Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.280 ·

serverPopulated marker extended to more compliance restrictions, including Artifacts

More compliance-policy restriction entries, including the Artifacts permission, can now be marked server-populated and killed remotely

Group of 2 Under the hood Internal Changes
JSON All of v2.1.280
Under the hoodTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
ComplianceArea: what it touches
Internal ChangesKind: in v2.1.280,
Internal ChangesSection of the release

What

  • Several HIPAA-restriction entries (for example allow_account_plugins_sync) gained a serverPopulated: true marker. A helper treats a restriction as server-populated only when that marker is set and a remote kill-flag is not served true, which changes how compliance taints are merged when deciding whether an action is allowed.
  • The allow_cobalt_plinth policy entry (labeled "Artifacts", denied under hipaa/zdr) also gained serverPopulated: true, matching the pattern already used by allow_remote_control ("Remote Control").

Why Marking these restrictions as server-populated lets them be controlled and killed remotely rather than being fixed at build time, giving more flexibility in how compliance policies are enforced for features like Artifacts.

See this entry in the whole of v2.1.280 →

Feedback