Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.224 Home All releases olderv2.1.223 v2.1.225newer

Host credentials path normalised like every other sandbox rule

You'll notice
Useful2 Signal2
Sandbox not in their notes

A trailing slash in your host credentials file path no longer changes whether the rule matches.

CLAUDE_CODE_HOST_CREDS_FILE
What

The file named by CLAUDE_CODE_HOST_CREDS_FILE is now run through the same path normaliser as sandbox allow/deny entries and permission deny rules, so a trailing slash no longer changes whether the rule matches.

Details
  • Sandbox deny and allow filesystem entries, permission deny rules and the host credentials path all share one trailing-separator-aware normaliser when sandbox rules are built.
  • Previously each of these handled paths its own way.
Evidence

CLAUDE_CODE_HOST_CREDS_FILE

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

See this entry in the whole of v2.1.224 →