claudecode/claude_api_client.py hardcodes claude-3-5-haiku-20241022 for its API-key validation call:
model="claude-3-5-haiku-20241022",
That model was retired on 2026-02-19, so this call now fails with not_found_error on every run, for every user of the action.
How it surfaced
Anthropic's automated retirement email, reporting failed requests from a key whose only use is this action in CI:
On October 3, 2026 (UTC) ... sent 2 failed requests to claude-3-5-haiku-20241022
Two PRs ran the action that day — one failed request each.
Impact
Low but not zero:
- The scan itself still works. The client fails open, and findings are unaffected (confirmed from our run artifact:
files_reviewed: 10, review_completed: true).
- But every user generates failing API requests, and Anthropic emails them about a model they never configured. Since the failures are
not_found_error, they don't show on the Usage page, so the email's advice — "search your application logs for the model name" — leads to code that doesn't contain it. It took tracing the key back to CI to find this.
Suggested fix
Point the validation call at a current model (claude-haiku-4-5), or reuse the configurable self.model / DEFAULT_CLAUDE_MODEL the main analysis path already uses, so a future retirement only has to be fixed in one place.
Happy to open a PR if useful.
Noting that main appears to have been last updated 2026-02-11, about a week before the retirement date.
claudecode/claude_api_client.pyhardcodesclaude-3-5-haiku-20241022for its API-key validation call:That model was retired on 2026-02-19, so this call now fails with
not_found_erroron every run, for every user of the action.How it surfaced
Anthropic's automated retirement email, reporting failed requests from a key whose only use is this action in CI:
Two PRs ran the action that day — one failed request each.
Impact
Low but not zero:
files_reviewed: 10, review_completed: true).not_found_error, they don't show on the Usage page, so the email's advice — "search your application logs for the model name" — leads to code that doesn't contain it. It took tracing the key back to CI to find this.Suggested fix
Point the validation call at a current model (
claude-haiku-4-5), or reuse the configurableself.model/DEFAULT_CLAUDE_MODELthe main analysis path already uses, so a future retirement only has to be fixed in one place.Happy to open a PR if useful.
Noting that
mainappears to have been last updated 2026-02-11, about a week before the retirement date.