{"name":"filesystem.denyRead","slug":"filesystem-denyread","family":"setting","title":"Settings keys","noun":"settings key","description":"Your sandbox `filesystem.denyWrite` paths are now enforced in the sandbox mode used when a proxy port is configured, where they were ignored","description_source":"entry","described_by":{"version":"2.1.284","anchor":"sandbox-filesystemdenywrite-now-applies-in-the-person-san"},"presence":{"first_seen":null,"removed_in":null,"in_current_build":false,"newest_mined":"2.1.284","builds":0,"mined_builds":127,"first_cited":null},"aliases":[],"entries":[{"version":"2.1.284","anchor":"sandbox-filesystemdenywrite-now-applies-in-the-person-san","heading":"Sandbox write-deny paths now apply in one more sandbox mode","line":"Your sandbox `filesystem.denyWrite` paths are now enforced in the sandbox mode used when a proxy port is configured, where they were ignored","released_at":"2026-09-28 17:11:59","reason":"found in this entry's text"},{"version":"2.1.284","anchor":"linux-sandbox-warning-now-also-covers-read-globs-anchored-at","heading":"Linux sandbox warning now also flags broad read rules","line":"On Linux, the sandbox glob warning now also checks `filesystem.denyRead` and `filesystem.allowRead` patterns that start at the root or have no fixed folder","released_at":"2026-09-28 17:11:59","reason":"named in this entry, found in this entry's text"},{"version":"2.1.284","anchor":"sandbox-settings-reject-deny-globs-that-end-in-a-path-separa","heading":"Sandbox deny rules ending in a slash are now flagged as invalid","line":"Sandbox deny paths that end in a slash now show a validation error, because they matched nothing and protected nothing","released_at":"2026-09-28 17:11:59","reason":"found in this entry's text"},{"version":"2.1.284","anchor":"sandbox-default-writable-npm-logs-and-claudedebug-n","heading":"Sandbox no longer keeps npm logs and Claude debug folders writable when you deny reading them","line":"The sandbox's default-writable ~\/.npm\/_logs and ~\/.claude\/debug folders now respect denyRead and denied credential files unless allowRead re-allows them","released_at":"2026-09-28 17:11:59","reason":"found in this entry's text"},{"version":"2.1.198","anchor":"windows-sandbox-per-exec-deny-flags","heading":"Windows Sandbox: Per-Exec Deny Flags","line":null,"released_at":"2026-07-01 16:50:16","reason":"found in this entry's text"},{"version":"2.1.187","anchor":"sandbox-credentials-credential-protection-in-sandbox","heading":"sandbox.credentials \u2014 Credential protection in sandbox","line":null,"released_at":"2026-06-23 17:55:41","reason":"found in this entry's text"}],"entries_total":6,"docs":[{"source":"claude-code","path":"managed-settings","title":"Deploy managed settings","documented":false},{"source":"claude-code","path":"sandboxing","title":"Configure the sandboxed Bash tool","documented":false},{"source":"claude-code","path":"settings","title":"Claude Code settings","documented":false},{"source":"claude-code","path":"settings-reference","title":"All settings","documented":false}],"docs_total":4,"gates":[],"related":[{"name":"filesystem.allowRead","slug":"filesystem-allowread","description":"On Linux, the sandbox glob warning now also checks `filesystem.denyRead` and `filesystem.allowRead` patterns that start at the root or have no fixed folder"},{"name":"filesystem.denyWrite","slug":"filesystem-denywrite","description":"Your sandbox `filesystem.denyWrite` paths are now enforced in the sandbox mode used when a proxy port is configured, where they were ignored"},{"name":"filesystem.disabled","slug":"filesystem-disabled","description":"Settings docs now explain that masked credential files survive a relaxed sandbox filesystem policy while denied ones do not."}],"url":"https:\/\/changelogs.core-directive.com\/reference\/setting\/filesystem-denyread","family_url":"https:\/\/changelogs.core-directive.com\/reference\/setting.json"}