Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.247 Home All releases olderv2.1.246 v2.1.248newer
Claude Code v2.1.247

Sandbox deny rules follow every hop of a symlinked path

You'll notice
Useful3 Signal3
Sandbox

Sandbox deny rules now block every directory a symlink chain passes through, not just the endpoint.

What

When a denied path is a symlink chain, the sandbox now denies the directories crossed along the way, not just the final target. Applies to everyone; on Windows no hop set is computed.

Details
  • The walk is capped by a hop budget and stops on anything other than the expected missing-or-not-a-directory errors.
  • A new resolver handles dangling paths before the old parent-directory fallback.
Evidence

hopDirectories

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.247 →