Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.285 ·

Sandbox text explains when read-deny values are ignored or dropped

New sandbox text says glob, UNC and automount values are ignored, and values re-pointed into a denied read path are dropped

You'll notice Improvements
JSON All of v2.1.285
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release
What

The sandbox is the protected area Claude Code runs commands in, which limits what files they can read and write. Claude Code now includes text describing how the sandbox treats certain values:

  • A value that sits under a path you have denied for reading is ignored.
  • A value written as a glob (a wildcard pattern such as *.txt) is ignored.
  • A value written as a UNC path (a Windows network path starting with \\) or an automount path is ignored.
  • A value inside a writable directory is checked again before every command, and dropped once it has been re-pointed into a denied read path.
Why

The text describes a tightening of the sandbox. A value cannot be quietly redirected into a folder you blocked from reading, because it is checked again before each command runs.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear where this text appears or which setting it describes.

See this entry in the whole of v2.1.285 →

Feedback