Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.282 ·

Settings check refuses paths that lead to network locations through a link

The scan that keeps a repository's settings inside it now refuses paths that reach a network location through a symlink

You'll notice Improvements
JSON All of v2.1.282
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SettingsArea: what it touches
ImprovementsKind: in v2.1.282,
ImprovementsSection of the release
What

Claude Code scans the settings a repository ships to make sure they stay inside the repository. It now checks each path before following it, and stops with a refusal in these cases:

  • A symlink (a file that points to another location) on the path leads to a network path.
  • The path is longer than 4096 bytes.
  • The path cannot be checked in time.

Before, the path was followed directly with no network check.

Why

Following a link shipped in a repository to a network location could reach the network before you decided whether to trust that repository.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhich commands or environments run this scan is not confirmed.

See this entry in the whole of v2.1.282 →

Feedback