You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
Bug FixesKind: in v2.1.284,
Bug FixesSection of the release
What
The sandbox is the walled-off environment Claude Code can run commands in, with rules about which files they may read or write. One of its modes, chosen when a proxy port is configured and that mode is available, used only your filesystem.denyRead setting from the sandbox configuration. It now also adds the paths in your filesystem.denyWrite setting to the list of places commands are not allowed to write.
Before, that mode blocked writes only to a fixed set of places such as project roots, your home folder, device files and temporary folders.
Why
A write rule you set could be silently ignored in this mode. It now takes effect there too, so stricter write limits you configure are actually enforced.