Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.235 ·

Cloud/frame SDK messages are validated instead of trusted

Cloud/frame SDK messages are now validated field-by-field instead of trusted

Under the hood Bug Fixes
JSON All of v2.1.235
Under the hoodTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SessionsArea: what it touches
Bug FixesKind: in v2.1.235,
Bug FixesSection of the release

The adapter that converts remote frame messages into local ones now validates each field before using it. A missing or non-string uuid is replaced with a freshly generated one and logged at error level. Frames whose content is not a string are dropped, as are tool_progress frames with non-string names or non-finite elapsed time, and compact_boundary frames without metadata.

For init frames, model, cwd, slash_commands, mcp_servers and tools are each checked individually: if any arrives in the wrong shape, it is ignored and logged rather than adopted.

See this entry in the whole of v2.1.235 →

Feedback