Agent Frameworks & Harnesses 2026-10-10

Framework Watch: Claude Code 2.1.296 Makes Managed Hook Denials End the Turn; Cloudflare Buys Deno to Self-Host Durable Objects for Agents

Claude Code 2.1.296 (October 9) fixes managed-settings hooks that refused a call without stopping the turn, closes a BASH_ARGV0 auto-approval gap, and refuses edits that would corrupt non-UTF-8 files. The same day Cloudflare acquired Deno: the runtime gets one more year of fixes, Deno Deploy six months, and its celld engine merges into workerd.

Two dated changes this week matter to teams that build and run agent harnesses: a security-heavy Claude Code release, and a change of ownership for one of the runtimes agents are often hosted on.

Claude Code 2.1.296 (October 9): what operators should act on

  • Managed denials now stop the turn. "Fixed managed-settings PreToolUse hooks that deny a tool call with "continue": false, and managed prompt hooks that block one, refusing the call but not ending the turn." Organisations using managed hooks as a stop switch should retest them on this version.
  • Permission gaps. Bash checks were "auto-approving some commands that assign the BASH_ARGV0 shell variable and then use it; these now prompt for approval." On Windows, rm -rf /c/Users/<name> in Git Bash was not asking in bypass-permissions mode.
  • Interrupts. Pressing Esc during a UserPromptSubmit hook could end headless sessions or let "the unchecked prompt through."
  • Secrets and files. Secret redaction in shared transcripts and debug logs missed "some values that follow a key with no value." Edit and NotebookEdit were "replacing every non-ASCII character in files that are not valid UTF-8 (Windows-1252, Shift-JIS, GBK)"; such edits are now refused.
  • Subagents and limits. New autoCompactWindow lets a subagent compact earlier than the main conversation; CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL pins all workflow agents to one model; the default cap on MCP tool descriptions and server instructions doubles from 2,048 to 4,096 characters. On Windows, PowerShell commands over about 1 KB no longer always prompt -- allow rules now apply up to 32 KB.

OpenAI's Codex 0.162.1, also October 9, is a small follow-up to the October 8 sandbox release: a TUI crash fix for multi-line questions and a startup fix for mismatched background-server feature settings.

Cloudflare acquires Deno (October 9)

Deno's announcement sets clear dates. "We will support the Deno runtime for another year with monthly releases containing bug fixes and security updates. After that year we will end our development of the Deno runtime. Deno will remain open source." And: "Deno Deploy will continue operating for six months before shutting down," with migration support for paying customers.

The reason is celld, Deno's open-source, distributed take on Cloudflare's Durable Objects. On Cloudflare's blog, Ryan Dahl describes it as "one binary, written in Rust, with object storage as its only external service dependency," and says the goal of bringing "celld and workerd together" is to make it "radically easy to build and operate distributed applications on your own infrastructure." In a Hacker News comment quoted by Simon Willison, Dahl said Deno "has been sucked into the gravity well of node compatibility."

The agent angle is explicit. Deno's post says Durable Objects "bring together capabilities that are particularly useful for agent harnesses: inexpensive, serverless execution, persistent state, WebSockets, and a high-level JavaScript interface." Each Durable Object is, in Dahl's words, "like a small, individually addressable server with its own relational database" -- a natural fit for one long-running agent session per object. Self-hostable Durable Objects would let teams run that model inside their own cloud, which addresses the lock-in worry Cloudflare's post takes on directly.

What to watch. When the merged workerd/celld actually ships; whether a community fork keeps the Deno runtime going after next October; and how Deno's per-script permission model, which Willison calls his favourite feature, survives the move.

Analysis: teams with agents on Deno Deploy have a six-month migration clock that started on October 9. Teams on managed Claude Code settings should confirm their deny hooks now end the turn, and audit any Windows bypass-mode sessions that ran before this release.

Claude Code 2.1.296 makes managed deny hooks end the turn, closes BASH_ARGV0 and Git Bash rm gaps, and refuses edits that would mangle non-UTF-8 files; Cloudflare's purchase of Deno ends Deno Deploy in six months and the runtime's development in a year, in exchange for self-hostable Durable Objects pitched at agent harnesses.