Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v1.0.116 Home All releases olderv1.0.115 v1.0.117newer
Claude Code v1.0.116

Refactored Sandbox System

What: Complete architectural overhaul of the sandboxing implementation

Key Changes:

  • Centralized sandbox manager with clean API (hV object at line 374998)
  • New configuration model: allowAllExcept (blacklist) vs denyAllExcept (whitelist)
  • Network deny-lists alongside allow-lists for more granular control
  • macOS sandbox profiles now use deny-by-default security model
  • Recommended defaults for common development tools (npm, cargo, yarn, etc.)
  • Dynamic permission callbacks for interactive network access control
  • Evidence: wBB() at line 374755, Zx6() at line 374844, DBB() at line 374642

Migration Notes:

  • Existing sandbox configurations continue to work
  • New includeRecommendedDefaults option automatically allows access to common tools
  • Deny-by-default macOS profiles are more secure but may require configuration updates

See this entry in the whole of v1.0.116 →