Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.280 ·

Compliance-taint handling reworked to separate server data, hints, and HIPAA

Compliance-taint checks now distinguish server-fetched state, local hints, and HIPAA when deciding restrictions

Group of 3 Under the hood Internal Changes
JSON All of v2.1.280
Under the hoodTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
ComplianceArea: what it touches
Internal ChangesKind: in v2.1.280,
Internal ChangesSection of the release

What

Claude Code's handling of compliance_taints (labels used to decide feature restrictions) was reworked:

  • The function that merges incoming compliance_taints now filters out taints that fail a new predicate before merging and truncating the combined list.
  • The restriction check (fTt) now only applies compliance_taints from state when the session data actually came from a server fetch (sessionFromServerFetch); otherwise it falls back to locally hinted taints only.
  • The hipaa taint is now special-cased separately from other compliance taints, and is checked against server-populated feature restrictions rather than being folded in with generic hints.

Why

This avoids applying compliance restrictions based on stale or unverified local hints when authoritative server data isn't available yet, and gives HIPAA-specific restrictions more careful, server-backed handling than generic compliance taints.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat specific taints the new filter excludes, and why, is not stated in the evidence.

See this entry in the whole of v2.1.280 →

Feedback