Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

denyRead

setting never mined JSON

A Claude Code settings key, read out of the shipped bundle. No mined inventory carries it: everything below comes from what this site has written about it.

Under a relaxed sandbox filesystem policy, the outside-reads block does nothing and this is now logged.

Not Anthropic's. This is the line from the earliest changelog entry here that named it, v2.1.257.

First seen — never in a mined build
Last seen — never in a mined build
Builds0 / 127on this box, as of v2.1.284
Written about v2.1.77 first named in a changelog, 16 Mar 2026

In the changelogs

10

Releases whose published page names denyRead.

  1. v2.1.284
    macOS sandbox blocks reading more paths

    On macOS, the sandbox now blocks reading hidden files and some other paths even when you have not set any read restrictions

    named in this entry, found in this entry's text

  2. v2.1.284
    Sandbox path rules now follow symbolic links and respect read-deny rules

    Sandbox path patterns now match through linked folders, and denyRead rules are no longer undercut by default writable folders

    found in this entry's text

  3. v2.1.284
    Sandbox read and write rules are now worked out together

    Paths Claude's sandbox may write to are now worked out from denyRead, allowRead and credentials together

    named in this entry, found in this entry's text

  4. v2.1.284
    Sandbox no longer keeps npm logs and Claude debug folders writable when you deny reading them

    The sandbox's default-writable ~/.npm/_logs and ~/.claude/debug folders now respect denyRead and denied credential files unless allowRead re-allows them

    found in this entry's text

  5. v2.1.283
    One invalid sandbox deny entry now withholds the matching allow rules

    If one entry in deniedDomains, denyWrite or denyRead is invalid, Claude Code now withholds the matching allow list instead of applying it

    found in this entry's text

  6. v2.1.257
    Relaxed filesystem policy disables the new block

    Under a relaxed sandbox filesystem policy, the outside-reads block does nothing and this is now logged.

    found in this entry's text

  7. v2.1.198
    Windows Sandbox: Per-Exec Deny Flags

    found in this entry's text

  8. v2.1.186

    found in this entry's text

  9. v2.1.90
    Linux Sandbox Improvements

    found in this entry's text

  10. v2.1.77
    Sandbox allowRead Setting

    found in this entry's text

First cited

4

The earliest release whose published evidence quoted denyRead was v2.1.90, 1 Apr 2026. That is the oldest release this project wrote about it, so it is a floor on the name's age and not the release that introduced it. It is not a presence reading: which builds carried the name is the table below.

ReleaseDateThe span that was quoted
v2.1.901 Apr 2026Re-bound write path wiped by denyRead tmpfs
v2.1.1981 Jul 2026Per-exec filesystem.allowRead (re-allow within denyRead) is not supported on Windows
v2.1.2571 Sep 2026the relaxed filesystem policy drops every denyRead at wrap time, so the sandbox half of the block does not apply
v2.1.28428 Sep 2026denyRead: De.filesystem.denyRead

Presence across releases

0

The miner has never read a build containing this name. It is here because a changelog entry of ours names it, which is evidence that it existed and not evidence of which releases carried it. The inventory starts at v2.1.138 and everything older than that was never mined.

Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the settings key does. All settings keys.

Feedback