Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.285 ·

Sandbox status shown to host apps now describes the rules actually enforced

The sandbox status that Claude Code reports to host apps now describes the enforced rules and gains a field for allowing all Unix sockets

You'll notice Improvements
JSON All of v2.1.285
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release
What

The sandbox is a set of limits on what commands run by Claude can reach. Claude Code reports the sandbox's current state to host apps, meaning programs that embed Claude Code. That report has changed:

  • fs_allow_read, fs_allow_write and unix_sockets now say they report what is enforced. Project settings are left out while managed settings, set by an organization, require the sandbox.
  • A new field, allow_all_unix_sockets, says whether all Unix sockets are allowed. A Unix socket is a way for programs on the same machine to talk to each other.
  • The descriptions of allowedDomains and strictAllowlist are expanded to match, and note that WebFetch(domain:…) allow rules are left out of the allowlist.
Why

A host app showing sandbox settings can now show the policy that is in force, not settings that are being overridden.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear whether the sandbox enforces anything differently or only reports it differently.

See this entry in the whole of v2.1.285 →

Feedback