| # Licensed to the Apache Software Foundation (ASF) under one |
| # or more contributor license agreements. See the NOTICE file |
| # distributed with this work for additional information |
| # regarding copyright ownership. The ASF licenses this file |
| # to you under the Apache License, Version 2.0 (the |
| # "License"); you may not use this file except in compliance |
| # with the License. You may obtain a copy of the License at |
| # |
| # http://www.apache.org/licenses/LICENSE-2.0 |
| # |
| # Unless required by applicable law or agreed to in writing, |
| # software distributed under the License is distributed on an |
| # "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY |
| # KIND, either express or implied. See the License for the |
| # specific language governing permissions and limitations |
| # under the License. |
| |
| # pinned-versions.toml |
| # |
| # Pinned upstream versions of the host-system tools the secure agent |
| # setup depends on. The pin shape mirrors the framework's broader |
| # cooldown convention (see `[tool.uv] exclude-newer = "7 days"` in |
| # the root pyproject.toml and the dependabot weekly cooldown of 7 |
| # days in `.github/dependabot.yml`): every entry below names a |
| # version that was released **at least `cooldown_days` ago at the |
| # time the entry was last touched**, so an upstream retag / |
| # withdrawal / fix-forward has had time to settle before adopters |
| # install it. |
| # |
| # Cooldown is **per-tool** with a 7-day default. A tool with an |
| # unusually well-watched release stream — `claude-code` is the |
| # canonical example, since its release cadence is high and any |
| # regression that affects the framework's permission-rule |
| # semantics or sandbox flags is caught broadly within hours of |
| # release — can override the default via `cooldown_days = N` in |
| # its `[tools.<name>]` table. Lowering the cooldown trades |
| # settle-time for currency; raise it back if a tool starts |
| # shipping pre-release fix-forwards routinely. |
| # |
| # Adopters consume this file by: |
| # 1. Reading the versions in `docs/setup/secure-agent-setup.md` and installing |
| # them on the host (the doc has the install commands per distro). |
| # 2. Running `tools/agent-isolation/check-tool-updates.sh` weekly |
| # (or via `/schedule`) to surface upstream releases that have |
| # themselves aged past each tool's cooldown — those are |
| # candidates for the next intentional bump. |
| # |
| # To bump a tool: only when the new upstream version was released at |
| # least the tool's `cooldown_days` ago, AND the framework maintainer |
| # wants to upgrade. Update the `version` and `released` fields |
| # together, then bump the `pinned_at` field below to today. |
| |
| # When this file was last touched. The check script uses this as the |
| # minimum age the entries below claim to satisfy. |
| pinned_at = "2026-07-08" |
| |
| [tools.bubblewrap] |
| version = "0.11.2" |
| released = "2026-04-23" |
| purpose = """ |
| Linux user-namespace sandbox. The strongest layer of credential |
| isolation: enforces the `denyRead` / `allowRead` filesystem rules |
| in `.claude/settings.json` for every Bash subprocess Claude Code |
| spawns. Required for the `sandbox.enabled: true` setting to |
| actually mean anything on Linux; macOS uses native Seatbelt |
| instead and does not need bubblewrap. |
| """ |
| docs = "https://github.com/containers/bubblewrap" |
| upstream_releases = "https://api.github.com/repos/containers/bubblewrap/releases" |
| # Install commands per distro (use the package manager's syntax for |
| # requesting a specific version where supported). See |
| # `docs/setup/secure-agent-setup.md` for adopter-facing install steps. |
| install.apt = "apt-get install --no-install-recommends bubblewrap=0.11.2-*" |
| install.dnf = "dnf install bubblewrap-0.11.2" |
| install.brew = "# macOS does not need bubblewrap; it uses Seatbelt." |
| install.from_source = "https://github.com/containers/bubblewrap/releases/tag/v0.11.2" |
| |
| [tools.socat] |
| version = "1.8.1.3" |
| released = "2026-06-26" |
| purpose = """ |
| TCP relay used by Claude Code's sandbox network proxy to enforce |
| the `sandbox.network.allowedDomains` allowlist. Without socat the |
| sandboxed session has no network at all (which is sometimes a |
| fine outcome). Linux only; macOS does not need it. |
| """ |
| docs = "http://www.dest-unreach.org/socat/" |
| upstream_releases = "http://www.dest-unreach.org/socat/download/" |
| install.apt = "apt-get install --no-install-recommends socat=1.8.1.3-*" |
| install.dnf = "dnf install socat-1.8.1.3" |
| install.from_source = "http://www.dest-unreach.org/socat/download/socat-1.8.1.3.tar.gz" |
| |
| [tools.claude-code] |
| version = "2.1.202" |
| released = "2026-07-06" |
| # Override the framework-wide 7-day default. Claude Code releases |
| # cadence is high (multiple releases per week) and any regression |
| # that affects the framework's permission-rule semantics, sandbox |
| # flags, or prompt-injection mitigations is caught broadly within |
| # hours of release — the wider Claude Code user base spans many |
| # more workloads than this framework's secure setup, and a 1-day |
| # floor is a reasonable balance between currency and settle-time |
| # for this specific tool. Raise back to 7 if Claude Code starts |
| # shipping pre-release fix-forwards routinely. |
| cooldown_days = 1 |
| purpose = """ |
| The agent runtime itself. Pinning matters because the |
| permission-rule semantics, the sandbox flags, and the |
| prompt-injection mitigations evolve between releases — a |
| silent autoupdate to a release with a different default would |
| change the framework's effective security posture without a |
| review pass. The framework maintainer bumps this in lockstep |
| with reviewing release-notes for behavioural changes that |
| affect the secure setup. |
| """ |
| docs = "https://code.claude.com/docs/" |
| upstream_releases = "https://api.github.com/repos/anthropics/claude-code/releases" |
| # Claude Code is distributed via npm; use `--no-save` so the global |
| # install doesn't drift the local lockfile of any project the user |
| # installs from. |
| install.npm = "npm install -g --no-save @anthropic-ai/claude-code@2.1.202" |
| install.brew = "# brew tap anthropics/claude-code; brew install claude-code@2.1.202 (when available)" |