Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.246 Home All releases olderv2.1.245 v2.1.247newer
Claude Code v2.1.246

Stricter check on whether a command's program sits in a writable location

Under the hood
Useful2 Signal3
Hooks

More hook and command programs are conservatively treated as tamperable rather than trusted.

What

The resolver that decides whether a hook or configured command points at a program you could tamper with got three new checks, so more commands are conservatively treated as unresolved or in reach rather than trusted.

Details
  • A file with more than one hard link is treated as reachable unless its first four bytes are a genuine ELF or Mach-O magic number.
  • env is only honoured at the literal paths /usr/bin/env and /bin/env, and its argument may not contain a slash.
  • Following #! interpreter lines is now depth-limited, with a final check that the target really is a script.
Evidence

program_unresolved

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.246 →