Follow Discord
Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.277 ·

Repository-trust question gated behind tengu_violin_bridgepin

Headless cloud client now restricts a repository-trust permission request to a single-hash format before forwarding it

TierNothing to try yethow much it should matter to you
Useful2my rating, 1 to 5
Signal3worth watching, 1 to 5
AreaCloud Sessionswhat it touches
KindIn Developmentin v2.1.277,
Nothing to try yet No documentation found

Headless cloud client now restricts a repository-trust permission request to a single-hash format before forwarding it

What

In the headless cloud client, a permission request tied to repository trust is now only passed on to the host if it names exactly one input (a content digest hash) plus a short description. If the request doesn't match that exact shape, it is blocked and a warning is logged instead of being forwarded.

Why

This is a tightening of what counts as a valid repository-trust request, closing off requests that try to attach anything other than the expected digest before they reach the host.

Read from
Names in the bundletengu_violin_bridgepin
Feature flag
tengu_violin_bridgepin Off in both readings

The flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.

This account: off · anonymous baseline: off · compiled default in v2.1.277: off

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.277. It isn't a statement about your account. What a flag value here can and cannot tell you

What has happened since
Flag reading moved The flag server now returns on for tengu_violin_bridgepin, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.

See this across every release →

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe gate `tengu_violin_bridgepin` controlling this was read as off for both this site's account and the anonymous baseline, with no reading…
The name it cites is new in this buildNew in this build: tengu_violin_bridgepin

See this entry in the whole of v2.1.277 →

Feedback