Follow Discord
Sweep 03 Oct 2026 · 20:28Z Build v2.1.289 510 read Stable v2.1.285 Latest v2.1.289 Next v2.1.289 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.280 ·

OPENSSL_CONF and LOCPATH added to the sanitized/stripped environment variable list

OPENSSL_CONF and LOCPATH join the list of environment variables Claude Code strips or guards against when spawning subprocesses.

Group of 2 You'll notice Improvements
JSON All of v2.1.280
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.280,
ImprovementsSection of the release

What

  • OPENSSL_CONF was added to the list of environment variables (alongside LD_PRELOAD, LD_AUDIT, DYLD_INSERT_LIBRARIES, NLSPATH) that get special, security-motivated handling, typically stripped when spawning subprocesses.
  • LOCPATH was likewise added to that list of guarded environment variables (which also includes LD_AUDIT, GCONV_PATH, NLSPATH, PSMODULEPATH, DYLD_INSERT_LIBRARIES).

Why

This closes off more ways a malicious or misconfigured environment variable could inject unexpected behavior into subprocesses that Claude Code spawns.

See this entry in the whole of v2.1.280 →

Feedback