Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.280 ·

Git tamper-detection hardened: character-device paths, split-index copying, and a curated git env-var allowlist

Claude Code hardened its git repo-tampering checks: device-file detection, split-index copying, and a curated env-var allowlist

You'll notice Improvements
JSON All of v2.1.280
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Git IntegrationArea: what it touches
ImprovementsKind: in v2.1.280,
ImprovementsSection of the release
What

Claude Code's internal checks for tampered or unusual git repositories have been strengthened in several ways:

  • Paths containing a 'character device' (a special kind of filesystem entry, not a normal file or folder) are now specifically detected and refused or guarded against during repo verification.
  • Worktree config (settings tied to a secondary git worktree) can now be treated as a recognized 'extension' instead of always being refused, controlled by a new perWorktreeConfig option that defaults to "refuse".
  • Git's split-index files (named sharedindex.*) are now copied into Claude Code's sandboxed internal git copy, up to a capped number of files, so operations relying on a split index continue to work.
  • When Claude Code runs git commands in its hardened mode, it now passes through a curated list of allowed GIT_*, proxy, and SSH-related environment variables, instead of stripping all environment variables.
Why

These changes make Claude Code's git safety checks more precise: instead of broadly refusing or stripping things that look unusual, it now recognizes and correctly handles more legitimate git setups (like repos using split indexes, worktrees, or environment-based proxy/SSH configuration) while still guarding against tampered paths involving device files.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe finding does not fully specify what triggers refuse-vs-guard behavior for character-device paths, nor the exact cap on split-index files…

See this entry in the whole of v2.1.280 →

Feedback