Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Risky git and ssh addresses are now caught even when padded with spaces or tabs

Claude Code's check for dangerous ssh, git and file addresses now ignores leading spaces and hidden tabs or line breaks before matching

You'll notice Improvements
JSON All of v2.1.284
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release
What

Claude Code checks certain addresses to see whether they start with a risky scheme, such as ssh://, git://, git+ssh://, ssh+git:// or file://. The scheme is the part before :// that says how to connect.

Before, the check only matched when the address began exactly with one of those schemes. It now first removes leading spaces and invisible control characters, and ignores tabs and line breaks inside the scheme. An address written as a space followed by ssh:, a tab, then // is now recognised as ssh.

Why

This closes a gap where extra whitespace could slip an ssh address past the check. Ssh addresses can be abused to make your computer run commands, so catching them matters.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear which Claude Code feature, such as plugin sources from git, relies on this check.

See this entry in the whole of v2.1.284 →

Feedback