterprise card and PayPal signups reopen, with October billing and model cuts
Practical dev impact: Orgs that were blocked on card/PayPal Copilot Business or Enterprise signups can try again over the next couple of weeks, but plan for prepaid seats and October 1 upfront charges before you promise access dates. GitHub’s September 3 note says new seat assignments require payment before users get Copilot, existing card/PayPal customers see upfront seat charges from October 1, 2026, and overage may need extra payment to keep using Copilot. Pricing and seat prorations stay the same. Pair that calendar with the same-day deprecation notice: on October 2, Copilot retires Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7 across chat, edits, ask/agent, and completions. Suggested replacements are Gemini 3.8 Flash, Kimi K3, and Claude Opus 5. Admins should enable those alternatives in model policy before CI or defaults still pin the retiring ids.

Practical Impact Analysis

The through-line today is trust in measurements, permissions, and package trust roots, not another model launch. Index v4.2 is Artificial Analysis answering skepticism after Astra’s launch scores: more private weight, AA-Briefcase, GDP.pdf, and GPQA Diamond out. Fable 5.1 still leads the headline Index; Astra wins the long-PDF all-pass rate and the output-token frontier. For an eng manager that means keep dual evals. Do not flip the whole org to Astra because a press release said “most intelligent,” and do not ignore Astra on document-heavy agents where 33.2% versus 26.2% on GDP.pdf is a real gap.

Claude Code 2.1.260 is the agent-side counterpart: a visible /diff for review, plus a security fix for parenthetical paths that silently failed open. If your CLAUDE.md or managed settings use paths like src/(legacy)/**, you may have been trusting a deny that never compiled. The 2.1.259 Read-on-Bash revert also matters for teams that deny build directories yet still need npm run build.

On the install plane, Sunday is late for the gh key expiry that hit September 5. Fleet images and CI runners that still ship only the old fingerprint will break on the next CLI package. Copilot’s signup reopen is good news for blocked buyers, but October 1 prepaid seats and October 2 model retirements land in the same planning window as Astra enablement from Friday. Write down which Copilot model ids your agents pin, which seats are card-billed, and which Linux hosts still need the dual-key keyring.

If you only do three things this morning: verify the gh keyring fingerprints on every Linux image that uses the official APT/RPM repo, upgrade Claude Code to 2.1.260 where permission paths include parentheses, and schedule a Fable-versus-Astra bake-off under Index v4.2-style tasks (one PDF corpus job, one multi-file agent job) before you change the team default.

Tutorial

Verify the GitHub CLI Linux keyring fingerprints, then pin Claude Code 2.1.260. Run this on any Linux host that installs gh from the official APT/RPM repositories. Expect both fingerprints below; then install the Claude Code release that carries /diff and the parentheses permission fix. Do not paste placeholder keys.

  1. Download the published dual-key keyring and print fingerprints.
  2. Confirm both expected fingerprints are present.
  3. If either check fails, refresh the keyring from cli/cli install docs before apt/dnf update.
  4. Pin @anthropic-ai/claude-code@2.1.260, confirm the version, then open a repo with a parenthetical path in a deny rule and toggle /diff.
bash
Tutorial

EXPECTED_OLD=2C6106201985B60E6C7AC87323F3D4EA75716059
EXPECTED_NEW=7F38BBB59D064DBCB3D84D725612B36462313325

tmp="$(mktemp)"
curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg -o "$tmp"
fingerprints="$(gpg --show-keys --with-colons "$tmp" | awk -F: '/^fpr:/ {print $10}')"
echo "$fingerprints"
echo "$fingerprints" | grep -qx "$EXPECTED_OLD" && echo "OK: old key $EXPECTED_OLD"
echo "$fingerprints" | grep -qx "$EXPECTED_NEW" && echo "OK: replacement key $EXPECTED_NEW"
# If either check fails, re-run the install steps in cli/cli docs/install_linux.md before apt/dnf update.
rm -f "$tmp"

npm i -g @anthropic-ai/claude-code@2.1.260
claude --version
▸ Show full code (14 lines)
EXPECTED_OLD=2C6106201985B60E6C7AC87323F3D4EA75716059
EXPECTED_NEW=7F38BBB59D064DBCB3D84D725612B36462313325

tmp="$(mktemp)"
curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg -o "$tmp"
fingerprints="$(gpg --show-keys --with-colons "$tmp" | awk -F: '/^fpr:/ {print $10}')"
echo "$fingerprints"
echo "$fingerprints" | grep -qx "$EXPECTED_OLD" && echo "OK: old key $EXPECTED_OLD"
echo "$fingerprints" | grep -qx "$EXPECTED_NEW" && echo "OK: replacement key $EXPECTED_NEW"
# If either check fails, re-run the install steps in cli/cli docs/install_linux.md before apt/dnf update.
rm -f "$tmp"

npm i -g @anthropic-ai/claude-code@2.1.260
claude --version

Recommended AI prompt

Copy this paragraph into ChatGPT, Claude, Gemini, Grok, or whatever you use.

You are my staff engineer for AI tooling on 2026-09-06 (quiet Sunday after Astra distribution). Artificial Analysis Index v4.2 keeps Claude Fable 5.1 first and GPT-6 Astra second, with Astra stronger on GDP.pdf and the output-token frontier. Claude Code 2.1.260 adds /diff and fixes parenthetical permission paths that failed open. GitHub CLI’s Linux APT/RPM signing key expired Sep 5 (dual-key keyring required). Copilot Business/Enterprise card/PayPal signups are reopening with Oct 1 prepaid seats and Oct 2 model retirements. Ask which harnesses we use and whether Linux hosts install gh from official APT/RPM. Then produce (1) a one-page Fable-versus-Astra eval matrix, (2) a Claude Code 2.1.260 upgrade checklist for parenthetical path rules, and (3) a 20-minute Linux fleet keyring checklist plus a Copilot Oct 1/Oct 2 calendar. Keep it concrete and copy-paste ready.

Leave a Comment