Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Sandbox write-deny paths now apply in one more sandbox mode

Your sandbox filesystem.denyWrite paths are now enforced in the sandbox mode used when a proxy port is configured, where they were ignored

You'll notice Bug Fixes
JSON All of v2.1.284
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
Bug FixesKind: in v2.1.284,
Bug FixesSection of the release
What

The sandbox is the walled-off environment Claude Code can run commands in, with rules about which files they may read or write. One of its modes, chosen when a proxy port is configured and that mode is available, used only your filesystem.denyRead setting from the sandbox configuration. It now also adds the paths in your filesystem.denyWrite setting to the list of places commands are not allowed to write.

Before, that mode blocked writes only to a fixed set of places such as project roots, your home folder, device files and temporary folders.

Why

A write rule you set could be silently ignored in this mode. It now takes effect there too, so stricter write limits you configure are actually enforced.

Read from
Names in the bundlefilesystem.denyWrite
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat this particular sandbox mode is used for is not clear; it may be a sandbox for scripts or checks.

See this entry in the whole of v2.1.284 →

Feedback