blob: 14f328eb4112d9e6c5fb838f4c0b961d80d14e13 [file]
# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements. See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership. The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing,
# software distributed under the License is distributed on an
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
# KIND, either express or implied. See the License for the
# specific language governing permissions and limitations
# under the License.
# pinned-versions.toml
#
# Pinned upstream versions of the host-system tools the secure agent
# setup depends on. The pin shape mirrors the framework's broader
# cooldown convention (see `[tool.uv] exclude-newer = "7 days"` in
# the root pyproject.toml and the dependabot weekly cooldown of 7
# days in `.github/dependabot.yml`): every entry below names a
# version that was released **at least `cooldown_days` ago at the
# time the entry was last touched**, so an upstream retag /
# withdrawal / fix-forward has had time to settle before adopters
# install it.
#
# Cooldown is **per-tool** with a 7-day default. A tool with an
# unusually well-watched release stream — `claude-code` is the
# canonical example, since its release cadence is high and any
# regression that affects the framework's permission-rule
# semantics or sandbox flags is caught broadly within hours of
# release — can override the default via `cooldown_days = N` in
# its `[tools.<name>]` table. Lowering the cooldown trades
# settle-time for currency; raise it back if a tool starts
# shipping pre-release fix-forwards routinely.
#
# Adopters consume this file by:
# 1. Reading the versions in `docs/setup/secure-agent-setup.md` and installing
# them on the host (the doc has the install commands per distro).
# 2. Running `tools/agent-isolation/check-tool-updates.sh` weekly
# (or via `/schedule`) to surface upstream releases that have
# themselves aged past each tool's cooldown — those are
# candidates for the next intentional bump.
#
# To bump a tool: only when the new upstream version was released at
# least the tool's `cooldown_days` ago, AND the framework maintainer
# wants to upgrade. Update the `version` and `released` fields
# together, then bump the `pinned_at` field below to today.
# When this file was last touched. The check script uses this as the
# minimum age the entries below claim to satisfy.
pinned_at = "2026-07-08"
[tools.bubblewrap]
version = "0.11.2"
released = "2026-04-23"
purpose = """
Linux user-namespace sandbox. The strongest layer of credential
isolation: enforces the `denyRead` / `allowRead` filesystem rules
in `.claude/settings.json` for every Bash subprocess Claude Code
spawns. Required for the `sandbox.enabled: true` setting to
actually mean anything on Linux; macOS uses native Seatbelt
instead and does not need bubblewrap.
"""
docs = "https://github.com/containers/bubblewrap"
upstream_releases = "https://api.github.com/repos/containers/bubblewrap/releases"
# Install commands per distro (use the package manager's syntax for
# requesting a specific version where supported). See
# `docs/setup/secure-agent-setup.md` for adopter-facing install steps.
install.apt = "apt-get install --no-install-recommends bubblewrap=0.11.2-*"
install.dnf = "dnf install bubblewrap-0.11.2"
install.brew = "# macOS does not need bubblewrap; it uses Seatbelt."
install.from_source = "https://github.com/containers/bubblewrap/releases/tag/v0.11.2"
[tools.socat]
version = "1.8.1.3"
released = "2026-06-26"
purpose = """
TCP relay used by Claude Code's sandbox network proxy to enforce
the `sandbox.network.allowedDomains` allowlist. Without socat the
sandboxed session has no network at all (which is sometimes a
fine outcome). Linux only; macOS does not need it.
"""
docs = "http://www.dest-unreach.org/socat/"
upstream_releases = "http://www.dest-unreach.org/socat/download/"
install.apt = "apt-get install --no-install-recommends socat=1.8.1.3-*"
install.dnf = "dnf install socat-1.8.1.3"
install.from_source = "http://www.dest-unreach.org/socat/download/socat-1.8.1.3.tar.gz"
[tools.claude-code]
version = "2.1.202"
released = "2026-07-06"
# Override the framework-wide 7-day default. Claude Code releases
# cadence is high (multiple releases per week) and any regression
# that affects the framework's permission-rule semantics, sandbox
# flags, or prompt-injection mitigations is caught broadly within
# hours of release — the wider Claude Code user base spans many
# more workloads than this framework's secure setup, and a 1-day
# floor is a reasonable balance between currency and settle-time
# for this specific tool. Raise back to 7 if Claude Code starts
# shipping pre-release fix-forwards routinely.
cooldown_days = 1
purpose = """
The agent runtime itself. Pinning matters because the
permission-rule semantics, the sandbox flags, and the
prompt-injection mitigations evolve between releases — a
silent autoupdate to a release with a different default would
change the framework's effective security posture without a
review pass. The framework maintainer bumps this in lockstep
with reviewing release-notes for behavioural changes that
affect the secure setup.
"""
docs = "https://code.claude.com/docs/"
upstream_releases = "https://api.github.com/repos/anthropics/claude-code/releases"
# Claude Code is distributed via npm; use `--no-save` so the global
# install doesn't drift the local lockfile of any project the user
# installs from.
install.npm = "npm install -g --no-save @anthropic-ai/claude-code@2.1.202"
install.brew = "# brew tap anthropics/claude-code; brew install claude-code@2.1.202 (when available)"