Conversation
…de-3-5-haiku validate_api_access() hardcoded claude-3-5-haiku-20241022 for its 10-token health check. That model was retired on 2026-02-19, so the check now fails unconditionally regardless of the claude-model input, and FindingsFilter responds by silently disabling Claude-powered false-positive filtering (findings_filter.py logs a warning and sets use_claude_filtering=False) while the action run stays green. Use self.model — the model the client was constructed with and will use for the actual filtering calls — so the health check validates the same access it is guarding.
… 3.5 validate_api_access() was pinned to claude-3-5-haiku-20241022, retired on 2026-02-19. Every preflight 404'd with not_found_error, and findings_filter.py treats a failed preflight as "Claude filtering unavailable" — it logs a warning to stderr and sets use_claude_filtering = False. In a GitHub Action that stderr goes to claudecode-error.log, which is never printed, so false-positive filtering has been off since the retirement date with no visible signal. Validating with self.model checks the model the client will actually call, so a preflight failure now means something real rather than a stale constant. Upstream: anthropics#127 (open, along with anthropics#69, anthropics#73, anthropics#88, anthropics#90, anthropics#102, anthropics#103, anthropics#114, anthropics#123, anthropics#128 for the same defect). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Supporting this one — it matches what we independently diagnosed, and I want to add the impact detail plus a second defect that this PR alone doesn't cover. The failure is swallowed, which is why it went unnoticed for six months
valid, error = self.claude_client.validate_api_access()
if not valid:
logger.warning(f"Claude API validation failed: {error}")
self.claude_client = None
self.use_claude_filtering = FalseIn the GitHub Action, that warning goes to We only found it because Anthropic's model-retirement notice reported 15 failed requests on 2026-08-26 from a key whose only user is CI, and none of our own code referenced the model. Every one of those 15 was a security review that produced findings and filtered none of them.
|
Fixes #127.
validate_api_access()hardcodedclaude-3-5-haiku-20241022for its 10-token health check. That model was retired on 2026-02-19, so the check now fails unconditionally — theclaude-modelinput never reaches it — andFindingsFilterresponds by silently disabling Claude-powered false-positive filtering (findings_filter.pylogs a warning and setsuse_claude_filtering = False) while the run stays green.This changes the health check to use
self.model, the model the client was constructed with and will use for the actual filtering calls, so it validates the same access it is guarding.Not included here (see #127):
DEFAULT_CLAUDE_MODELinconstants.pyfalls back toclaude-opus-4-1-20250805, which is also retired — happy to bump that in this PR too if you'd like.🤖 Generated with Claude Code