Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Sandbox deny rules ending in a slash are now flagged as invalid

Sandbox deny paths that end in a slash now show a validation error, because they matched nothing and protected nothing

You'll notice Improvements
JSON All of v2.1.284
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release
What

The sandbox is the restricted space Claude Code runs commands in. Its settings can deny access to files. Claude Code now checks deny entries in these places:

An absolute path, or a path starting with ~, that ends in a separator such as / is now reported, because such a pattern can match no path. The message suggests removing the trailing slash or adding ** at the end. The check only runs when filesystem sandboxing is not turned off.

Why

Before this, a deny rule written with a trailing slash silently protected nothing. It is now reported, so you can fix it.

What the documentation says
filesystem.denyRead Deploy managed settings modified, high confidence * While `filesystem.denyRead`, `filesystem.denyWrite`, or any entry in either is invalid, Claude Code also withholds both `filesystem.allowRead` and `filesystem.allowWrite` until you fix the deny list. see the edit
filesystem.denyWrite Deploy managed settings modified, high confidence * While `filesystem.denyRead`, `filesystem.denyWrite`, or any entry in either is invalid, Claude Code also withholds both `filesystem.allowRead` and `filesystem.allowWrite` until you fix the deny list. see the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear whether this error stops the settings from loading or is only reported.
Anthropic's documentation agreesfilesystem.denyRead on Deploy managed settings

See this entry in the whole of v2.1.284 →

Feedback