Choose a sandbox environment changedsandbox-environments
Nearest release: v2.1.286, published 10 hours after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 30 Sep 2026 07:07 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 30 Sep 2026 07:37 UTC.
Upstream edited
Recorded here
Lines+2added
Lines−2removed
From line
120
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits14to this page, all time
The whole hunk
from line 120, old and new numbered
/
from line 120
120120* At the project root, the runtime denies `.git/hooks`, denies `.git/config` unless you set `filesystem.allowGitConfig: true`, and denies `.mcp.json`, `.claude/commands`, `.claude/agents`, and shell startup files.
121121* On macOS, these denies are checked when a write happens, so they also cover nested files and repositories created during the session.
122122* On Linux and WSL2, the runtime builds the deny list once at launch. It reliably covers the project root, makes a best-effort shallow scan for nested copies that exist at that point, and does not cover anything the session creates later, such as `git init`, `git clone`, or scaffolding. The README's `mandatoryDenySearchDepth` section describes the scan's exact semantics.
123* Without a valid `~/.srt-settings.json`, the runtime starts anyway, blocks network access, and confines writes to built-in runtime paths such as `/tmp/claude`, `~/.npm/_logs`, and `~/.claude/debug`. Don't take a clean start as proof your settings loaded.
124* When you pass `--settings`, the runtime refuses to start if the file fails to load.
123* If `~/.srt-settings.json` doesn't exist and you don't pass `--settings`, the runtime starts anyway. It blocks network access and confines writes to built-in runtime paths such as `/tmp/claude`, `~/.npm/_logs`, and `~/.claude/debug`. Don't take a clean start as proof your settings loaded.
124* If the settings file exists but is empty, unreadable, or invalid, the runtime refuses to start, whether it's `~/.srt-settings.json` or a file you pass with `--settings`. It also refuses to start if the `--settings` file doesn't exist.
125125
126126Your write grants still include other paths Claude Code loads configuration from, so deny those with `denyWrite`. A sandboxed session that can write them can persist hooks, permission rules, or MCP servers that run unsandboxed the next time you launch Claude Code.
127127
No line in this hunk matches that.