Claude Code Tightens Repository Trust While GitHub Pre-Approves Dynamic Workflows

At a glance

  • Claude Code's Monday evening build stops a repository's settings files from turning on Claude in Chrome or setting the attachments switch, and makes more commands that only look read-only ask before they run.
  • A follow-up Claude Code patch a few hours later fixes a regression that could drop permission prompt answers in cloud sessions, so machines on the faster update channel should take the patch rather than the build before it.
  • The newest GitHub Agentic Workflows pre-release turns dynamic workflows on by default for the Copilot engine, pre-approves their runs, and adds one artifact retention setting per repository.
  • The Copilot CLI build we called a pilot on Monday is now the default npm install, so sandboxed shells on ordinary installs no longer see an ambient GITHUB_TOKEN unless it is configured.

Claude Code shipped two builds on Monday evening ET, and the first moves a trust line for anyone who clones other people’s repositories. GitHub moved the other way, since the newest agentic-workflows pre-release pre-approves dynamic workflow runs by default, and Copilot CLI promoted the build we had called a pilot. Treat today as the day to move latest machines to Claude Code v2.1.291 and skip v2.1.290, tell anyone who relied on a project file for Claude in Chrome to use /chrome instead, and opt gh-aw workflows that do not need dynamic workflows out before you compile on the v0.91 pre-release.

Top Stories

1. Claude Code v2.1.290 stops repo settings from switching on Chrome, and v2.1.291 fixes its cloud regression

Anthropic published v2.1.290 on GitHub at 7:33 PM ET on Monday 5 Oct and v2.1.291 at 11:55 PM ET the same night. As of about 5:55 AM ET Tuesday, npm latest and next and the native installer’s latest pointer all read v2.1.291, while stable is still v2.1.285. Several v2.1.290 changes narrow what a repository can do to your session. A project’s settings files can no longer turn on Claude in Chrome, so use --chrome, /chrome or your user settings instead. A repository’s .claude/settings.json or .claude/settings.local.json can also no longer set CLAUDE_CODE_DISABLE_ATTACHMENTS, the variable that sends @ file mentions as plain text, although shell, user and managed settings still can.

The Bash checks move in the same direction. Read-only commands such as rg or git grep whose arguments the shell would still expand as wildcards now prompt instead of being auto-approved, and so do certain commands whose variable names zsh reads differently from bash, pyright, and more forms of ps. Some permission rules and safety checks now apply to a tool call after a PreToolUse hook rewrites its input, and Read deny rules now cover image paths pasted or dragged into the prompt. Then v2.1.291 fixes a v2.1.290 regression in which cloud sessions could drop answers to permission prompts, along with an older regression that could lose the last messages on quit. Sunday’s deny-rule changes are background here rather than news, and they are covered in “Claude Code 2.1.289 Closes Deny Rule Gaps Stable Channel Still Lacks”.

Practical dev impact: Expect a few more prompts from commands that used to run silently, because those were auto-approvals the shell could widen, so answer them rather than writing a broad allow rule. If your team switched on Claude in Chrome through a committed project file, it stays off after the update until each person turns it on with /chrome, and anyone on latest should land on v2.1.291 rather than stop at v2.1.290. Both builds are on the latest channel only, and npm stable is still v2.1.285, so stable machines get none of this until Anthropic moves that pointer. On those machines, leave the channel where your policy puts it and review committed .claude settings by hand for Chrome and the attachments variable.

2. The gh-aw v0.91 pre-release turns dynamic workflows on by default for the Copilot engine

Monday’s brief, “Copilot Dynamic Workflows Split App and CLI as gh-aw v0.90.3 Fails Closed”, covered dynamic workflows in Copilot itself. What is new is that the GitHub Agentic Workflows pre-release now turns them on by default for its Copilot engine, and engine.dynamic-workflows: false is the opt-out. v0.91.0 was published as a pre-release at 7:03 PM ET on Monday and v0.91.1 followed at 12:29 AM ET Tuesday, while the latest non-pre-release is still v0.89.21. Per the engine docs, Copilot CLI dynamic workflows are now enabled by default in gh-aw, which turns on the CLI’s EXTENSIONS feature flag, loads project extensions in prompt mode and pre-approves workflow runs. For the Claude engine, gh-aw pre-approves the Workflow tool by default. The docs say the agents a workflow starts stay under the configured tool permissions and sandbox, and that gh-aw restores the engine’s configuration folder from the activation checkout so extension code, settings and hooks from a pull request’s head cannot replace trusted definitions. Setting engine.dynamic-workflows: false turns the feature flag and extension loading off and denies workflow runs.

The v0.91.1 patch adds artifact_retention_days in .github/workflows/aw.json, an integer from 1 to 400 or a single-line Actions expression, which sets retention for every artifact the compiled workflows upload.

Practical dev impact: A Copilot or Claude workflow compiled on the v0.91 pre-release can run a named dynamic workflow without a separate approval, so decide workflow by workflow and add dynamic-workflows: false under engine: wherever nobody asked for it, starting with workflows that untrusted issues or comments can trigger. For one retention period across agent logs and uploads, set it once in aw.json and recompile, and if you try the pre-release at all, take v0.91.1 rather than v0.91.0.

3. Copilot CLI v1.0.92 is now the default install

GitHub published v1.0.92 at 3:42 PM ET on Monday, and npm now lists it as latest, with prerelease at v1.0.93-1. What Monday’s brief covered as a pre-release now reaches ordinary installs, including sandboxed shells that withhold an ambient GITHUB_TOKEN unless it is explicitly configured. New since that pre-release, Entra-protected MCP servers can silently renew access-token-only credentials.

Practical dev impact: Monday’s advice to keep fleets on v1.0.91 has expired, because v1.0.92 is what a normal update now installs. Before it reaches CI or shared machines, run one sandboxed script that calls gh or the GitHub API and confirm it still authenticates, then make credentials available in the sandbox only for the tasks that need them.

Practical Impact Analysis

Today’s defaults move in opposite directions, so the review work depends on the tool. Claude Code tightened what a cloned repository can switch on, so the work there is choosing a channel: machines on latest should reach v2.1.291 today, while a fleet held on stable at v2.1.285 has none of these changes and needs committed .claude settings reviewed by hand until the pointer moves. GitHub Agentic Workflows loosened one default by pre-approving dynamic workflow runs, but only on a pre-release, so teams on v0.89.21 are unaffected until they choose to move, while anyone who followed Monday’s brief onto v0.90.3 will pick up the new default on the next upgrade and should add the opt-out before recompiling.

Copilot CLI is the change easiest to miss, because little shipped beyond what the pre-releases carried, yet the channel move puts the GITHUB_TOKEN change on every machine that updates normally. Codex shipped only v0.160.1, a one-fix Windows MCP patch, so it is no reason to move a fleet today.

Tutorial

Steps 1, 2, 3 and 5 are in the script below, and step 4 is two small file edits.

  1. Confirm the channels first. The tags we saw at about 5:55 AM ET on 6 Oct are in the stories above.
  2. Move npm installs on latest straight to v2.1.291. Native installs on latest get it on the next auto-update or claude update. Leave stable machines where your policy puts them.
  3. Search each repository’s committed .claude folder for Chrome or the attachments variable, and turn Chrome on per person with /chrome instead. Move the attachments variable to user settings.
  4. On a branch, opt a gh-aw workflow out of dynamic workflows by adding dynamic-workflows: false under engine: in its frontmatter, next to the id: line. If you want one retention period, put {"artifact_retention_days": 7} in .github/workflows/aw.json, with your own number of days.
  5. To compile that branch on the pre-release, install gh-aw pinned to v0.91.1 on a test machine, because a plain upgrade stops at v0.89.21. If gh-aw is already installed, remove it first and reinstall it pinned. We did not compile a real repository, so treat the first run as a test.
bash Tutorial
#!/usr/bin/env bash
set -u

# Step 1: channel tags before you change anything
npm view @anthropic-ai/claude-code dist-tags --json
npm view @github/copilot dist-tags --json
claude --version

# Step 2: uncomment only on npm installs that follow latest
# npm install -g @anthropic-ai/claude-code@2.1.291

# Step 3: project settings that mention Chrome or the attachments switch
git grep -n -i -e chrome -e CLAUDE_CODE_DISABLE_ATTACHMENTS -- .claude

# Step 5: pinned gh-aw pre-release (machine-wide), then compile the branch

... click "Show full code" below to expand
▸ Show full code (20 lines)
#!/usr/bin/env bash
set -u

# Step 1: channel tags before you change anything
npm view @anthropic-ai/claude-code dist-tags --json
npm view @github/copilot dist-tags --json
claude --version

# Step 2: uncomment only on npm installs that follow latest
# npm install -g @anthropic-ai/claude-code@2.1.291

# Step 3: project settings that mention Chrome or the attachments switch
git grep -n -i -e chrome -e CLAUDE_CODE_DISABLE_ATTACHMENTS -- .claude

# Step 5: pinned gh-aw pre-release (machine-wide), then compile the branch
# Uncomment the remove line only if gh-aw is already installed.
# gh extension remove gh-aw
gh extension install github/gh-aw --pin v0.91.1
gh aw --version
gh aw compile

Recommended AI prompt

Copy this paragraph into ChatGPT, Claude, Gemini, Grok, or whatever AI you use.

I run a small team on Claude Code, GitHub Copilot CLI and GitHub Agentic Workflows. Claude Code v2.1.290 stops a repository’s settings files from turning on Claude in Chrome and makes some read-only commands such as rg and git grep prompt when their arguments would expand as wildcards, and v2.1.291 fixes a v2.1.290 regression that could drop permission prompt answers in cloud sessions, while stable is still v2.1.285. The gh-aw v0.91 pre-release enables dynamic workflows by default for the Copilot engine and pre-approves their runs unless engine.dynamic-workflows is false, and Copilot CLI v1.0.92 is now the npm latest release, with sandboxed shells that withhold an ambient GITHUB_TOKEN. Write me a one-page checklist, in order, covering how to confirm each tool’s version and channel, which latest-channel machines to move to v2.1.291 and what to check on machines held on stable, what to look for in committed .claude settings, which gh-aw workflows should opt out of dynamic workflows, and how to test that a sandboxed Copilot CLI script still authenticates to GitHub. Name the exact command or setting for each step and the risk it avoids. If you need our install methods or channel policy, ask me instead of guessing.

Go deeper in Grok

Explore each Top Story in Grok. Links open in a new tab. On phones, the same link may open the Grok app if you have it installed (via your device's normal link handling).

Article: Claude Code Tightens Repository Trust While GitHub Pre-Approves Dynamic Workflows

Privacy: links open grok.com in your session only. AIDevPulse does not run your prompts through our API.

1 thought on “Claude Code Tightens Repository Trust While GitHub Pre-Approves Dynamic Workflows”

Leave a Comment