What
Claude Code scans the settings a repository ships to make sure they stay inside the repository. It now checks each path before following it, and stops with a refusal in these cases:
- A symlink (a file that points to another location) on the path leads to a network path.
- The path is longer than 4096 bytes.
- The path cannot be checked in time.
Before, the path was followed directly with no network check.
Why
Following a link shipped in a repository to a network location could reach the network before you decided whether to trust that repository.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
Which commands or environments run this scan is not confirmed.