Follow Discord
Sweep 03 Oct 2026 · 20:28Z Build v2.1.289 510 read Stable v2.1.285 Latest v2.1.289 Next v2.1.289 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.280 ·

Path-outside-boundary denial messages now include the resolved landing path

Permission-denial messages for paths that escape an allowed folder now show where the path actually ends up

You'll notice Improvements
JSON All of v2.1.280
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.280,
ImprovementsSection of the release
What

When a file path resolves, via a symlink or .. traversal, to somewhere outside a folder Claude Code is allowed to access, the denial message and the blocked path it reports now show the actual resolved landing location rather than the original path string as typed. The permission-denial builder also now checks for an unresolved-path case first.

Why

This makes it clearer why a permission was denied, since the reader can see exactly where a seemingly-safe path actually pointed, rather than just the path they entered.

See this entry in the whole of v2.1.280 →

Feedback