Follow Discord
Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.260 ·

Loopback/non-https URL rejection widened to array-valued bootstrap fields

URL safety checks now cover list-valued config fields, with a new setting to allow loopback response URLs.

TierUse it nowhow much it should matter to you
Useful2my rating, 1 to 5
Signal1worth watching, 1 to 5
AreaBootstrap Configwhat it touches
KindImprovementsin v2.1.260,
Use it now Notable No documentation found

URL safety checks now cover list-valued config fields, with a new setting to allow loopback response URLs.

The loopback/https hygiene check for bootstrap config, previously limited to single string URLs, now also inspects array-valued fields using a new helper that collects URLs from strings, arrays, and {url} objects. A new allowLoopbackResponseUrls setting can explicitly permit response URLs to point at loopback hosts.

Read from
Names in the bundleallowLoopbackResponseUrls

See this entry in the whole of v2.1.260 →

Feedback