Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.283 ·

One invalid sandbox deny entry now withholds the matching allow rules

If one entry in deniedDomains, denyWrite or denyRead is invalid, Claude Code now withholds the matching allow list instead of applying it

You'll notice Improvements
JSON All of v2.1.283
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.283,
ImprovementsSection of the release
What

The sandbox limits which websites and files commands run by Claude can reach. Its sandbox.network and sandbox.filesystem settings now fail safe when a single deny entry is invalid and gets dropped:

  • An invalid entry in deniedDomains withholds allowedDomains.
  • An invalid entry in denyWrite withholds allowWrite.
  • An invalid entry in denyRead withholds allowRead.

Before, this happened only when a whole deny setting could not be read. autoMode already worked this way.

Why

A typo in one deny rule can no longer leave your allow rules fully in force while part of the restriction silently goes missing. If some access you allowed stops working, check your deny lists for an invalid entry.

Read from
What the documentation says
sandbox.network Set up Claude Code for your organization modified, high confidence | [Sandboxing](/docs/en/sandboxing) | OS-level filesystem and network isolation with domain allowlists | `sandbox.enabled`, `sandbox.network.allowedDomains` | see the edit
sandbox.network Deploy managed settings modified, high confidence | [`sandbox.network.allowManagedDomainsOnly`](/docs/en/settings-reference#sandbox-network-allowmanageddomainsonly) | Honor only managed `allowedDomains` and `WebFetch(domain:...)` allow rules; block other domains without prompting | see the edit
sandbox.filesystem Deploy managed settings modified, high confidence | [`sandbox.filesystem.allowManagedReadPathsOnly`](/docs/en/settings-reference#sandbox-filesystem-allowmanagedreadpathsonly) | When `true`, only `filesystem.allowRead` paths from managed settings are respected. `denyRead` still merges from… see the edit
sandbox.filesystem All settings modified, high confidence Protect credential files or directories from sandboxed commands. With `"mode": "deny"`, Claude Code blocks reads of the path inside the sandbox, the same read block as [`sandbox.filesystem.denyRead`](#sandbox-filesystem-denyread). With `"m… see the edit
sandbox.network Use Claude Science on a corporate network modified, medium confidence Configuring a mirror removes the public package hosts from the sandbox's network allowlist and admits the mirror host in their place, so a misconfigured mirror fails with an error that names the mirror rather than falling back to the publi… see the edit
sandbox.network Network requirements modified, medium confidence When Claude runs code, its network access passes through a local filtering proxy that allows only the domains on the sandbox's built-in allowlist, grouped by purpose below. By default, each member manages the list on their own computer. Me… see the edit
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up sandbox.network, on Set up Claude Code for your organization. | [Sandboxing](/docs/en/sandboxing) | OS-level filesystem and network isolation with domain allowlists | `sandbox.enabled`, `sandbox.network.allowedDomains` | admin-setup see the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhich settings sources this applies to, such as managed or personal settings, is not clear.
Anthropic's documentation agreessandbox.network on Set up Claude Code for your organization

See this entry in the whole of v2.1.283 →

Feedback