Follow Discord
Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.257 ·

New signed-cache shadow verification (telemetry-only)

Managed-settings and policy-limits caches are signature-checked against embedded trust roots, but only report telemetry for now.

TierNothing to try yethow much it should matter to you
Useful3my rating, 1 to 5
Signal4worth watching, 1 to 5
AreaSettingswhat it touches
KindIn Developmentin v2.1.257,
Nothing to try yet No documentation found

Managed-settings and policy-limits caches are signature-checked against embedded trust roots, but only report telemetry for now.

A new signature-verification path checks managed-settings and policy-limits caches against embedded trust roots, using JWS with an x5c certificate chain and ES256. It computes age, cert-expiry, and chain-validation results, but currently only emits telemetry (tengu_signed_cache_shadow) rather than enforcing anything, as a shadow rollout of cache integrity checking.

See this entry in the whole of v2.1.257 →

Feedback