Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.285 ·

Project sandbox.network settings ignored under admin control, including proxy ports

Under an admin sandbox mandate, sandbox.network entries from project and local settings are ignored, and only managed settings may replace the proxy

Group of 2 You'll notice Improvements
JSON All of v2.1.285
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release

What

The sandbox limits which hosts and ports commands run by Claude can reach, using the sandbox.network settings. Before, project settings, which can be committed to a repository, could supply these network allowances. Now:

  • When an admin sandbox mandate (managed settings require the sandbox) or a trusted network deny list applies, sandbox.network allowances from project and local settings are ignored. A log line says "[sandbox] admin sandbox mandate: ignoring sandbox.network."
  • Under allowManagedDomainsOnly, only managed settings can replace the filtering proxy (the program that checks where sandboxed traffic goes) through httpProxyPort and socksProxyPort. A project that tries is logged with "a project may not replace the filtering proxy".
  • httpProxyPort and socksProxyPort now have descriptions in the settings schema.

Why

A repository's settings can no longer send sandboxed traffic through a proxy of its own or widen network access when an administrator controls the sandbox.

Read from
Names in the bundlesandbox.network
What the documentation says
sandbox.network All settings modified, high confidence | [`sandbox.network`](#sandbox-network) | Control which hosts, ports, and sockets [sandboxed](/docs/en/sandboxing#network-isolation) commands reach | Sandbox settings | Any file | see the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreessandbox.network on All settings

See this entry in the whole of v2.1.285 →

Feedback