This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
ReleasePort's take
Light signalRelease v0.55.56 fixes wrapped hook paths in Claude Code, Codex, and Gemini for isolated worktrees and stops stale ANTHROPIC_API_KEY values from being inherited by child processes.
Why it matters: Patch to v0.55.56 immediately to correct path wrapping bugs and prevent unintended API key inheritance in child processes.
Summary
AI summaryFixed path wrapping for Claude Code, Codex, and Gemini hooks in isolated attempt worktrees and prevented inheritance of stale ANTHROPIC_API_KEY.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Fix wrapped hook paths in Claude Code, Codex, and Gemini for isolated worktrees. Fix wrapped hook paths in Claude Code, Codex, and Gemini for isolated worktrees. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Prevent stale ANTHROPIC_API_KEY values from being inherited by Claude Code child processes. Prevent stale ANTHROPIC_API_KEY values from being inherited by Claude Code child processes. Source: llm_adapter@2026-05-21 Confidence: high |
— |
Full changelog
Fix wrapped Claude Code, Codex, and Gemini hook paths when AIT runs agent commands inside isolated attempt worktrees. The executable pain-point demos also avoid inheriting stale ANTHROPIC_API_KEY values into Claude Code child processes.
Security Fixes
- Prevented inheritance of stale ANTHROPIC_API_KEY into Claude Code child processes
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Ait
All releases →Related context
Related tools
Earlier breaking changes
- v0.55.52 Keep the built-in claude-code reviewer pinned to the local claude -p CLI even when repository policy defines a conflicting command override.
Beta — feedback welcome: [email protected]