{"version":"2.1.293","anchor":"artifact-prompts-now-require-pinned-library-versions-at-leas","canonical_anchor":"artifact-prompts-now-require-pinned-library-versions-at-leas","heading":"Artifacts are told to use library versions at least two weeks old","tier":"notice","area":"Artifacts","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293\/e\/artifact-prompts-now-require-pinned-library-versions-at-leas","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293","markdown":"### Artifacts are told to use library versions at least two weeks old\n\nClaude's instructions for building artifacts now say to pin each library to an exact version at least two weeks old\n\n**What**\n\nArtifacts are pages, such as small web apps, that Claude builds for you. They often load outside code libraries from a web address. Claude's built-in instructions for artifacts, and the artifact viewer's guidance on outside resources, used to say only to pin an exact version of each library. They now also say to choose a version that is at least two weeks old.\n\nThe guidance for pages written before the artifact instructions load says the same thing, using `react@18.3.1` as an example of an exact version.\n\n**Why**\n\nLibraries are sometimes tampered with soon after a new version is published. Asking for versions at least two weeks old makes it less likely that an artifact loads a newly released version that has been compromised.\n\n- Area: Artifacts\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: no"}