Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

docker logs / docker inspect read-only checks now refuse remote-daemon flags and tilde paths

docker logs and docker inspect stop running automatically as read-only when given connection flags or tilde paths

Entry
JSON All of v2.1.281
EntryKind: in v2.1.281,
ChangesSection of the release
What

Claude Code treats docker logs and docker inspect as read-only commands it can run without asking. Both now use a stricter check, and a command is no longer approved automatically when it includes:

  • An option that picks which Docker daemon or connection to use, from a list including --host, --context, --config, --tlscacert, --url, --connection, --identity, --remote and --out
  • Such an option hidden inside bundled short flags, such as -Hx
  • A ~ after = or :
  • A ~ together with {

A Docker daemon is the background service that actually carries out docker commands, and it may be on another machine. In a shell, ~ can expand into a home directory path.

Why

A docker command that looks harmless can be pointed at a different machine or path by these options. Such commands now show a permission prompt instead of running silently.

What the documentation says
--out cmek-aws-kms modified, high confidence To find [your AWS account ID](https://docs.aws.amazon.com/IAM/latest/UserGuide/console-account-id.html), run `aws sts get-caller-identity --query Account --output text`. see the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agrees--out on cmek-aws-kms

See this entry in the whole of v2.1.281 →

Feedback