AI Coding Tools Roundup: Claude Code v2.1.283 Adds Model Locks, Copilot Autofix Gains Memory

Three updates worth tracking landed in the AI coding stack over the past day: Claude Code climbed to v2.1.283 with new model-locking controls and a prompt-audit command, GitHub Copilot's agentic autofix started drawing on Copilot Memory to resolve security alerts, and OpenCode shipped v1.18.32 with fixes for Bedrock image routing and Together AI usage reporting. Here's what changed.
Claude Code v2.1.283 Adds Model-Locking Controls and a Prompt-Audit Command
Anthropic's Claude Code v2.1.283, released September 25, gives admins tighter control over which models a team can run. A new availableModelsMatch managed setting supports an "exact" option to lock a deployment to specific model versions, and a companion deniedModels setting blocks named models outright. The release also adds /doctor prompt-audit, a new command that scans CLAUDE.md files, skills, agents, and slash commands for outdated prompting patterns — useful for teams cleaning up prompt libraries that have accumulated cruft. On the infrastructure side, a new mantle upstream provider adds support for Amazon Bedrock's Mantle endpoint, and a load_test_mode block lets teams load-test the Claude apps gateway without hitting upstream providers.
The fix list matters just as much for anyone running Claude Code against MCP servers or through the SDK: the release fixes SDK sessions losing deferred tool calls or finished tool results when turns ended early, MCP progress notifications getting discarded during long-running background tools, stdio MCP servers being left running after a session ends, and HTTP 404 responses from stateless remote MCP servers making those servers unusable. A fix for DISABLE_PROMPT_CACHING_HAIKU having no effect when Haiku is the main model closes out a release focused squarely on reliability rather than new capabilities.
GitHub Copilot's Agentic Autofix Now Draws on Copilot Memory
GitHub's biggest Copilot update in the past day is on the security side. As of September 25, agentic autofix — GitHub's AI-assisted vulnerability remediation feature — now taps Copilot Memory when it's enabled. Before proposing a fix, autofix reviews existing memories for context that can help resolve a security alert, and once it creates a fix, it stores that fix pattern as a new memory for next time. Those memories compound: they help autofix resolve future alerts faster, and they also inform other Copilot features, including code review and cloud agents, about secure coding patterns specific to a given codebase. Both agentic autofix and Copilot Memory remain public preview features.
The same day, GitHub also shipped an in-product validator for enterprise managed settings, catching misconfiguration before it's applied, and extended the Copilot usage metrics API to report pull request review stages — giving engineering leads more granular visibility into where Copilot's code review is spending time across a PR's lifecycle.
OpenCode v1.18.32 Fixes Bedrock Image Routing and Together AI Usage Reporting
On the open-source side, OpenCode v1.18.32 fixed a routing bug where Bedrock image attachments were being hoisted for model families that don't support them; they're now only hoisted for Claude, Nova, and Llama 4 models on Bedrock. The release also addressed incorrect streaming usage reporting for Together AI, a fix that matters for teams tracking token spend across multiple providers through OpenCode's unified interface.
Also Shipped: A Quiet Codex CLI Maintenance Release
OpenAI's Codex CLI also pushed a new stable tag, rust-v0.157.1, on September 26 — a narrow maintenance release following the prior day's larger rust-v0.157.0 update that introduced the GPT-6 Sol and Luna models with Amazon Bedrock support. No user-facing changes are called out in this build; it's a housekeeping release while the alpha channel keeps cutting builds toward v0.158 and v0.159.
What It Means for Developers
None of today's changes is a flashy new model, but together they show where the major agentic coding tools are investing: governance and safety controls (Claude Code's model locks and prompt audits), trust-building automation (Copilot's memory-backed autofix), and the unglamorous cross-provider plumbing that keeps multi-model workflows honest (OpenCode's Bedrock and Together AI fixes). If you administer Claude Code for a team, the new deniedModels and availableModelsMatch settings are worth reviewing today. If you rely on agentic autofix, Copilot Memory is now quietly doing more work behind the scenes on your behalf.
Resources & References
Comments
Share your thoughts and join the conversation
