You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Cloud SessionsArea: what it touches
ImprovementsKind: in v2.1.280,
ImprovementsSection of the release
What
Claude Code adds a large set of new functions that verify git commits, trees, and objects built for syncing files during cloud or remote sessions read back as exactly what their content hashes claim. If they don't match, sync now reports a distinct "tampered" status instead of silently proceeding. Before uploading working-tree state, this process also builds a scratch index and tree that filters out uncommitted files that look like credentials, such as .env, .npmrc, .pem files, SSH keys, and AWS, Azure, GnuPG, or Kubernetes config files.
Why
This protects cloud and remote sessions from syncing corrupted or tampered file data, and reduces the risk of accidentally uploading sensitive credential files that hadn't been committed.