Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.285 ·

Repository sandbox file grants are dropped or withheld in more cases

Sandbox read and write grants from a repo's project or local settings are now ignored under an admin mandate or when they point into denied paths

Group of 2 You'll notice Improvements
JSON All of v2.1.285
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release

What

The sandbox limits which files commands run by Claude can read and write. Project and local settings files, which can be committed to a repository, can add grants to that list. Before, their allowWrite and allowRead entries were always merged in. Now they are checked first:

  • Under an admin sandbox mandate (managed settings require the sandbox), sandbox.filesystem.allowWrite, Edit allow-rule paths and allowRead paths from project and local settings are dropped. A one-time log line says "[sandbox] filesystem grants restricted to trusted settings tiers: ignoring".
  • The same grants are also dropped when the path is under or inside a path you denied reading.
  • With blockReadsOutsideWorkingDirectories on, repo-committed allowRead and allowWrite grants are withheld if they are globs (wildcard patterns), UNC paths (Windows network-share paths), automount paths, or lead through symlinks (shortcuts to other locations) into denied read paths. The log line starts "[sandbox] withheld".

Why

A repository's settings can no longer quietly widen what sandboxed commands may touch. If you relied on project or local settings to grant sandbox access, check the log for these lines when a command is refused.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtExactly when an administrator's sandbox requirement counts as active is not stated.

See this entry in the whole of v2.1.285 →

Feedback