Claude Code v2.1.283 ·
Sandbox gains a deny-all-network option
The sandbox accepts a new denyAllNetwork option that cuts off all network access without a proxy; it is not supported on Windows
Group of 2 You'll notice Notable
No documentation found New Features
JSON
All of v2.1.283
You'll noticeTier: how much it should matter to you
4Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
SandboxArea: what it touches
New FeaturesKind: in v2.1.283,
What probably matters to youSection of the release
What
The sandbox (the restricted environment Claude Code can run commands in) has a new per-command option, denyAllNetwork, accepted by wrapWithSandbox.
- It forces network restriction without starting a network proxy.
- It also turns off unix sockets, local binding, mach lookup, weaker network isolation, Apple events and the weaker nested sandbox.
- On Windows it fails with "denyAllNetwork is not supported on Windows".
- Support is advertised as
denyAllNetworkOption, which the sandbox config passthrough now forwards, and one sandbox configuration sets it to true.
Why
This gives a strict no-network mode for sandboxed commands, with no proxy in between. It is not available on Windows.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtNothing appears to use this option yet, so it may not affect any command in this release.
See this entry in the whole of v2.1.283 →