Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.221 Home All releases olderv2.1.220 v2.1.222newer

Sandbox filesystem.disabled description corrected on credential masks

Use it now
Useful3 Signal0
Sandbox Notable

Settings docs now explain that masked credential files survive a relaxed sandbox filesystem policy while denied ones do not.

filesystem.disabledcredentials.files
What

The settings schema text for skipping filesystem isolation now separates two kinds of credentials.files entries that behave differently under a relaxed filesystem policy.

Details
  • Deny entries in credentials.files are dropped and pin the setting to managed settings.
  • Mask entries are implemented as sentinel binds, survive the relaxed filesystem policy, and do not pin the setting.
  • Env scrubbing is likewise independent of the filesystem policy.
Evidence

do not pin it — env scrubbing and sentinel binds are independent of the filesystem

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.221 →