You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release
What
The sandbox is the protection that limits which files and network addresses Claude Code's commands can reach. The built-in descriptions of its settings were expanded:
sandbox.enabled now reads "Run Bash commands inside the sandbox. Default: false."
ignoreViolations and enableWeakerNestedSandbox gain descriptions, including a Linux-only option to run without the fresh /proc mount.
allowUnsandboxedCommands: a false set in managed settings, a --settings file or user settings holds, and in some cases a project-level value is ignored.
overrides_locked is now described as true also when allowUnsandboxedCommands: false comes from a --settings file or user settings, not only from an admin policy.
Project settings cannot re-open paths that another layer denies for reading, and a project-level network.strictAllowlist value is ignored in some cases.
Why
These are descriptions, not new behaviour. They make it clearer that a project's own settings file cannot loosen sandbox limits set by your administrator, a --settings file or your own user settings.