{"version":"2.1.280","anchor":"cloudremote-session-file-sync-gets-cryptographic-tamper-ver","canonical_anchor":"cloudremote-session-file-sync-gets-cryptographic-tamper-ver","heading":"Cloud\/remote-session file sync gets cryptographic tamper verification","tier":"notice","area":"Cloud Sessions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/cloudremote-session-file-sync-gets-cryptographic-tamper-ver","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### Cloud\/remote-session file sync gets cryptographic tamper verification\n\nCloud and remote-session file sync now cryptographically verifies that synced git data hasn't been tampered with\n\n**What**\n\nClaude Code adds a large set of new functions that verify git commits, trees, and objects built for syncing files during cloud or remote sessions read back as exactly what their content hashes claim. If they don't match, sync now reports a distinct \"tampered\" status instead of silently proceeding. Before uploading working-tree state, this process also builds a scratch index and tree that filters out uncommitted files that look like credentials, such as `.env`, `.npmrc`, `.pem` files, SSH keys, and AWS, Azure, GnuPG, or Kubernetes config files.\n\n**Why**\n\nThis protects cloud and remote sessions from syncing corrupted or tampered file data, and reduces the risk of accidentally uploading sensitive credential files that hadn't been committed.\n\n- Area: Cloud Sessions\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 2\/5"}