Skip to content

chore(deps): upgrade @anthropic-ai/claude-agent-sdk to ^0.3.220 - #21

Open
cryptotavares wants to merge 1 commit into
mainfrom
cryptotavares/upgrade-claude-agents-sdk
Open

chore(deps): upgrade @anthropic-ai/claude-agent-sdk to ^0.3.220#21
cryptotavares wants to merge 1 commit into
mainfrom
cryptotavares/upgrade-claude-agents-sdk

Conversation

@cryptotavares

Copy link
Copy Markdown
Collaborator

Description

Bump from ^0.2.136 to ^0.3.220 (0.3.221 is quarantined by the repo's 3-day npm age gate). No source changes required: the adapter treats SDK messages as Record<string, unknown> behind safe accessors, and the new Task tools that replace the deprecated TodoWrite pass through as opaque strings. The 0.3.143 move of @anthropic-ai/sdk and @modelcontextprotocol/sdk to peer dependencies does not affect this package.

Changes

  • update @anthropic-ai/claude-agent-sdk to v0.3.220

References

Checklist

  • Tests are included if applicable
  • Changelog is updated if applicable

Bump from ^0.2.136 to ^0.3.220 (0.3.221 is quarantined by the repo's
3-day npm age gate). No source changes required: the adapter treats SDK
messages as Record<string, unknown> behind safe accessors, and the new
Task tools that replace the deprecated TodoWrite pass through as opaque
strings. The 0.3.143 move of @anthropic-ai/sdk and @modelcontextprotocol/sdk
to peer dependencies does not affect this package.
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​anthropic-ai/​claude-agent-sdk@​0.2.138 ⏵ 0.3.22080 +610092 +610070

View full report

@socket-security

Copy link
Copy Markdown

Caution

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Action Severity Alert  (click "▶" to expand/collapse)
Block Medium
Potential security risk (AI signal): npm @anthropic-ai/claude-agent-sdk is 62.0% likely risky

Notes: This module fragment is largely consistent with a bundled cryptography + ASN.1/DER+PEM encoding/decoding library, but it includes a high-sensitivity behavior: Node.js vm.runInThisContext to execute dynamically generated JavaScript for named decoder/encoder creation. If the interpolated identifier(s) can be influenced by untrusted input via normal library usage, this becomes a potential arbitrary code execution risk. No obvious malware behaviors like exfiltration, persistence, or shell/process activity are present in the excerpt.

Confidence: 0.62

Severity: 0.78

From: package.jsonnpm/@anthropic-ai/claude-agent-sdk@0.3.220

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@anthropic-ai/claude-agent-sdk@0.3.220. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant