{"version":"2.1.282","anchor":"sandbox-settings-scan-refuses-paths-that-reach-network-paths","canonical_anchor":"sandbox-settings-scan-refuses-paths-that-reach-network-paths","heading":"Settings check refuses paths that lead to network locations through a link","tier":"notice","area":"Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282\/e\/sandbox-settings-scan-refuses-paths-that-reach-network-paths","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282","markdown":"### Settings check refuses paths that lead to network locations through a link\n\nThe scan that keeps a repository's settings inside it now refuses paths that reach a network location through a symlink\n\n**Unclear.** Which commands or environments run this scan is not confirmed.\n\n**What**\n\nClaude Code scans the settings a repository ships to make sure they stay inside the repository. It now checks each path before following it, and stops with a refusal in these cases:\n\n- A symlink (a file that points to another location) on the path leads to a network path.\n\n- The path is longer than 4096 bytes.\n\n- The path cannot be checked in time.\n\nBefore, the path was followed directly with no network check.\n\n**Why**\n\nFollowing a link shipped in a repository to a network location could reach the network before you decided whether to trust that repository.\n\n- Area: Settings\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}