Follow Discord

Claude Code v2.1.284

latestnext 434 entries read Grouped into 328 v2.1.283 → v2.1.284 Mods API: +22 added · 0 removed · 7 changed · 12 docs only Markdown JSON Follow Unofficial

You can now use Sonnet 5.5 by choosing sonnet on the Anthropic API, where it replaces Sonnet 5. Bedrock, Vertex and other providers still get their older models under that name. A new sandbox network setting, deniedResolvedAddresses, blocks allowed websites that resolve to IP addresses or ranges you list. Apps built on the SDK can save a feedback report as a local zip with the new save_locally option. The Claude gateway can now sign in to its identity provider with a certificate, so oidc.client_secret is optional. /rate-limit-options now shows up in the command list.

Several features are in this build but not switched on yet. Claude Code can clear old tool results when you return after more than an hour idle. It keeps the last 5 results and stays off unless switched on remotely. PR Steward is an agent that looks after pull requests. /autofix-pr can now step aside when PR Steward is already working on one. A hidden guide plugin for the live mods added in v2.1.283 is built in but off.

Cleaning up an agent team no longer deletes its members' worktrees. Ending a session now closes only the tmux or iTerm teammate panes that session opened. Calls to an MCP tool whose server is still starting now wait instead of failing. A broken image in a prompt no longer crashes the turn. The /design canvas mode and the dashboard artifact template are removed. Claude can also no longer start /design on its own.

Written by our agent from the shipped bundle, not by Anthropic.

Five to try today

Picked from 18 you can use now
  1. Sonnet 5.5 becomes the default Sonnet model, with Sonnet 5 kept in the picker

    The sonnet alias now means Sonnet 5.5 (claude-sonnet-5-5) on the Anthropic API, Sonnet 5 stays pickable, and refusal handling now covers Sonnet

    Sessions & agents
  2. New appendSystemPromptHead option moves a verified start of the appended system prompt into the cached part, in remote sessions

    Remote sessions can move a hash-verified opening of --append-system-prompt text into the cached system prompt via CLAUDE_CODE_APPEND_PROMPT_HEAD

    Elsewhere
  3. Telemetry moves onto the plugin hook system, with a built-in cc-plugin-otlp and new rules for plugin telemetry hooks

    A built-in cc-plugin-otlp can send OpenTelemetry records through plugin hooks, and plugin telemetry hooks must name a stream, with anthropic reserved

    Extensions
  4. Unattended-serving consent gets a Remote Control hub row, and a Yes is not saved when settings turn it off

    A new hub row lets you see or withdraw consent for cloud sessions running commands on your computer, and policy-blocked Yes answers are not stored

    Sessions & agents
  5. SDK feedback can be saved as a local bundle, and hosts learn the feedback mode up front

    SDK hosts can save a feedback report as a local redacted zip with save_locally, and learn at startup whether feedback is sent, bundled or disabled

    Sessions & agents

Want the reasoning? Read walks the 42 entries that probably matter to you, each one opening to what changed and why.

Read this release → Every row →
Reading as
Show only
Tier
Flag state
Names
Pick an entry · j / k steps through · rest on a row to peek
155 entries

Improvementsopen

Continued from page 1

9 more of these are in What probably matters to you, on page 1.

↑Improved
You'll notice
Useful2 Signal1
Group of 2 Permissions unclear

.claude/rules from outside the project now need external-include approval#

A symlinked .claude/rules pointing outside the project is skipped unless external includes are approved, and the warning now names .claude/rules

Unclear The exact set of cases in which a symlinked rules folder is now skipped is not fully clear.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Group of 2 MCP unclear

Headless runs wait for MCP servers that allow rules and hooks depend on#

In -p and SDK runs, the first turn now waits for MCP servers named in allow rules or mcp_tool hooks before starting

Unclear It is not confirmed that the servers collected from allow rules and hooks are the same list the headless wait uses.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal2
Plugins unclear

Adding a claude.ai marketplace is refused in sessions that cannot save it#

In a session that cannot write to disk, adding a claude.ai marketplace now fails with a clear message instead of attempting the save

Unclear It is not clear which kind of session counts as unable to write to disk, or what happened in that situation before.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal2
Cloud Sessions unclear

Cloud folder sync stops when this machine has no signing key#

Attaching a git- or folder-backed synced session now needs a signing key for this device, and sync stops if there is none

Unclear Which users or sessions this sync feature is available to is not settled.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal2
Effort unclear

The xhigh effort level no longer names a specific model#

The xhigh effort description now ends "on supported models" instead of naming a model, and the check for which models allow it was reworked

Unclear Whether the reworked check changes which models allow xhigh is not known.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal2
Diskless Mode unclear

Bash is never treated as read-only in cloud-only sessions#

In sessions that run file and shell tools only in the cloud, Bash is never counted as read-only, and a local git check is skipped

Unclear It is not confirmed that the git status check and the hook change depend on the diskless option.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Terminal UI unclear

Tabbed dialogs wrap their tabs onto more lines in narrow terminals#

Tab headers in dialogs now wrap onto extra lines when the terminal is narrow, instead of staying on one row

Unclear It is not clear which dialogs let their content take over the arrow keys.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Artifacts unclear

Artifacts can no longer be published from files on network shares#

Publishing an artifact from a file on a network share is now refused unless that location is listed as a trusted network directory

Unclear Exactly which network path forms are caught, and how trusted network directories are set, is not stated.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
MCP unclear

Waiting for slow MCP servers is now shared across one response#

Several tool calls in one response now share one wait for a connecting MCP server, and a server that already timed out can be skipped

Unclear When the skipping of already timed-out servers is switched on is not known.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Slash Commands unclear

Self-paced /loop runs confirm and re-arm in a different order#

The instructions Claude follows when /loop paces itself were rebuilt, changing when it confirms, how it re-arms and what it says on stopping

Unclear It is not clear what decides whether the confirmation comes before or after the next run is scheduled.

Details 0 0 Feedback
/loop
↑Improved
You'll notice
Useful2 Signal1
Artifacts

Artifact pages may load scripts from more CDNs#

Artifact pages can now load scripts from unpkg.com, cdn.tailwindcss.com and code.jquery.com, as well as cdnjs and jsdelivr

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Terminal UI unclear

Collapsed output now shows roughly how much text is hidden#

Collapsed output that says how many lines are hidden now also gives the hidden size in KB when at least 1000 characters are cut

Unclear Which kinds of collapsed output show the size is not fully settled, though tool output and diffs are among them.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Plugins unclear

Plugins can tell when output from a process they ran was cut off#

The plugin runtime's $.process.run now reports isStdoutTruncated and isStderrTruncated when output passes its 4 MiB limit

Unclear It is not clear whether the 4 MiB limit is also new or only the two truncation values are.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Terminal UI unclear

Long pick lists can show how many options are hidden below#

Pick lists in Claude Code can now show an indented "N more" row when options are hidden below the visible ones

Unclear Which menus actually supply a name for their options, and so show this row, is not known.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Models unclear

Model aliases like opus now pick the first matching model in a configured list#

With a configured model list, opus, sonnet and haiku now map to the first model of that family in the list, not the canonical claude- ID

Unclear It is not clear where the configured model list comes from or which features use this lookup.

Details 0 0 Feedback
opussonnethaiku
↑Improved
You'll notice
Useful2 Signal1
Tools unclear

Claude is told to ask you questions only when your answer changes what it does next#

Claude is now told to skip questions with an obvious default or an answer it can check itself, pick the obvious option, say so, and carry on

Unclear The prompt record lists the AskUserQuestion description as unchanged since v2.1.283, which conflicts with the added text reported between v2.1.283 and v2.1.284, so the release it arrived in is unclear.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Group of 2 Git unclear

Remote-session uploads from git worktrees handle per-worktree config differently#

Per-worktree git config now has an 'inert' state with its own error message, and the refuse policy now rejects any worktree config that is present

Unclear It is not clear which worktree configuration states exist besides absent, extension and file, or exactly when this check runs.

Details 0 0 Feedback
extensions.worktreeConfig
↑Improved
You'll notice
Useful1 Signal1
Group of 2 Git unclear

Cloud directory sync tracks git repository identity more precisely#

Directory sync now records each downloaded apply's written files and upload generation, and compares the shared .git directory's identity

Unclear It is not stated which visible Claude Code feature depends on this comparison.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Account Memory unclear

Declining an account memory save can send Claude a specific message#

When you refuse to let Claude save to account memory, Claude can now receive a message written for that dialog instead of a generic one

Unclear It is not clear whether account memory is available to users yet.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Sandbox unclear

Linux sandbox also protects the parent folders of protected paths#

The Linux sandbox now mounts the parent folders of protected paths inside writable areas as read-only

Unclear The exact problem this guards against, such as renaming a parent folder, is not stated.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Slash Commands unclear

More custom commands keep their full name as an alternative name#

More custom prompt commands now keep their full name as an alias, which used to happen only for names that contain a colon

Unclear It is not clear which names pass the new check.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Artifacts unclear

Clearer errors when the artifact tool is given links it cannot read#

The artifact tool now explains when a link is a claude.ai chat artifact, chat or project link, or a bare id, and suggests what to do

Unclear It is not clear who can use the artifact tool in this release.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Gateway unclear

Gateway config now checks the login settings for telemetry forwarding#

Gateway configuration now checks the auth settings on each telemetry.forward_to entry and reports problems with their Google login settings

Unclear Which specific problems the check reports is not stated.

Details 0 0 Feedback
telemetry.forward_to
↑Improved
You'll notice
Useful1 Signal1
Permissions unclear

Bash command checks now follow line continuations and refuse commands they can't read#

The reader that checks shell commands before they run now follows backslash line breaks and marks more tricky commands as unreadable

Unclear What happens next with a command marked unreadable is not settled, though most likely Claude Code asks you for permission.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Plugins unclear

Unset on/off plugin options now show their default value#

Plugin options that are on/off switches now show true or false, using the default when unset, instead of showing blank

Unclear Which screen or output shows this list of values is not confirmed.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Plugins unclear

Plugin true/false settings that cannot be read are now left out#

A plugin setting that should be true or false is now dropped if its value cannot be read as one, instead of being forced into one

Unclear Exactly which texts are accepted as true or false is not known.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Plugins unclear

Failed plugin installs clean up according to why they failed#

When a plugin install fails, Claude Code now undoes only what that failure left behind, and can suggest updating a dependency that is too old

Unclear How the suggestion to update a dependency is shown to the user is not settled.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Permissions unclear

Bash network allow list now catches bracketed loopback addresses#

The Bash tool's per-command allowed_domains check now also rejects disguised loopback or IPv4 addresses written inside square brackets

Unclear Exactly which bracketed addresses got past the check before is not settled.

Details 0 0 Feedback
allowed_domains
↑Improved
You'll notice
Useful1 Signal1
Cloud Sessions unclear

New error for cloud sessions created without your folder's files#

A new message covers a cloud session that has none of this folder's files because this computer's device key could not be read

Unclear It is unclear where this message is shown or what decides when it appears.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Artifacts unclear

Claude is told to read an artifact before publishing changes to it#

The Artifact tool's instructions now accept only claude.ai artifact links and say a publish is refused unless Claude has read the artifact first

Unclear It is unclear whether the refusal is enforced in this version or only described in the instructions.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Plugins unclear

Plugin install prompt ignores answers typed too quickly#

The 'Run this command now?' prompt when installing a plugin now discards any answer given within 250 ms and asks again

Unclear The same check is used at one other prompt, and it is unclear which one.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Sandbox unclear

Sandbox deny rules ending in a slash are now flagged as invalid#

Sandbox deny paths that end in a slash now show a validation error, because they matched nothing and protected nothing

Unclear It is not clear whether this error stops the settings from loading or is only reported.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Elsewhere unclear

The "double-tap Esc to rewind" tip appears in fewer situations#

The tip suggesting you double-tap Esc to rewind the conversation now has an extra condition and shows up in fewer situations

Unclear Which situations now hide the tip is not clear.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Prompt Suggestions unclear

Prompt-suggestion hint no longer appears after commands or exit words#

The prompt-suggestion back-off hint now only shows after a normal prompt, not after slash commands or words like exit and :q

Unclear One further condition that skips the hint could not be identified.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Plugins unclear

Number fields in the configuration form now reject non-numbers#

In the Save configuration form, a number field now warns about input that is not a number, and empty input is still accepted

Unclear It is not certain that this form is the one for plugin settings.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Elsewhere unclear

A fixed order decides which feedback survey appears#

When several feedback surveys are waiting, Claude Code now picks one in a fixed order, preferring one that is actively asking

Unclear How surveys were chosen before, and whether each survey has its own switch.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Plugins unclear

Plugin version errors can suggest how to update the plugin#

When an installed plugin's version falls outside a required range, the error can now suggest updating that plugin

Unclear In which situations the hint is added is not known.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Cloud Sessions unclear

Cloud sessions explain why file sync is off in git worktrees#

In a linked git worktree, or a checkout whose git folder lives elsewhere, Claude Code says file sync is off and the session starts from GitHub

Unclear It is not clear which command shows these messages, or whether a server-side setting controls them.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Usage & Limits unclear

Usage checks stop retrying after a rejected token or a rate limit#

After a rejected token or a rate limit, Claude Code now stops re-asking the usage endpoint for a while, and retries once after a token refresh

Unclear It looks like the re-send after a token refresh runs even when the server-side setting is off, but this is not confirmed.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Plugins unclear

Plugin marketplace sources can now have credentials removed and odd URLs refused#

Claude Code now has a check that strips usernames, passwords and headers from plugin marketplace sources and refuses suspicious URLs

Unclear It is not clear when Claude Code runs this check, for example when saving or when displaying marketplace sources.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Permissions unclear

Risky git and ssh addresses are now caught even when padded with spaces or tabs#

Claude Code's check for dangerous ssh, git and file addresses now ignores leading spaces and hidden tabs or line breaks before matching

Unclear It is not clear which Claude Code feature, such as plugin sources from git, relies on this check.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Permissions unclear

The prompt for reading outside your folders now asks about just this read#

The permission prompt for reading a file outside your working folders now asks about this one read rather than reads in general

Unclear It is not clear whether what a Yes actually allows changed along with the wording.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Memory unclear

Recalled memory files are cleaned before Claude reads them#

A memory file's content now goes through the same cleaning step used when memories are written before it is added to Claude's context

Unclear What the cleaning step removes or changes is not clear.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal0
Sandbox unclear

Sandbox no longer warns when its Java proxy helper is missing#

Claude Code checks fewer places for its Java proxy helper and no longer logs a warning when it is missing

Unclear It is not confirmed that the helper still logs anything at all in this build.

Details 0 0 Feedback
38 entries

Bug Fixesopen

✓Fixed
You'll notice
Useful2 Signal2
Group of 2 Permissions unclear

Self-relaunch carries home-directory trust so the prompt is not asked again#

When Claude Code restarts itself from your home directory after you accepted the trust prompt, the restarted copy no longer asks again

Unclear Exactly which two paths are compared before the prompt is skipped is not confirmed.

Details 0 0 Feedback
--resume
✓Fixed
You'll notice
Useful3 Signal1
Images unclear

A broken image in a prompt no longer crashes the turn#

A malformed image in a submitted prompt is replaced by a short text note saying it could not be processed, instead of causing an error

Unclear It is not known whether images arriving by other routes than prompt submission get the same check.

Details 0 0 Feedback

Continues on page 3 →

Verbatim
Official · Anthropic

Anthropic’s official release notes

Published verbatim by Anthropic for v2.1.284. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.

Of these 100 bullets, 33 name something an entry on this page also names, 24 name something no entry here does, and 43 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.

System prompt

1 added and 1 removed, of 218 lines, about 4 words, in the prompt 15 of 27 arms receive. 3 other prompts also changed. 1 of 27 tool descriptions changed. The appended system-reminder blocks moved: 1 line added.

Claude Code, interactive mode

Documentation

What the docs did around this release

153 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.

Switches

Every name in this release

The 79 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.

Slash commands

CLI flags

Environment variables

Settings and names in the code

Feedback