{"version":"2.1.283","anchor":"sandbox-new-denyallnetwork-per-exec-option-not-supported-o","canonical_anchor":"sandbox-new-denyallnetwork-per-exec-option-not-supported-o","heading":"Sandbox gains a deny-all-network option","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/sandbox-new-denyallnetwork-per-exec-option-not-supported-o","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### Sandbox gains a deny-all-network option\n\nThe sandbox accepts a new denyAllNetwork option that cuts off all network access without a proxy; it is not supported on Windows\n\n**Unclear.** Nothing appears to use this option yet, so it may not affect any command in this release.\n\n**What**\n\nThe sandbox (the restricted environment Claude Code can run commands in) has a new per-command option, `denyAllNetwork`, accepted by `wrapWithSandbox`.\n\n- It forces network restriction without starting a network proxy.\n\n- It also turns off unix sockets, local binding, mach lookup, weaker network isolation, Apple events and the weaker nested sandbox.\n\n- On Windows it fails with \"denyAllNetwork is not supported on Windows\".\n\n- Support is advertised as `denyAllNetworkOption`, which the sandbox config passthrough now forwards, and one sandbox configuration sets it to true.\n\n**Why**\n\nThis gives a strict no-network mode for sandboxed commands, with no proxy in between. It is not available on Windows.\n\n- Area: Sandbox\n- Names: `denyAllNetwork`\n- Tier: You'll notice\n- Useful: 4\/5\n- Signal: 3\/5"}