Telemetry endpoints set by your launching environment are now protected too, and warnings name the real source.
What's wrong with this entry?
The rule that stops lower-trust config, such as project or user settings, from redirecting OpenTelemetry traffic now also honours OpenTelemetry variables set by whatever process launched Claude Code, not just managed policy settings. Warnings now name the actual source that claimed the setting, for example managed settings or the host spawn environment, rather than always blaming managed settings.
- Enforcement kicks in whenever such variables are present from either source.
is claimed by ${i}, so lower-trust scopes cannot redirect
Strings lifted out of the shipped bundle, so the claim above can be checked against them.