Skip to content

claude-flow

v3.10.42 Bugfix

This release fixes issues for SREs watching stability and regressions.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

agentic-ai agentic-framework agentic-workflow agents ai-agents ai-assistant
+14 more
ai-coding ai-skills autonomous-agents claude-code codex harness mcp-server multi-agent multi-agent-systems npm skills swarm swarm-intelligence typescript

Summary

AI summary

Fixed Windows path rejection in post‑edit hooks, ensured feedback distillation without steps, and made init hooks generate the hooks block.

Changes in this release

Feature Low

Adds distillation of step-less feedback in `trajectory-end` into searchable patterns.

Adds distillation of step-less feedback in `trajectory-end` into searchable patterns.

Source: llm_adapter@2026-06-11

Confidence: high

Bugfix Medium

Fixes Windows path rejection in `hooks post-edit` and surfaces errors correctly.

Fixes Windows path rejection in `hooks post-edit` and surfaces errors correctly.

Source: llm_adapter@2026-06-11

Confidence: high

Bugfix Medium

Fixes missing `hooks` block in `settings.json` when running `init hooks` subcommand.

Fixes missing `hooks` block in `settings.json` when running `init hooks` subcommand.

Source: llm_adapter@2026-06-11

Confidence: high

Full changelog

Patch release fixing three reproducible community bugs reported by @grym3s, batched in the style of v3.10.41 / PR #2346.

Fixes

#2352 — hooks post-edit: Windows paths rejected, failure printed as [OK]

  • validatePath used the general SHELL_META set which includes \, so every absolute Windows path (E:\Repos\…) failed with "shell metacharacters". Claude Code hook events deliver absolute paths in tool_input.file_path, so every forwarded post-edit call failed silently on Windows.
  • The CLI action printed [OK] Outcome recorded for … whenever the MCP call returned at all, masking the failure. Now checks result.success, surfaces the error, and exits non-zero.

#2351 — trajectory-end: step-less feedback never distilled

When trajectory-end is called with feedback but no recorded steps (the common LLM-agent case), the feedback was persisted with the trajectory but never embedded as a searchable pattern — patternsExtracted always reported 0 and pattern-search never surfaced it. Now routes the trimmed feedback through bridge.bridgeStorePattern (or store-fallback) with modest default confidence, tagged trajectory-feedback. New feedbackDistilled.{patternId, controller} field on the response.

#2350 — init hooks: subcommand wrote no hooks block to settings.json

The settings generator gates the hooks block on components.helpers (the hook commands point at the helper script). The init hooks subcommand had helpers: false, so the one subcommand whose purpose is "Initialize only hooks configuration" produced settings.json with no hooks key while reporting "N hooks enabled". Helpers now ship with the subcommand.

Install / upgrade

npx ruflo@latest init        # 3.10.42
npx @claude-flow/cli@latest  # 3.10.42

All three packages (@claude-flow/cli, claude-flow, ruflo) and all three dist-tags (latest, alpha, v3alpha) are pinned to 3.10.42.

Tests

  • New validate-input-path-2352.test.ts — 22 tests pin Windows-path acceptance, POSIX still works, all shell metacharacters and traversal still rejected.
  • All existing validate-input, init-wizard-bugs, hooks-intelligence-learning, hooks-post-task tests still pass.

Diff

PR #2355 · main…v3.10.42

🤖 Generated with RuFlo

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track claude-flow

Get notified when new releases ship.

Sign up free

About claude-flow

Deploy multi-agent swarms with coordinated workflows.

All releases →

Related context

Beta — feedback welcome: [email protected]