Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v1.0.111 Home All releases olderv1.0.110 v1.0.112newer
Claude Code v1.0.111

Environment Variable Whitelist

What: Settings files (.claude/settings.json and .claude/settings.local.json) can now only set specific whitelisted environment variables.

Details:

  • 45 allowed environment variables including:
  • API configuration: ANTHROPIC_API_KEY, ANTHROPIC_MODEL
  • Feature flags: DISABLE_TELEMETRY, DISABLE_ERROR_REPORTING
  • Proxy settings: HTTP_PROXY, HTTPS_PROXY
  • Tool timeouts: BASH_MAX_TIMEOUT_MS, MCP_TIMEOUT
  • Prevents arbitrary environment variable injection via settings files
  • Security enhancement to protect against potential configuration exploits
  • Evidence: YCB Set at lines 427822-427867, WCB() at line 427868

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v1.0.111 →