File sync copies changes between a cloud session and your machine. It now treats these files as protected names:
- build scripts: Makefile, GNUmakefile, justfile
- package files: package.json, package-lock.json, npm-shrinkwrap.json
- lockfiles: yarn.lock, pnpm-lock.yaml, bun.lock, bun.lockb
- instruction files for Claude and other agents: CLAUDE.md, CLAUDE.local.md, AGENTS.md
Matching also covers the short Windows forms of these names, such as PACKAG~1.JSO. When sync would apply an incoming change to one of these files, it records a conflict instead and does not write the file. There is also a new skip reason, protected_name, for files that have names this machine protects and were not written.
A cloud session can no longer quietly rewrite your build scripts, package files or instruction files on your machine. These files can run code or steer Claude, so you now get to decide whether the change goes in.
How a recorded conflict is shown to you is not clear.