Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · claude-docs

Security and data handling changedgovernment/security/security-and-data-handling

Nearest release: v2.1.286, published under an hour before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Upstream edited this page at 30 Sep 2026 17:42 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 30 Sep 2026 18:07 UTC.

Upstream edited
Recorded here
Lines+3added
Lines−3removed
From line 46 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits21to this page, all time

The whole hunk

from line 46, old and new numbered
/
lines
from line 46
4646 
4747Exempting git commands such as `git commit` with `sandbox.excludedCommands` is not a safe way around the socket restriction. A sandboxed command can still change files that git runs during a commit, such as hook scripts kept in the working tree, and an exempted `git commit` would then run that code outside the sandbox. On macOS, git also cannot reach remotes over SSH from inside the sandbox, so a user who needs to push can use an HTTPS remote whose host is on the **Allowed network hosts** list, or push from a terminal outside the Code session.
4848 
49In container-based Linux environments, such as cloud development workspaces, the sandbox can fail to start, and shell commands in Code sessions then fail with a `bwrap` error. To run Code sessions there, deploy Claude Code's own [managed settings file](https://code.claude.com/docs/en/managed-settings) at `/etc/claude-code/managed-settings.json`, set [`parentSettingsBehavior`](https://code.claude.com/docs/en/settings-reference#parentsettingsbehavior) to `"merge"` in it so that your organization's other settings for Code sessions stay in force, and add one of the two settings that follow.
49In container-based Linux environments, such as cloud development workspaces, the sandbox can fail to start, and shell commands in Code sessions then fail with a `bwrap` error. To run Code sessions there, turn off the **Shell command sandbox** switch under **Advanced settings** in the **Claude Code** section of the [Config](/docs/government/config/settings) page, at the level that applies to the members who work in those environments, such as a [directory group](/docs/government/config/overview#group-specific-settings).
5050 
51In that managed settings file, setting `sandbox.enableWeakerNestedSandbox` to `true` runs the sandbox in the [weaker mode that Claude Code documents for containers](https://code.claude.com/docs/en/settings-reference#sandbox-enableweakernestedsandbox), which keeps the network and filesystem restrictions but lets sandboxed commands see the container's other processes. Use it only where the container already provides the isolation you need. If the sandbox still cannot start with that setting, or you prefer to rely on the container's own controls alone, set `sandbox.enabled` to `false` instead. Shell commands then run directly in the container under the permission mode the user selects for the session, as they do on Windows, and the **Allowed network hosts** and **Allowed workspace folders** settings no longer confine what those commands can reach or change.
51The **Shell command sandbox** switch applies to those members on every device they use, not only in the container workspaces. Shell commands in their Code sessions then run without the sandbox, under the permission mode the user selects for the session, as they do on Windows, and the **Allowed network hosts** and **Allowed workspace folders** settings no longer confine what those commands can reach or change. The switch reaches Code sessions in Claude Desktop 2.9939.2 or later. The switch also turns the sandbox off in those members' sessions in the Claude Code command-line tool.
5252 
5353On Windows, there is no operating-system-level sandbox for Code sessions. Shell commands run directly on the device under the permission mode the user selects for the session and under your agency's own endpoint and network controls. The **Allowed network hosts** and **Allowed workspace folders** settings do not confine what those commands can reach, read, or change.
5454 
Feedback