Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.224 Home All releases olderv2.1.223 v2.1.225newer

Sandbox network rules can specify a port

Use it now
Useful4 Signal2
Sandbox Notable

Sandbox allow and deny rules can now target a specific port instead of the whole host.

What

Domain allow and deny rules in the sandbox now parse a host pattern plus an optional port, so a rule can target a single port rather than the whole host.

Details
  • Matching fails closed on both sides: a port-qualified rule matches a request with an unknown port when denying, and does not match when allowing.
  • Otherwise the port must match exactly.
  • Deny rules still come from sandbox.network.deniedDomains plus WebFetch-style domain: permission rules.
Evidence

sandbox.network.allowManagedDomainsOnly is set and

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.224 →